Welcome!

@CloudExpo Authors: Yeshim Deniz, Liz McMillan, Pat Romanski, Zakia Bouachraoui, Elizabeth White

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Linux Containers, Cloud Security, SDN Journal

@CloudExpo: Blog Feed Post

Caught! The Real Culprit of Shadow IT

There are some amazing SaaS options out there, so many that IT cannot be expected to find them all first

Once you learn the definition of shadow IT, it shouldn’t be too shocking to learn how widespread it is at companies large and small all over the world. I hate to assume, but the odds are, that you yourself have used a non-IT approved SaaS option for the same reason as everyone else, myself included. We’re all expected to do our jobs faster, and at a higher quality than we did in the past, and sometimes it’s just too easy to go behind the backs of those whom we perceive to slow us down, or act as a blocker.

A recent study showed that eighty percent of those polled admitted using SaaS applications and tools without IT’s approval, which, when you’re part of that eighty percent, isn’t all that shocking. The real kicker is the revelation of who has been using shadow IT SaaS solutions more than anyone.

IT employees themselves.

What’s their reasoning? “IT users feel they can handle the risk better.” That's...not really good enough.

Even as an occasional user of shadow IT myself (I’m trying to quit!) I am happy to see that not every article found online simply touts the ill-advised practice as out-of-control, or impossible to stop. In fact, now that we’ve all learned just how widespread the problem is, many are already well underway in finding a way to rein it in. And in what should relieve CIOs, security professionals, and others responsible for heeling shadow IT as soon as possible—the solution is shockingly simple.

Put a clear policy in place that lists the SaaS options that are allowed, and also formally states that if you’re using one that is not listed, particularly those that are discovered to put you and your customers’ data at risk—this is a real problem.

But how do you know which ones to allow? Not only is this easy, it’s healthy for the culture of your business. Speak with those employees who are using shadow IT, and who have come to rely on these apps to do their job. Let them explain why they chose this or that option, and why the non-shadowy options prohibit them from doing their jobs, or more importantly, from innovating and helping take the company to the next level.

Many of the applications that employees are secretly utilizing probably aren’t a security threat, and like we learned earlier, I’d be willing to bet that many of them are also being used by IT employees as well as others. But as McAfee Asia-Pacific CTO Sean Duca explains, it’s the “shadow” aspect that’s ultimately “bad for business.”

With shadow IT usage being so rampant, across multiple departments, employees aren’t turning to these non-approved options out of laziness, or spite. It’s because IT doesn’t have the time to fully vet every SaaS option out there. Speak with employees to learn what’s helping them do their jobs. Make this an opportunity, as Duca suggests, to “be more open and candid,” to increase the collaboration and communication between departments, and so that “companies can consider purchasing the products so they could be used securely from inside their organizations.”

There are some amazing SaaS options out there, so many that IT cannot be expected to find them all first. But when a new option comes along, especially one that helps you innovate better and faster—don’t leave it in the shadows and put your job or your company at risk. If it’s as great of a solution as you think it is, get it approved, and perhaps even more of your company can benefit and innovate from it than just yourself.

Read the original blog entry...

More Stories By Skytap Blog

Author: Noel Wurst is the managing content editor at Skytap. Skytap provides SaaS-based dev/test environments to the enterprise. Skytap solution removes the inefficiencies and constraints that companies have within their software development lifecycle. As a result, customers release better software faster. In this blog, we publish engaging, thought provoking stories that revolve around agile enterprise applications and cloud-based development and testing.

CloudEXPO Stories
Whenever a new technology hits the high points of hype, everyone starts talking about it like it will solve all their business problems. Blockchain is one of those technologies. According to Gartner's latest report on the hype cycle of emerging technologies, blockchain has just passed the peak of their hype cycle curve. If you read the news articles about it, one would think it has taken over the technology world. No disruptive technology is without its challenges and potential impediments that frequently get lost in the hype. The panel will discuss their perspective on what they see as they key challenges and/or impediments to adoption, and how they see those issues could be resolved or mitigated.
There's no doubt that blockchain technology is a powerful tool for the enterprise, but bringing it mainstream has not been without challenges. As VP of Technology at 8base, Andrei is working to make developing a blockchain application accessible to anyone. With better tools, entrepreneurs and developers can work together to quickly and effectively launch applications that integrate smart contracts and blockchain technology. This will ultimately accelerate blockchain adoption on a global scale.
Despite being the market leader, we recognized the need to transform and reinvent our business at Dynatrace, before someone else disrupted the market. Over the course of three years, we changed everything - our technology, our culture and our brand image. In this session we'll discuss how we navigated through our own innovator's dilemma, and share takeaways from our experience that you can apply to your own organization.
DXWorldEXPO LLC announced today that Nutanix has been named "Platinum Sponsor" of CloudEXPO | DevOpsSUMMIT | DXWorldEXPO New York, which will take place November 12-13, 2018 in New York City. Nutanix makes infrastructure invisible, elevating IT to focus on the applications and services that power their business. The Nutanix Enterprise Cloud Platform blends web-scale engineering and consumer-grade design to natively converge server, storage, virtualization and networking into a resilient, software-defined solution with rich machine intelligence.
Founded in 2002 and headquartered in Chicago, Nexum® takes a comprehensive approach to security. Nexum approaches business with one simple statement: “Do what’s right for the customer and success will follow.” Nexum helps you mitigate risks, protect your data, increase business continuity and meet your unique business objectives by: Detecting and preventing network threats, intrusions and disruptions Equipping you with the information, tools, training and resources you need to effectively manage IT risk Nexum, Latin for an arrangement by which one pledged one’s very liberty as security, Nexum is committed to ensuring your security. At Nexum, We Mean Security®.