Over the last several years Shadow IT has grown from a minor annoyance into a major threat to business operations. While the term is often used to refer to runaway tech spending by users in marketing or dev-ops or finance, it has in fact become a much larger issue that involves the very core of organizational infrastructure with the potential to pose enormous cyber risk.
With the recent shift to large scale work from home due to the COVID-19 pandemic, that risk has multiplied. With some industries seeing as much as 75% of their workforce shift to working from home or remote offices (which by the way are up to 3.5x more likely to have at least one malware infection than corporate networks), the data in your cloud has never been more necessary-- or more vulnerable, which is all the more reason organizations need to aggressively gain visibility into and secure their attack surface.
The Rise of Infrastructure Shadow IT
What is Shadow IT? Basically, it’s services or capabilities that IT and security teams don’t know about, don’t have visibility into and don’t have governance over. As mentioned above, there’s a few ways this can become an issue-- and while SaaS applications that marketing onboards without IT knowing certainly pose a risk, but lack of visibility into unknown cloud instances and / or data services may also pose high levels of cyber risk to your organization.
But surely something as big as an AWS or Oracle Cloud instance couldn’t go unnoticed, right?
That’s what many security leaders believe, but it’s shockingly easy for cloud instances to fly under the radar. In fact, there may even be several unauthorized clouds in your organization.
There are several ways this can happen. The most common is the result of an acquisition or merger, where systems are inherited by the parent company, but are missed or overlooked in an IT audit. It also commonly happens when organizations operate all over the globe, with offices in different geo’s spinning up new services to meet specific needs or because regional regulations or laws may make it difficult for them to use corporate approved assets.
Why Is Shadow IT Risky?
Shadow IT poses a real danger to organizations precisely because it’s unmanaged, and this is especially true of cloud instances since the attack surface can expand significantly without the organization being aware of the risk.
First, most organizations are fairly stringent about ensuring vendors are properly assessed before doing business with them. With shadow IT, there is usually no way to know if a vendor is approved for use or has been found compliant. However, even if it’s a vendor like Google, there is still another issue that can loom large for any organization.
Most cloud providers use a security method called the Shared Responsibility Model, in which the provider secures the infrastructure itself, but the customer is responsible for securing their data and apps. Research shows this model is often poorly understood by most security professionals, leading to misconfigured security that leaves sensitive cloud information at risk, as a trove of recent breaches illustrated last year. When cloud assets aren’t accounted for at the organizational level, there is a critical gap in visibility and accountability.