Live data from Hacker News

When Employees Use Software That IT Hasn’t Approved

hbr.org

11–20 of 326 posts

Re: When Employees Use Software That IT Hasn’t Approved

#12
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

It depends. If the company has instituted SSO and MFA and someone goes out and uses a solution that is outside of that, they could be exposing the company to liability.

Re: When Employees Use Software That IT Hasn’t Approved

#13
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

To be honest, I find it odd when you treat it as if everyone else that you work with is a customer. I don't believe in this philosophy. The business is my customer. The business is what IT is trying to protect. If you have individuals that are not following policies, they would be disciplined like HR would discipline for not following policies. It's all in place to protect the business and what's best for the busines…

Agreed. Everyone is beholden to the company and its principles, not the CEO or manager, though there should be alignment, but when there isn’t, then it’s the company.

Re: When Employees Use Software That IT Hasn’t Approved

#14
post #6
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

No, CIO role often carries responsibility for security. VP violates policy is like skirting regulation - yes it cost less money, but for all you know they are not compliant with policy and aren’t doing the whole job. However it does often seem like IT doesn’t consider SaaS solutions - they always want to build something their selves without doing cost analysis.

I have to use SaaS solutions for work, and the security situation terrifies me. I have to put my corporate password, with access to all sorts of important stuff, into a sketchy 3rd-party web site. This looks mighty bad.

Re: When Employees Use Software That IT Hasn’t Approved

#15
post #12
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

It depends. If the company has instituted SSO and MFA and someone goes out and uses a solution that is outside of that, they could be exposing the company to liability.

It's the fact that something like a "disciplinary council" exists, and that it was the first tactic the CIO went with that bothers me.

There's a reason they went around the CIO. I suspect if the CIO had met with this person they could have learned and helped.

Re: When Employees Use Software That IT Hasn’t Approved

#16
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

To be honest, I find it odd when you treat it as if everyone else that you work with is a customer. I don't believe in this philosophy. The business is my customer. The business is what IT is trying to protect. If you have individuals that are not following policies, they would be disciplined like HR would discipline for not following policies. It's all in place to protect the business and what's best for the busines…

Did you miss the line where it was written "before we started the program, we were losing revenue. Now we increased it by 1MM$ / month"?

It seems that the whole point of the article is that while IT thinks that it is serving the customer (the business), it actually lost track of what it was needed to: helping it succeed.

Re: When Employees Use Software That IT Hasn’t Approved

#18
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

To be honest, I find it odd when you treat it as if everyone else that you work with is a customer. I don't believe in this philosophy. The business is my customer. The business is what IT is trying to protect. If you have individuals that are not following policies, they would be disciplined like HR would discipline for not following policies. It's all in place to protect the business and what's best for the busines…

It goes both ways. Is the business user taking inappropriate risks to get his own work done quicker? Or is IT denying access to vendors to minimize his personal responsibility?
Post reply on HN