• Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Intelligence
    • Policy Intelligence
    • Security Intelligence
    • Economic Intelligence
    • Fashion Intelligence
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • LBNN Blueprints
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Intelligence
    • Policy Intelligence
    • Security Intelligence
    • Economic Intelligence
    • Fashion Intelligence
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • LBNN Blueprints

the risks unauthorized IT products pose to business

Simon Osuji by Simon Osuji
December 26, 2023
in Telecoms
0
the risks unauthorized IT products pose to business
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter



Companies are at an increased risk of becoming targets of cyber incidents due to the use of shadow IT by their employees amid the growing trend towards a distributed workforce, a recent study has found. According to research by Kaspersky, 87% of companies in the UAE suffered cyber incidents in the last two years, and 13% of these were caused by the use of shadow IT.

A recent Kaspersky study[1] showed that, in the last two years, 11% of companies worldwide have suffered cyber incidents due to the use of shadow IT by employees. The consequences of the use of shadow IT can be diverse in their severity, but they are never insignificant, whether it’s the leak of a piece of confidential data or tangible damage to business. 

Related posts

Iraq plans $65bln multi-service economic city at Al-Tayeb

Iraq plans $65bln multi-service economic city at Al-Tayeb

February 22, 2026
King Salman International Airport signs 7 MoUs to develop real estate projects

King Salman International Airport signs 7 MoUs to develop real estate projects

February 22, 2026

So, what is shadow IT? 

Shadow IT is the part of the company’s IT infrastructure that is outside the purview of the IT and Information Security departments, i.e. applications, devices, public cloud services etc. but that is not being used in accordance with information security policies. Deployment and operating shadow IT can lead to serious negative outcomes for businesses. Many instances were found in the Kaspersky study, which revealed that the IT industry – had been the hardest hit, suffering 16% of cyber incidents due to the unauthorized use of shadow IT in 2022 and 2023. Other sectors hit by the problem were critical infrastructure and transport & logistics organizations, which saw 13%. 

Recent case of Okta clearly proves the dangers of using shadow IT. This year, an employee using a personal Google account on a company-owned device unintentionally allowed threat actors to gain unauthorized access to Okta’s customer support system. There they were able to hijack files containing session tokens that could then be used to conduct attacks. This cyber incident lasted for 20 days and impacted 134 company’s customers according to Okta’s report.

Outlining ‘blurry shadows’

So, when you are looking for shadow IT, what to look for? These can be either unauthorized applications installed on employee computers, or unsolicited flash drives, mobile phones, laptops, etc.

But there are also some options that are less conspicuous. One example of this is abandoned hardware left over after the modernization or reorganization of the IT infrastructure. It can be used ‘in the shadows’ by other employees, acquiring vulnerabilities that will sooner or later find their way into the company’s infrastructure.

Regarding IT specialists and programmers, as it often occurs, they can create a tailored programs themselves to optimize work within a team/department, or to solve internal problems, making work faster and more efficient. However, they don’t always ask to the Information Security department for authorization to use these programs, and this could have disastrous consequences.

“Employees who use applications, devices or cloud services that are not approved by the IT-department, believe that if those IT-products come from trusted providers, they should be protected and safe. However, in the ‘terms and conditions’ third-party providers use the so-called ‘shared responsibility model’. It states that, by choosing ‘I agree’ users confirm that they will perform regular updates of this software and that they take responsibility for incidents related to the use of this software (including corporate data leakages). But at the end of the day business needs tools to control the shadow IT when it’s used by employees. Kaspersky Endpoint Security for Business and Kaspersky Endpoint Security Cloud, offer this control with Application, Web and Device control functions that limit the use of unsolicited apps, websites and peripherals. The Information Security department will of course still need to conduct regular scans of their company’s internal network to avoid the unauthorized use of uncontrolled and unsafe hardware, services and software applications.” comments Alexey Vovk, Head of Information Security at Kaspersky.

In general, the situation with the widespread usage of shadow IT is complicated by the fact that many organizations do not have any documented sanctions where their employees will suffer as a consequence of going against IT policies in this matter. Moreover, it is assumed that shadow IT could become one of the top threats to corporate cybersecurity by 2025. The good news is that the motivation for employees to use shadow IT is not always malicious, even more often, it’s the opposite. Employees in many cases use this as an option to expand the functionality of the products they use at work because they believe that the set of allowed software is insufficient, or they simply prefer the familiar program from their personal computer. 

