Live data from Hacker News

Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

accessowl.io

11–20 of 38 posts

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#11
What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes?

On the one hand, such a rule sounds like stodgy company friction to "getting it done".

On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who needed it, and often eventually losing the information entirely.

I've also seen (to pick one anecdote) newer software developers pasting the data of a very sensitive proprietary engineering model into some random developer's Web site that provided a visualization. This random Web site then spread around engineering as the standard way you visualize that model.

And I've seen third-party service dependencies that made no sense at all, but people were just following tutorials and StackOverflow answers they found.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#12
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

We talked to lots of CISOs, InfoSec managers and IT admins about that issue. There's basically two camps: Actively block any new tool vs. not block but educate so people don't do anything stupid.

I feel not blocking makes most sense. Employee's want to be treated like adults, especially in tech savvy companies. If they feel like they are unnecessarily blocked they will just find a workaround (i.e. non-work email or device).

However, you definitely want to keep track of people are signing up for - that's where the Shadow IT scanner comes in handy. In case you see something that's against policy it's often enough to just explain why it's a risk for the company. No employee means harm and just wants to be treated like an adult.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#13
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

Having also worked with many corps around this area for many years

It also comes down to appropriate procurement processes. Employees should not be able to buy or procure anything without requiring them to assess the inherent risks that service will introduce. Those risks include the cyber/information security related risks of that service including SaaS platforms.

You should not be able to purchase an use any technology service without a risk assessment and that includes SaaS platforms, to identify if the information you're providing to that platform is secure.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#14
In a previous role many years ago I used a tool called Netskope which monitored Firewall traffic and it was excellent at identifying almost every web related service being used.

This was helpful because it would detect SaaS platforms being used that were not integrated into SSO, like PDF converters etc

But I really like how simple this looks to use and it looks powerful

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#15
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

Nobody without the power to sign contracts in company name can legally register and use a SaaS at work. They can make a personal account and using it amounts to extracting data out of the company.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#16
post #12
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

We talked to lots of CISOs, InfoSec managers and IT admins about that issue. There's basically two camps: Actively block any new tool vs. not block but educate so people don't do anything stupid. I feel not blocking makes most sense. Employee's want to be treated like adults, especially in tech savvy companies. If they feel like they are unnecessarily blocked they will just find a workaround (i.e. non-work email or d…

Agree it isn't practical to block everything while still allowing software engineers to do their job. An online regex tester is super useful or could be a big risk is an employee uses it incorrectly.

But it is helpful to block certain things that are just too common outside of work so people just don't think twice. Things like ChatGPT, Grammerly, Pastebin, etc. should be manually blocked.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#17
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

Having also worked with many corps around this area for many years It also comes down to appropriate procurement processes. Employees should not be able to buy or procure anything without requiring them to assess the inherent risks that service will introduce. Those risks include the cyber/information security related risks of that service including SaaS platforms. You should not be able to purchase an use any techno…

The biggest challenge is that there's an abundance of SaaS tools that are free to use or have extensive free trials. This often lures employee's in "just trying" a platform and ending up importing critical company data.

Slack and Loom are great examples of SaaS that profited from being "Shadow IT". They gained traction by employee's quickly self-onboarding onto the free-plan, without their IT or Security knowing what data is being shared.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#18
post #12

Earlier quoted context omitted.

We talked to lots of CISOs, InfoSec managers and IT admins about that issue. There's basically two camps: Actively block any new tool vs. not block but educate so people don't do anything stupid. I feel not blocking makes most sense. Employee's want to be treated like adults, especially in tech savvy companies. If they feel like they are unnecessarily blocked they will just find a workaround (i.e. non-work email or d…

Agree it isn't practical to block everything while still allowing software engineers to do their job. An online regex tester is super useful or could be a big risk is an employee uses it incorrectly. But it is helpful to block certain things that are just too common outside of work so people just don't think twice. Things like ChatGPT, Grammerly, Pastebin, etc. should be manually blocked.

Another interesting approach I learned from the Director of IT at Intercom (Emanuele Sparvoli): They pay for a single seat in each of the typical "Shadow IT" SaaS apps. Then they block within the SaaS app the ability to sign up with email/password coming from their domain.

It's pretty drastic since you literally pay for a seat in a tool you don't want to use. But it stops anybody from quickly signing up and instead will guide them to the IT team. They then have the chance to explain what the official alternatives are.

What's important is that the employee's understand the reason why certain apps are not allowed - whether that's cost, security or something else.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#19

In a previous role many years ago I used a tool called Netskope which monitored Firewall traffic and it was excellent at identifying almost every web related service being used. This was helpful because it would detect SaaS platforms being used that were not integrated into SSO, like PDF converters etc But I really like how simple this looks to use and it looks powerful

Indeed, there are some great alternatives for discovering Shadow IT, some with more or less overhead (i.e. browser extensions that nobody wants to install).

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#20
post #17

Earlier quoted context omitted.

Having also worked with many corps around this area for many years It also comes down to appropriate procurement processes. Employees should not be able to buy or procure anything without requiring them to assess the inherent risks that service will introduce. Those risks include the cyber/information security related risks of that service including SaaS platforms. You should not be able to purchase an use any techno…

The biggest challenge is that there's an abundance of SaaS tools that are free to use or have extensive free trials. This often lures employee's in "just trying" a platform and ending up importing critical company data. Slack and Loom are great examples of SaaS that profited from being "Shadow IT". They gained traction by employee's quickly self-onboarding onto the free-plan, without their IT or Security knowing what…

If you block marketing from using the tools they want, they will do it anyway but using personal email addresses like Gmail or something like that especially with the generous free tiers.
Post reply on HN