1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:03,750
we'll explore the hidden world of shadow IT.

3
00:00:03,750 --> 00:00:06,450
Shadow IT provides us with some unique challenges

4
00:00:06,450 --> 00:00:09,360
because it refers to the use of information technology

5
00:00:09,360 --> 00:00:13,200
systems, devices, software, applications, and services,

6
00:00:13,200 --> 00:00:16,410
without explicit organizational approval.

7
00:00:16,410 --> 00:00:19,590
You may hear the terms stealth IT or client IT

8
00:00:19,590 --> 00:00:22,200
also used to refer to shadow IT when you are working

9
00:00:22,200 --> 00:00:25,050
out in the field as a cybersecurity professional.

10
00:00:25,050 --> 00:00:28,320
Now, shadow IT refers to IT-related projects

11
00:00:28,320 --> 00:00:31,020
that are managed outside of and without the knowledge

12
00:00:31,020 --> 00:00:33,630
of the IT department, and they can include anything

13
00:00:33,630 --> 00:00:36,480
from the use of personal devices for work purposes,

14
00:00:36,480 --> 00:00:38,910
the installation of unapproved software,

15
00:00:38,910 --> 00:00:40,590
or the use of cloud services

16
00:00:40,590 --> 00:00:43,410
that have not been approved by the organization.

17
00:00:43,410 --> 00:00:45,600
So why does shadow IT exist?

18
00:00:45,600 --> 00:00:47,970
Well, I normally find that shadow IT exists

19
00:00:47,970 --> 00:00:49,980
because an organization's security posture

20
00:00:49,980 --> 00:00:52,230
is actually being set too high

21
00:00:52,230 --> 00:00:55,110
or is too complex for business operations to occur

22
00:00:55,110 --> 00:00:57,420
without being negatively affected.

23
00:00:57,420 --> 00:00:59,400
For example, let's pretend that you want to have

24
00:00:59,400 --> 00:01:02,280
a second monitor added to your office computer setup.

25
00:01:02,280 --> 00:01:04,110
In one organization I was working for,

26
00:01:04,110 --> 00:01:06,480
the process to request a second monitor,

27
00:01:06,480 --> 00:01:09,720
get it approved, get it ordered and then get it delivered,

28
00:01:09,720 --> 00:01:12,600
and get it installed took about 45 days.

29
00:01:12,600 --> 00:01:14,940
This is just ridiculous for something as easy

30
00:01:14,940 --> 00:01:17,160
and inexpensive as a new monitor.

31
00:01:17,160 --> 00:01:19,440
So, many people would simply not bother

32
00:01:19,440 --> 00:01:21,577
requesting a new monitor, and they would just buy

33
00:01:21,577 --> 00:01:24,330
$100 monitor at the store, bring it to work,

34
00:01:24,330 --> 00:01:25,800
and connect it themselves.

35
00:01:25,800 --> 00:01:29,490
But this monitor is now considered to be shadow IT

36
00:01:29,490 --> 00:01:31,380
because no one knows where it came from,

37
00:01:31,380 --> 00:01:33,060
the security posture of the device,

38
00:01:33,060 --> 00:01:35,940
and there's no lifecycle management for the device,

39
00:01:35,940 --> 00:01:37,950
so if it breaks, the IT department

40
00:01:37,950 --> 00:01:40,500
cannot repair it or replace it.

41
00:01:40,500 --> 00:01:42,960
Now, a monitor is not that big of a deal,

42
00:01:42,960 --> 00:01:44,790
but if you connect a USB thumb drive,

43
00:01:44,790 --> 00:01:48,060
an external hard drive, a keyboard, a wired mouse,

44
00:01:48,060 --> 00:01:51,000
a network adapter, or any other type of device,

45
00:01:51,000 --> 00:01:54,240
you could be introducing a whole range of vulnerabilities

46
00:01:54,240 --> 00:01:57,060
into the network without even realizing it.

47
00:01:57,060 --> 00:02:00,780
So while shadow IT could possibly boost the productivity

48
00:02:00,780 --> 00:02:03,390
and innovation in the organization,

49
00:02:03,390 --> 00:02:06,090
allowing employees to find their own technology solutions

50
00:02:06,090 --> 00:02:09,360
for their problems, it also poses a significant risk,

51
00:02:09,360 --> 00:02:11,670
including opening up your organization

52
00:02:11,670 --> 00:02:15,060
to potential data breaches, non-compliance with regulation,

53
00:02:15,060 --> 00:02:17,070
and system disruptions.

54
00:02:17,070 --> 00:02:18,930
The reason for this is that shadow IT

55
00:02:18,930 --> 00:02:22,410
can lead to a lack of standardization across the network,

56
00:02:22,410 --> 00:02:24,750
which makes the management and strategic planning

57
00:02:24,750 --> 00:02:27,390
of your network much more complicated.

58
00:02:27,390 --> 00:02:31,080
When problems arise from the use of unsanctioned technology,

59
00:02:31,080 --> 00:02:33,870
they can be harder to resolve due to the IT department's

60
00:02:33,870 --> 00:02:36,060
lack of awareness or understanding

61
00:02:36,060 --> 00:02:38,910
of the specific technology deployed by the user.

