Live data from Hacker News

When Employees Use Software That IT Hasn’t Approved

hbr.org

151–160 of 326 posts

Re: When Employees Use Software That IT Hasn’t Approved

#151
post #47
post #22

This is exactly extremely common. In my company there is this constant battle about the devs having admin rights on their machines. We need admin rights to do our job. We have had dozens of meetings explaining the situation but IT can’t come up with a solution so the devs go around security because they have no alternative if they want to finish their work . Same with Dropbox. They block it but we have suppliers who…

I think most of the reasons for admin rights are no longer valid. Its easy to change user environment variables and lots of applications can be installed as a user. Why would you need admin rights? Dropbox/googledrive is a huge security hole that is definitely blocked at most companies I work at.

Running things like wireshark or certain debuggers without admin rights is often difficult.

Also, lots of stuff simply cannot be installed as a regular user, especially stuff that needs unfettered access to network cards or memory.

Re: When Employees Use Software That IT Hasn’t Approved

#152
post #144

Hehe, if you think this is nuts, come to pharma. We can't do jack shit with our machines. If you so much as change the time on your machine, that is a 'data integrity breach', and if your actions are determined to be malicious it can result in a firing.

To be honest, changing the time on a machine is a very serious concern. Accurate timekeeping is crucial in security, that's how you connect events together.

Well, all the rigid policies like no dropbox or no FTP or no whatever, also arise from serious concerns. I just wanted to point out another seemingly innocuous one. Most of our equipment is not internet connected, and we need to manually change the time for daylight savings or other corrections. We have a company policy and procedure to do that periodically so that our audit trails are accurate. Sometimes folks get busy and the shop floor guys take matters into their own hands.

Re: When Employees Use Software That IT Hasn’t Approved

#153

Earlier quoted context omitted.

You can ask IT to install it for you. You don’t need to install it yourself.

But then you're waiting around for the rest of the day for them to come install it.

They wouldn't even know how to install our stuff.

Re: When Employees Use Software That IT Hasn’t Approved

#154
post #8

Earlier quoted context omitted.

Sure, you need security. I would, though, expect to be summarily fired if I proposed something like a "disciplinary council" for when I had a disagreement with my customers. If you need rules to force the business to engage with you, you've failed.

If a large part of your job is security, and your "customers" had opted to start stealing product off the floor because it was "easier than waiting in a line", you would be fired for not bringing it up. Thats the situation the CIO had to respond to. Just because its not part if your role to consider security implications of these SaaS services doesnt mean he's out of line for doing so.

To true up the analogy, they are waiting in a line that's 3 years long.

Re: When Employees Use Software That IT Hasn’t Approved

#155
post #87

Earlier quoted context omitted.

Shouldn't this kind of thing be a problem for the managers to address? If you just circumvent this kind of nonsense instead of addressing it head on it just proliferates and allows the people who promote it to think they are doing an acceptable job. At minimum you should inform your direct manager of the situation so they can address it or accept the consequences that the work that depends on the restricted resource…

I've heard security management say it is their job to say no all day. They definitely don't care about preventing work getting done. They will only get fired if a data leak occurs, etc.. Preventing work won't even ding their promo outcomes.

The most secure network is one that no one uses. Therefore the goal is to make the network as difficult to use as possible.

Re: When Employees Use Software That IT Hasn’t Approved

#156

Earlier quoted context omitted.

But then you're waiting around for the rest of the day for them to come install it.

They wouldn't even know how to install our stuff.

Precisely! And then they'll get it wrong (or worse still say they won't do it the way you ask even though you will know better why those choices are needed!)

Re: When Employees Use Software That IT Hasn’t Approved

#157

Earlier quoted context omitted.

There’s nothing wrong with a block Dropbox policy. The problem here is a failure to establish a standardized method of transferring files in and out of the company.

And what if two companies standardized methods are incompatible?

They could hire a third company to copy the data from one standardized method to the other.

Re: When Employees Use Software That IT Hasn’t Approved

#158
post #49

Earlier quoted context omitted.

This resonates so much and seems to be a major trend in non-traditional tech companies. I've mostly worked in the financial industry and the executives' knowledge of technology is almost always horrible. As you said, a couple buzz words and very set opinions on the ways to do things. It's like they get pet projects in their head from reading an article in a magazine and get locked into it. I don't really have an issu…

You'd probably really appreciate this comedy sketch video: https://www.youtube.com/watch?v=BKorP55Aqvg

This is amazing! Thank you

Re: When Employees Use Software That IT Hasn’t Approved

#159
post #21

I see this a lot in consulting. When a new CIO (or CEO or other C level) arrives, they want to make their mark with a digital transformation intiative. This usually just means that the new C level employee is coming into a medium to large business and would like to add a bullet point to their resume and get that new shiny object everyone is talking about. Tableau, Salesforce, Data lakes, blockchain, ERP, Identity Man…

We've got a Salesforce implementation going at the nonprofit where I work. While there was some debate about which big CRM we'd buy, the need to consolidate was blindingly obvious.

Why? Because our organization has been quite forward thinking about allowing managers and executives to source the technology they think they to succeed. As this article advocates for, IT was largely consultative rather than dictatorial, and a lot of business units were able to pick what they wanted.

But what this has left us with is dozens of places where customer data was being stored, some of them now past their end of life. No central visibility into customer experience. People getting multiple copies of the same email from different departments using different email platforms. Poor deliverability. Subscriptions on random credit cards that suddenly turn off because the person left and no one knows how to get into the admin account and update the card.

We hired a boutique shop to do the Salesforce implementation; we're not scared of doing that. Unfortunately this time it did not pay off... their performance fell off, to the point that they couldn't even reply to emails on time. As sometimes happens with small firms, they grew too fast and exceeded their ability to operate. We can't wait for them to figure it out... so here we go with a big dog firm. Let's see how that goes.

Maybe I'm lucky in who I work with, but I find the "add a bullet point to the resume" take to be maybe a bit too cynical. Tableau, Salesforce, data lakes, ERP, identity management, and "cloud" infrastructure each seem like useful tools if implemented smartly. (Note that I took out blockchain...)

Re: When Employees Use Software That IT Hasn’t Approved

#160

How many years since The Phoenix Project and this conversation has barely moved an inch? CIO probably wins this battle and gets the VP fired, but will be mystified when they're reporting to the CFO or a Chief Digital Officer when it happens 3 more times by the end of the year.

It is wonderful. Each crack in a behemoth’s process is a point of leverage for a startup. We will outcompete by being better.
Post reply on HN