Live data from Hacker News

When Employees Use Software That IT Hasn’t Approved

hbr.org

91–100 of 326 posts

Re: When Employees Use Software That IT Hasn’t Approved

#91
post #84

Its the user who downloaded a program they "needed" which had malware which sent out a lot of spam email because this was a user that did announcements which basically got an e-mail server listed on blacklists that creates these IT policies. You want to treat people like responsible adults, but they aren't the ones who have to deal with the fallout. Developers know the score for the most part, so full privileges are…

Yep, a company I worked at hired a tech writer that downloaded some cracked version of software that included ransomware on their first day of work because they said they didn't want to wait for the company to get them a legitimate copy.

Well, that used to be common practice... in the '90s.

Thank $deity for the rise of opensource.

Re: When Employees Use Software That IT Hasn’t Approved

#92
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

The "customer" doesn't care about IT and wants to do things behind the back of the CIO. The "customer" goes to extreme lengths to hide the fact that he is violating company policy by purchasing SaaS with his own credit card. If that employee leaves one day, all the data inside the SaaS is gone because nobody else knew about it. A malicious employee could also use it to extort the company.

Re: When Employees Use Software That IT Hasn’t Approved

#93
post #87
post #22

This is exactly extremely common. In my company there is this constant battle about the devs having admin rights on their machines. We need admin rights to do our job. We have had dozens of meetings explaining the situation but IT can’t come up with a solution so the devs go around security because they have no alternative if they want to finish their work . Same with Dropbox. They block it but we have suppliers who…

Shouldn't this kind of thing be a problem for the managers to address? If you just circumvent this kind of nonsense instead of addressing it head on it just proliferates and allows the people who promote it to think they are doing an acceptable job. At minimum you should inform your direct manager of the situation so they can address it or accept the consequences that the work that depends on the restricted resource…

Management knows.

Re: When Employees Use Software That IT Hasn’t Approved

#94
post #8
post #6

Earlier quoted context omitted.

No, CIO role often carries responsibility for security. VP violates policy is like skirting regulation - yes it cost less money, but for all you know they are not compliant with policy and aren’t doing the whole job. However it does often seem like IT doesn’t consider SaaS solutions - they always want to build something their selves without doing cost analysis.

Sure, you need security. I would, though, expect to be summarily fired if I proposed something like a "disciplinary council" for when I had a disagreement with my customers. If you need rules to force the business to engage with you, you've failed.

If a large part of your job is security, and your "customers" had opted to start stealing product off the floor because it was "easier than waiting in a line", you would be fired for not bringing it up.

Thats the situation the CIO had to respond to. Just because its not part if your role to consider security implications of these SaaS services doesnt mean he's out of line for doing so.

Re: When Employees Use Software That IT Hasn’t Approved

#95
post #91
post #84

Earlier quoted context omitted.

Yep, a company I worked at hired a tech writer that downloaded some cracked version of software that included ransomware on their first day of work because they said they didn't want to wait for the company to get them a legitimate copy.

Well, that used to be common practice... in the '90s. Thank $deity for the rise of opensource.

OpenSource still isn't a force in that particular area. Its Microsoft or Adobe there.

Re: When Employees Use Software That IT Hasn’t Approved

#96

I work in an IT organization & I see (in the sense of witness) both sides of this. We are over-tasked and under-resourced and new projects/ideas/initiatives that come in the door go into a backlog of requests. So I see business/end users signing up on their own for SAAS solutions to solve their problems.

Right, the CIO is also being held to a lower standard than a P&L. The CIO could have planed out an interim solution to meet the business needs quicker.

If the tables were turned, say the CIO needed to deliver a service and didn’t have a big enough budget, then what?

Re: When Employees Use Software That IT Hasn’t Approved

#97

Earlier quoted context omitted.

I find most “IT security policies” that hamper developers to be mostly security theatre. No matter how many policies they put in place, since they aren’t developers, one junior developer can write: var sql = “select * from Customer where firstname = ‘“ + firstname + “‘“; And thwart all of your security “best practices.” I was the lead dev at a medium size non tech company, and the hoops I had to go through to get any…

I find most “IT security policies” that hamper developers to be mostly security theatre. No matter how many policies they put in place, since they aren’t developers, one junior developer can write... IT policies at large corporations aren't implemented for developers (only). They're implemented for everybody. For every developer, there is a salesperson, admin, manager, or HRBP who will do things they might not fully…

Yes. I remember ILOVEYOU too. It also confirms my point.

- It spread by reading the person’s contact information which doesn’t require administrator access.

- It also corrupted the user’s files and didn’t require administrator access for that either.

Re: When Employees Use Software That IT Hasn’t Approved

#98
post #51
post #21

I see this a lot in consulting. When a new CIO (or CEO or other C level) arrives, they want to make their mark with a digital transformation intiative. This usually just means that the new C level employee is coming into a medium to large business and would like to add a bullet point to their resume and get that new shiny object everyone is talking about. Tableau, Salesforce, Data lakes, blockchain, ERP, Identity Man…

> Nobody every gets fired for hiring Accenture/Deloitte/PwC. What usually happens in the non trivial niches is that these big shops sleeve the boutiques through them to get things done... To provide a prospective as someone who works for a consulting firm like the ones you've mentioned... Hiring the "big" firms versus boutiques is a lot about a perception of risk, maintaining partnerships (procurement with new vendor…

Sure, they get fired but are hired somewhere else because of the contracts they made botching a multi-million dollar contract. There isn't much of a downside to them for over-promising and under-delivering.

Re: When Employees Use Software That IT Hasn’t Approved

#99
post #6
post #2

"Soon enough the CIO sniffed out the project and called her in to a disciplinary council." Somebody has apparently lost touch with who the customer for IT is.

No, CIO role often carries responsibility for security. VP violates policy is like skirting regulation - yes it cost less money, but for all you know they are not compliant with policy and aren’t doing the whole job. However it does often seem like IT doesn’t consider SaaS solutions - they always want to build something their selves without doing cost analysis.

The security triad is confidentiality, integrity and availability. If a security expert doesn't make sure that their security policies give users access to the things that they need, then they are only doing two-thirds of their job.

Re: When Employees Use Software That IT Hasn’t Approved

#100
post #22

This is exactly extremely common. In my company there is this constant battle about the devs having admin rights on their machines. We need admin rights to do our job. We have had dozens of meetings explaining the situation but IT can’t come up with a solution so the devs go around security because they have no alternative if they want to finish their work . Same with Dropbox. They block it but we have suppliers who…

I have my own PC strapped under my desk connected to public Wi-Fi. I use it to do all my work. My company pc is left turned on but disconnected, sitting on top of my desk to dissuade suspicion.

Does your company know you have their IP on your personal device (and are sending company communications over public WiFi)?
Post reply on HN