To mitigate the risks of using shadow IT in an organization, Kaspersky recommends:

  • Ensure cooperation between the business and IT departments to regularly discuss new business needs, obtain feedback on the IT services used, in order to create new and improve existing IT services needed by the business.
  • Regularly conduct an inventory of IT assets and scan your internal network to avoid the appearance of uncontrolled hardware and services.
  • When it comes to personal employee devices, it’s best to give users as limited access as possible to only the resources they need to do their job. Use an access control system that will only allow authorized devices onto the network.
  • Carry out training programs to improve the information security literacy of employees. To boost security awareness among employees, educate them with the Kaspersky Automated Security Awareness Platform training program, which teaches safe internet behavior.
  • Invest in relevant training programs for IT security specialists. Kaspersky Cybersecurity for IT Online training helps build up simple yet effective IT security-related best practices and simple incident response scenarios for generalist IT admins, while Kaspersky Expert Training equips your security team with the latest knowledge and skills in threat management and mitigation.
  • Use products and solutions that allow you to control the use of shadow IT within your organization. Kaspersky Endpoint Security for Business and Kaspersky Endpoint Security Cloud offer Application, Web and Device controls which limit the use of unsolicited apps, websites and peripherals, significantly reducing infection risks even in cases where employees use shadow IT or make mistakes due lack of cybersafe habits.
  • Regularly conduct an inventory of IT assets to eliminate the appearance of abandoned devices and hardware.
  • Organize a centralized process for publishing self-written solutions so that IT, so Information Security specialists learn about them in a timely manner.
  • Limit the work of employees with third-party external services and if possible, block access to the most popular cloud information exchange resources.

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and specialized security solutions and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help over 220,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.


[1] The survey covered 19 countries: Brazil, Chile, China, Colombia, France, Germany, India, Indonesia, Japan, Kazakhstan, Mexico, Russia, Saudi Arabia, South Africa, Spain, Turkey, UAE, UK and USA. All respondents were IT & IT security engineers at Manager+ level working for SMEs with 100+ employees, or Enterprises with more than 1,000 employees.



Source link

Previous Post

Ukrainian Pilots Start British-Led F-16 Training in Denmark

Next Post

WIRED’s 11 Noteworthy Long-form Stories of 2023

Next Post
WIRED’s 11 Noteworthy Long-form Stories of 2023

WIRED's 11 Noteworthy Long-form Stories of 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

G7 foreign ministers’ statement on the escalation of violence in the eastern Democratic Republic of the Congo

G7 foreign ministers’ statement on the escalation of violence in the eastern Democratic Republic of the Congo

1 year ago
New report uncovers Congo Basin’s hidden $23 trillion untapped green goldmine

New report uncovers Congo Basin’s hidden $23 trillion untapped green goldmine

4 months ago
Top 10 African countries with the highest rice imports

Top 10 African countries with the highest rice imports

1 year ago
Mass job cuts at Lesotho’s diamond mines expose fragility amid escalating U.S. trade rift

Mass job cuts at Lesotho’s diamond mines expose fragility amid escalating U.S. trade rift

6 months ago

POPULAR NEWS

  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • The world’s top 10 most valuable car brands in 2025

    0 shares
    Share 0 Tweet 0
  • Top 10 African countries with the highest GDP per capita in 2025

    0 shares
    Share 0 Tweet 0
  • Global ranking of Top 5 smartphone brands in Q3, 2024

    0 shares
    Share 0 Tweet 0
  • When Will SHIB Reach $1? Here’s What ChatGPT Says

    0 shares
    Share 0 Tweet 0

Get strategic intelligence you won’t find anywhere else. Subscribe to the Limitless Beliefs Newsletter for monthly insights on overlooked business opportunities across Africa.

Subscription Form

© 2026 LBNN – All rights reserved.

Privacy Policy | About Us | Contact

Tiktok Youtube Telegram Instagram Linkedin X-twitter
No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • LBNN Blueprints
  • Quizzes
    • Enneagram quiz
  • Fashion Intelligence

© 2023 LBNN - All rights reserved.