The Hidden Perils of Shadow IT: Safeguarding National Infrastructure

Author: Chris Crowther

22 Jul 2024

Tags:

In today’s digital age, along with people and process, technology forms the backbone of many critical sectors, including defence, government, the banking sector and law enforcement. As these organisations rely heavily on IT systems to operate efficiently, an often-overlooked threat looms large: Shadow IT. Understanding and addressing this issue is paramount to ensuring the security and integrity of our national infrastructure.

What is Shadow IT?

Shadow IT refers to the use of information technology systems, devices, software, applications, and services without explicit organisational approval. These unauthorised tools often fly under the radar of the IT department, leading to a lack of oversight and control.

Imagine an employee using a free file-sharing service to send sensitive documents because the approved system is too slow. This seemingly harmless act can introduce significant security vulnerabilities. Shadow IT isn’t inherently malicious, but its unmanaged and often non-security compliant nature creates numerous risks.

Why is Shadow IT used by employees?

Despite the inherent risks, Shadow IT continues to proliferate within organisations and the reasons are varied:

  1. Efficiency and Convenience: Employees often find that OFFICIAL systems are cumbersome and slow. They also tend to be difficult to use because of security; as the systems' designers have been unable to reach the right balance between usability and security. To meet tight deadlines, they might turn to faster, more user-friendly alternatives available on the market. For example, a team might use a cloud-based collaboration tool instead of the company’s sanctioned but outdated platform. The recent Covid-19 enquiry highlights Downing Street officials using unofficial channels i.e. WhatsApp for OFFICIAL communications and then deleting them.

  2. Innovation and Experimentation: Staff members may want to experiment with new tools to enhance productivity and innovation, bypassing the slow procurement processes of their organisations. They might believe that using the latest app or service will give them a competitive edge in their work. However, care must be taken, in 2023; Morgan Stanley was fined, when some of its traders used WhatsApp to discuss business which was in breach of OFGEM regulations.

  3. Lack of Awareness: Many employees may not be aware of the security risks associated with using unauthorised applications. They might think that their actions are harmless and don’t realise the potential for data breaches or other security issues. While not Shadow IT, it was a lack of awareness that led to the Florida Water Treatment hack in 2021, which caused a huge CNI scare when hackers used a badly configured remote access tool to run the system from a Work-From-Home Engineer laptop and attempted to dump lethal levels of chemicals into the supply

How Shadow IT risks information security and can lead to a security breach

The unchecked growth of Shadow IT poses significant security risks, especially for organisations handling sensitive information. Here are some of the dangers:

  1. Data Breaches: Unauthorised applications may not comply with the organisation's security standards, making them vulnerable to cyber-attacks. Sensitive data can be exposed or stolen, leading to severe breaches. For instance, an unsecured cloud storage service used without IT’s knowledge could be a treasure trove for hackers.

  2. Non-compliance: Many industries, particularly defence and government, have strict regulatory requirements. Shadow IT can lead to non-compliance, resulting in hefty fines and legal consequences. Regulatory bodies expect strict adherence to data protection laws, and any deviation can be costly.

  3. Increased Attack Surface: The more unauthorised applications in use, the larger the attack surface becomes. This makes it easier for cybercriminals to exploit weaknesses. Each application or device connected to the network is a potential entry point for attackers.

  4. Data Loss: Without proper oversight, data stored in shadow IT systems can be lost or irretrievable, especially if an employee leaves the organisation or the service is discontinued. Imagine a crucial project stored on a personal account that becomes inaccessible when the employee departs.

How companies and organisations can protect themselves from Shadow IT

To mitigate the risks associated with Shadow IT, organisations should adopt a multi-faceted approach:

  1. Education and Training: Regularly educate employees about the risks of Shadow IT and the importance of using authorised tools. Awareness campaigns can significantly reduce the tendency to bypass official channels. Training sessions should highlight real-world examples of security breaches caused by Shadow IT.

  2. Implement Robust Policies: Establish clear IT policies that define the use of technology within the organisation. Ensure these policies are communicated effectively and enforced consistently. Policies should outline the approval process for new tools and the repercussions of unauthorised usage.

  3. Monitoring and Detection: Utilise advanced monitoring tools to detect unauthorised applications and devices within the network. Continuous monitoring can help identify and address Shadow IT before it becomes a significant issue. Tools like network monitoring and endpoint detection systems can provide visibility into shadow IT activities.

  4. Provide Alternatives: Ensure that the IT department offers efficient, user-friendly, and secure alternatives to popular Shadow IT tools. By meeting the needs of employees, the reliance on unauthorised applications can be reduced. Conduct regular surveys to understand employees' needs and address gaps with approved solutions.

  5. Foster a Collaborative Environment: Encourage open communication between IT departments and other staff members. When employees feel their technological needs are understood and addressed, they are less likely to resort to Shadow IT. Creating a feedback loop where employees can suggest tools and improvements can build trust and compliance.

Conclusion

Shadow IT represents a significant threat to the security of critical national infrastructure. By understanding its causes and implementing effective countermeasures, organisations can protect themselves against the hidden perils that come with unauthorised technology use. Ensuring robust cybersecurity practices and fostering a culture of compliance are essential steps in safeguarding our most sensitive sectors.

The blame for the use of Shadow IT does not lie entirely with the users, it's up to the organisation to ensure that the security measures balance with the useability and the assessed risk. Generally, people want to protect the organisation they work for, but often processes and security get in the way of them doing their job, at the pace they need, so enabling them to do the right thing should be the goal of any organisation's security team and this healthy tension should flow down from the CIO and clear risk statements.

By taking proactive measures, we can secure our infrastructure and maintain the trust and integrity of our CNI and critical Government agencies and departments.

Key Takeaways

  • Shadow IT: Unauthorised technology use within organisations.

  • Risks: Data breaches, non-compliance, increased attack surface, data loss.

  • Prevention: Education, robust policies, monitoring, providing alternatives, fostering collaboration.

By addressing the dangers of Shadow IT, we can eliminate one of the key threat vectors to the critical systems that form the backbone of our national security.

Secure your organisation against Shadow IT

As experts in secure information exchange, Nexor is uniquely positioned to help you tackle the challenges of Shadow IT. We specialise in implementing tailored solutions that ensure robust security while maintaining an excellent user experience, thereby discouraging the use of unauthorised applications. Our services, solutions and technologies would have played a key role in defeating the cited breaches mentioned in this blog.

Don’t leave your organisation’s IT security to chance. Contact us today to learn how we can help safeguard your systems against the hidden risks of Shadow IT and strengthen your cybersecurity measures. Together, we can protect the critical infrastructure that forms the backbone of our national security.

Read more posts on

About the author

Dr Chris Crowther is the Head of Professional Services at Nexor. With over 30 years of experience in information assurance and security sectors, Chris has led the delivery of demanding national security programs in the UK, US, and EMEA. Operating at the highest levels of government, he possesses an exceptional track record of driving and delivering change in complex organisations.

Chris Crowther on Linkedin

Read more posts by Chris Crowther

Read more posts on