62
00:02:38,910 --> 00:02:41,460
For example, if a specific user has downloaded

63
00:02:41,460 --> 00:02:44,220
a piece of software to perform some kind of task,

64
00:02:44,220 --> 00:02:46,830
and this software is included in some type of malware

65
00:02:46,830 --> 00:02:49,500
that they did not know about, it will be much harder

66
00:02:49,500 --> 00:02:51,480
for the technical support department

67
00:02:51,480 --> 00:02:53,640
to find the reason for malware spreading out

68
00:02:53,640 --> 00:02:55,230
across the organization network,

69
00:02:55,230 --> 00:02:57,120
since they don't know where this program

70
00:02:57,120 --> 00:02:59,130
was installed on their network.

71
00:02:59,130 --> 00:03:01,380
Another reason for the rise of shadow IT

72
00:03:01,380 --> 00:03:03,660
is that employees want to gain more efficiency

73
00:03:03,660 --> 00:03:05,340
and convenience when working.

74
00:03:05,340 --> 00:03:08,460
So they may install a web browser plugin or extension

75
00:03:08,460 --> 00:03:11,310
and other unsanctioned tools and applications

76
00:03:11,310 --> 00:03:13,920
to make their experience more user-friendly

77
00:03:13,920 --> 00:03:17,070
than the tools provided by the organization's network.

78
00:03:17,070 --> 00:03:19,920
Also, the large scale adoption of cloud-based services

79
00:03:19,920 --> 00:03:23,010
and mobile apps combined with the bring your own device,

80
00:03:23,010 --> 00:03:26,220
or BYOD trend, has also facilitated

81
00:03:26,220 --> 00:03:29,370
the rise of shadow IT in many enterprise networks.

82
00:03:29,370 --> 00:03:32,010
Some shadow IT is more virtual in nature.

83
00:03:32,010 --> 00:03:33,840
For example, if an employee decides

84
00:03:33,840 --> 00:03:37,200
to use cloud storage services like Dropbox or Google Drive

85
00:03:37,200 --> 00:03:40,170
for sharing and storing work-related documents

86
00:03:40,170 --> 00:03:42,990
without the IT department's knowledge or approval,

87
00:03:42,990 --> 00:03:45,630
this is yet another form of shadow IT.

88
00:03:45,630 --> 00:03:47,250
While these services can enhance

89
00:03:47,250 --> 00:03:49,290
the collaboration and efficiency,

90
00:03:49,290 --> 00:03:52,320
they can also lead to data leakage or breaches

91
00:03:52,320 --> 00:03:54,060
if not properly managed.

92
00:03:54,060 --> 00:03:57,090
So organizations should make a conscious decision

93
00:03:57,090 --> 00:04:00,270
as to which, if any, of these cloud storage services

94
00:04:00,270 --> 00:04:02,700
they will support for organizational use.

95
00:04:02,700 --> 00:04:04,500
Bring your own devices, or BYOD,

96
00:04:04,500 --> 00:04:07,620
involves the use of personal devices for work purposes.

97
00:04:07,620 --> 00:04:10,890
Employees may use their personal smartphones, tablets,

98
00:04:10,890 --> 00:04:13,770
or laptops to access work emails or documents,

99
00:04:13,770 --> 00:04:15,870
which gives them a lot of convenience,

100
00:04:15,870 --> 00:04:18,870
but it also has the potential for exposing sensitive data

101
00:04:18,870 --> 00:04:20,459
to security risks.

102
00:04:20,459 --> 00:04:23,220
Since these personal devices might not have the same levels

103
00:04:23,220 --> 00:04:25,800
of required protections as other corporate-owned

104
00:04:25,800 --> 00:04:29,160
or procured devices that are managed by the IT department,

105
00:04:29,160 --> 00:04:31,860
these personal devices can become an easy target

106
00:04:31,860 --> 00:04:34,020
for opportunistic threat actors.

107
00:04:34,020 --> 00:04:36,540
So remember, shadow IT can represent

108
00:04:36,540 --> 00:04:39,090
a significant challenge for organizations.

109
00:04:39,090 --> 00:04:42,000
Shadow IT is the use of information technology systems,

110
00:04:42,000 --> 00:04:44,880
devices, software, applications, and services,

111
00:04:44,880 --> 00:04:47,670
without explicit organizational approval.

112
00:04:47,670 --> 00:04:50,370
While it can drive innovation and efficiency,

113
00:04:50,370 --> 00:04:52,800
it also poses substantial security risks,

114
00:04:52,800 --> 00:04:55,650
so organizations must try to strike a healthy balance

115
00:04:55,650 --> 00:04:57,600
by developing policies that allow

116
00:04:57,600 --> 00:04:59,760
for flexibility and innovation,

117
00:04:59,760 --> 00:05:03,900
while also ensuring data security and compliance.

118
00:05:03,900 --> 00:05:06,300
If the technology department of your organization

119
00:05:06,300 --> 00:05:08,640
doesn't know that a particular piece of hardware,

120
00:05:08,640 --> 00:05:12,180
software, or cloud service is being used by its employees,

121
00:05:12,180 --> 00:05:14,730
then they are going to be unable to secure it.

122
00:05:14,730 --> 00:05:17,130
This is why shadow IT is so dangerous

123
00:05:17,130 --> 00:05:20,343
to the security of your enterprise networks.

