Shadow IT - Reasons, Risks and Remediation
Shadow IT covers far more than apps installed without authorization or PCs and routers brought in from home. This talk discusses how uncontrolled IT also stays hidden in devices, cloud services and supply chains. Causes include hard-to-use corporate systems, time pressure, insufficient resources, pressure to outsource services, as well as user creativity and a lack of discipline among privileged power users and administrators. This creates potential risks from unpatched systems to data leakage, compliance violations, unknown dependencies and unclear responsibilities. As complexity, regulation and misuse increase, training and policies alone are not enough. What is needed: up-to-date inventories, limited privileges, adequate supplier due diligence, ongoing monitoring, automated pattern detection, rapid response, sufficient evidence of due-diligence compliance, realistic fallback plans, and a new understanding of trust.