Live data from Hacker News

IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

openera.com

21–30 of 53 posts

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#22
Of course the "security" to which CIOs refer is not DLP or anything cool like that (I'm not implying that DLP works, only that it's cool) but rather their own job security. IT is a cost center, and CIOs only survive when they can account their costs to other parts of the business. If e.g. marketing, sales, and accounting can honestly say they don't need anything that IT is providing, IT might not be around much longer.

From an actual security standpoint, it makes sense to really evaluate how secret your data need to be, and then set up an infrastructure to support that. Individual customer demographic data should be absolutely secret, but that doesn't just mean that marketing people shouldn't upload it to Dropbox so it's easier to pull into their abominable Access DB. That means that the only people who ever see it are CSRs while they're actually talking to the customer. Then IT can add value by isolating CSR desktops on their own 802.1X-secured wired network, while providing a more open network for their other work, and encouraging a shred-all-post-it-notes policy.

I think IT can make legitimate security arguments, but these can't start with "gosh Dropbox is terrible!" Dropbox and other cloud services are used because they are useful. Rather than depriving the individual employee of useful services, find services the business as a whole needs but doesn't realize it needs.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#23

The described IT painfully reminds me of Soviet-style planned economy. It tries to be the only economy in tow", but as it falls behind due to inefficiency, it tries hard to suppress any other economies that try to arise. And of course it is done in the name of security! Obviously everyone is trying to steal your secrets and that's why you have to live in outdated and broken environment.

A lot of different aspects of companies remind me of this. Usually dictatorial control, rigid hierarchies, policies made with no input from those who will follow them, etc. It's wonderfully ironic that the iconic capitalist organization is often so communist internally.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#24

I really do hate reading articles that praise rogue employees using cloud services. It's wrong for an infinite string of Data Loss reasons, uncontrolled access to cloud services is no different than leaving a laptop filled with confidential information lying in the front seat of your car. It doesn't matter how secure the user thinks it is, nobody in Security or Risk Management has qualified or quantified the risk. To…

We're not trying to praise rogue employees for shunning corporate policies and opening up huge security holes.

The reality is that it's happening regardless. People are going to do what they feel they need to to get their job done.

Thus far, the general approach to dealing with this is to enforce more policy, block where possible, etc... which again, has done little to reduce employees from "going rogue".

We want to open the conversation on better ways to solve this problem since current methods simply aren't working.

As a network guy who gets that best understands the risks and consequences of unsecured, unsactioned clouds being used in a company - what would you suggest as potential solutions to give employees tools they need to get their job done, and the Company and IT the security it needs?

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#25
post #23

The described IT painfully reminds me of Soviet-style planned economy. It tries to be the only economy in tow", but as it falls behind due to inefficiency, it tries hard to suppress any other economies that try to arise. And of course it is done in the name of security! Obviously everyone is trying to steal your secrets and that's why you have to live in outdated and broken environment.

A lot of different aspects of companies remind me of this. Usually dictatorial control, rigid hierarchies, policies made with no input from those who will follow them, etc. It's wonderfully ironic that the iconic capitalist organization is often so communist internally.

http://en.wikipedia.org/wiki/The_Nature_of_the_Firm

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#26
Its fun to rail on internal IT. Most organizations inadvertently set the department up to fail and then find themselves shocked, shocked I tell you, to find that they have failed to deliver.

The boys in the basement aren't a bunch of Luddites, before the upstairs staff has even heard of the new tech out there, they're already dependent on it in their personal life (or have demoed and tossed it to the curb).

Spoilers: They actually can stop it, they're the ones managing firewall config after all. You should ask yourself "Why haven't they?" Probably has something to do with the fact the buisness requirements and/or budget preventing them from using the tools everybody would prefer.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#27

You need two networks: one internal without any Internet connection and computers with no WiFi and no USB. Make people work on their workstation, connected to the internal network and let them use their other computer / laptop to search the Web. I can name at least one very important chip-designing company that is worth $$$ bn that used to work this way (don't know where they're at now).

I work at a facility where all web browsing must be done through a remote desktop session to a server connected to the exterior network, which is reimaged regularly.

Unfortunately they don't keep software fully up to date on the remote desktop server, so the security benefits are lessened. But malicious websites have no way of stealing your secret files.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#28
post #26

Its fun to rail on internal IT. Most organizations inadvertently set the department up to fail and then find themselves shocked, shocked I tell you, to find that they have failed to deliver. The boys in the basement aren't a bunch of Luddites, before the upstairs staff has even heard of the new tech out there, they're already dependent on it in their personal life (or have demoed and tossed it to the curb). Spoilers:…

Hadn't really considered things from this angle - I'd be happy to see a win-win-win for the people, IT, and the company.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#29

You need two networks: one internal without any Internet connection and computers with no WiFi and no USB. Make people work on their workstation, connected to the internal network and let them use their other computer / laptop to search the Web. I can name at least one very important chip-designing company that is worth $$$ bn that used to work this way (don't know where they're at now).

I work at a facility where all web browsing must be done through a remote desktop session to a server connected to the exterior network, which is reimaged regularly. Unfortunately they don't keep software fully up to date on the remote desktop server, so the security benefits are lessened. But malicious websites have no way of stealing your secret files.

Unless there is a bug in your remote desktop client that can be exploited by a compromised server...

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#30
post #18

Sadly in large companies with IT departments that have accountability and as such have internal costing to another department. Well in those sitauation it is often common for one department head to go behind official channels and outsource for a cheaper price. This sadly bypasses alot of security and other standards the company has. It's not new, and will happen again and again. One example would be bank that had a w…

WTF?
Post reply on HN