Live data from Hacker News

IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

openera.com

11–20 of 53 posts

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#11
The idea there is something wrong with the resourceful workers instead of the lagging IT is perposterous.

IT right now in many companies is living in 2004 still. SO MUCH has changed in the intervening 8 years, it's no surprise that people are going with consumer grade products when corporate IT doesn't deliver modern resources.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#12
I really do hate reading articles that praise rogue employees using cloud services.

It's wrong for an infinite string of Data Loss reasons, uncontrolled access to cloud services is no different than leaving a laptop filled with confidential information lying in the front seat of your car.

It doesn't matter how secure the user thinks it is, nobody in Security or Risk Management has qualified or quantified the risk.

To say that Executives would rather stifle productivity is false, they will get the appropriate tools for the job for their workers, that has never been the issue at any organization I've worked for directly, or consulted for.

The real reason nobody cracks down on this, is kind of ironic, although the executives know it's going on, and they will chastise or have you written up for breaking policy/procedure, the truth is that they don't really know what their security posture is and they don't want to know for liability reasons.

There's a lot of willful ignorance, because Security in IT truly is a giant black hole cost center to these people, and rather than seeing it as protective measure, they see it as something that stifles productivity and costs enormous amounts of money.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#13

The described IT painfully reminds me of Soviet-style planned economy. It tries to be the only economy in tow", but as it falls behind due to inefficiency, it tries hard to suppress any other economies that try to arise. And of course it is done in the name of security! Obviously everyone is trying to steal your secrets and that's why you have to live in outdated and broken environment.

Actually, people are trying to steal business secrets, and they are doing so all the time. The Chinese are notorious for it, and they target basically any business that has a valuable trade secret, even those that are not military. Even the US has been caught using its intelligence apparatus to pass foreign trade secrets to domestic businesses:

https://en.wikipedia.org/wiki/ECHELON#Controversy

If I were running a business whose trade secrets were worth more than a few hours of some Eastern European hacker's time, I would be concerned about computer security.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#14

You need two networks: one internal without any Internet connection and computers with no WiFi and no USB. Make people work on their workstation, connected to the internal network and let them use their other computer / laptop to search the Web. I can name at least one very important chip-designing company that is worth $$$ bn that used to work this way (don't know where they're at now).

I interned at an outfit like that a long time ago. It sucked then and would never work now in the age of smart devices. Unless of course these devices were banned from, or confiscated on entry to, the workpla^H^H gulag.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#15
post #2

> While nearly two-thirds of companies (60 percent)report they have corporate policies in place that prohibit such actions, respondents say there are no real deterrents for purchasing cloud services by stealth. In fact, 29 percent report there are no ramifications whatsoever and another 48 percent say it is little more than a warning. If it's such a big deal that employees are using Dropbox in the office, employ some…

Policies and punishment have proven to be useless tools to stop the spread of rogue clouds. Employees will do what they need to do to get their job done.

CIO's are adopting cloud apps. The reality is that users will still inadvertently save files in the wrong place. I know I do all the time. If we can help get the files into the right place, even if the user saves them in the wrong place, then that is progress and lessens the negative impact of rogue clouds.

Make it easy for people to do the right thing and don't make them change the way they work.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#16
post #2

> While nearly two-thirds of companies (60 percent)report they have corporate policies in place that prohibit such actions, respondents say there are no real deterrents for purchasing cloud services by stealth. In fact, 29 percent report there are no ramifications whatsoever and another 48 percent say it is little more than a warning. If it's such a big deal that employees are using Dropbox in the office, employ some…

> "why not stamp it all out at once? Or, work with it!"

You can't work with it, because of liability. If you bless Dropbox and champion it to the rest of management, it becomes your problem when the inevitable data breach happens.

But you don't want to stamp it out all at once, because: 1. CIOs know that cutting off things people want really badly just leads to better circumvention tech (more people running proxies or using 3G laptops, etc) and suddenly you can't even watch what they're doing, let alone stop it.

