That story probably never happened anyway. But the essence of the article is very true. I never have been in a corp where IT enforces 100% conformity anyway (apart from medical industry).
Sure, there are actual successful attacks, but that is mostly not the fault of unsanctioned programs.
But there are systems where people should not just start to use any system, because information gets lost on the way. That would include CRM and ERP in my opinion. That a company can exist without a CRM is questionable to begin with and solutions are plentiful. If they did not have anything like that...
If the story were true, it would not be the fault of Chief Input/Output.