2. Those things are useful. Just because the Enterprise can't make peace with limitations or find a suitable analogue doesn't mean those tools don't legitimately make people more productive.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#17
post #14

You need two networks: one internal without any Internet connection and computers with no WiFi and no USB. Make people work on their workstation, connected to the internal network and let them use their other computer / laptop to search the Web. I can name at least one very important chip-designing company that is worth $$$ bn that used to work this way (don't know where they're at now).

I interned at an outfit like that a long time ago. It sucked then and would never work now in the age of smart devices. Unless of course these devices were banned from, or confiscated on entry to, the workpla^H^H gulag.

I don't think I'd want to work in a place like that.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#18
Sadly in large companies with IT departments that have accountability and as such have internal costing to another department. Well in those sitauation it is often common for one department head to go behind official channels and outsource for a cheaper price. This sadly bypasses alot of security and other standards the company has. It's not new, and will happen again and again.

One example would be bank that had a website defaced around 12 or so years ago in protest to petrol prices. Turned out that the server was located in a server room with a dog running around in it and would be best described as a spare bedroom almost. The marketing department manager had organised that gem of a disaster. Was lucky as forensics upon that server indicated it had been hacked at least half a dozen times previously. So the defacement hacker had done that bank a realy big favour.

So your company can have the best and most excellent security standards in the World that are completely unbeatable. But it only takes one department head to outsource behind your back or for one individual with a BYOD or the like to plugs in and your open to a screwing.

Clouds are popular as for some reason people have been sold that there all uber secure in that all your worries are removed. They are not, shifting the storage elsewere not only opens up another access point publicly to potentual get at your data but the over comfortable attitude it installs will be inclined to make the clients not as secure as they should be.

If I was a Administrator and I was responsible for the data and liable to getting legaly shafted if there is a breach and the company used clouds and had a BYOD policy then I'd be very much underpaid and with that googling for some form of disclaimer you got every user to sign and every manager to sign. Just so I could sleep at night.

Remember this, when it comes to IT most users are like children and with that they will find a way to break it if one exists and failing that they will find a way.

Block everything website wise and add as an exception, as there realy isn't many websites that companies need you to access. If you want to access any other site then BYOD and network, just don't go driving on the internet in the name of your company. I often wonder if I was to set up a free porn site and then check what companies have employee's browsing it and then have a name and shame of the companies. But I feel that would be cruel upon poor employees with a porn addiction and with that I just can't do it as it would just get alot of people sacked and no company would take any heat from it.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#19

I really do hate reading articles that praise rogue employees using cloud services. It's wrong for an infinite string of Data Loss reasons, uncontrolled access to cloud services is no different than leaving a laptop filled with confidential information lying in the front seat of your car. It doesn't matter how secure the user thinks it is, nobody in Security or Risk Management has qualified or quantified the risk. To…

Good points. There is a lot of willful ignorance. (Plausible deniability is one of my favorite excuses I hear!) I think its a bigger problem that really depends on the type of company or organization. Small and large commercial firms face less risk than Defense, Pharma, Financial and other highly regulated industries.

I don't think anyone is praising employees who go rogue, but I for one completely understand why they do, and sympathize. In many cases companies have made it way too hard to get things done. When systems get in the way of getting $#!t done, people find a way. Especially if their livelihood (sales, consultants...) depends on it.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#20

The described IT painfully reminds me of Soviet-style planned economy. It tries to be the only economy in tow", but as it falls behind due to inefficiency, it tries hard to suppress any other economies that try to arise. And of course it is done in the name of security! Obviously everyone is trying to steal your secrets and that's why you have to live in outdated and broken environment.

Actually, people are trying to steal business secrets, and they are doing so all the time. The Chinese are notorious for it, and they target basically any business that has a valuable trade secret, even those that are not military. Even the US has been caught using its intelligence apparatus to pass foreign trade secrets to domestic businesses: https://en.wikipedia.org/wiki/ECHELON#Controversy If I were running a bus…

Security measures prevent you from doing work. You have to find a balance. USSR never found one, but USA did. So there is no longer any USSR.
Post reply on HN