Feeds

You... (Sigh). You store our financials in a 'Clowds4U' account?

Survey shows biz unprepared for 'shadow IT' use

Gartner critical capabilities for enterprise endpoint backup

More than 80 per cent of employees use software that has not been signed off on for use by their employer, according to a new survey.

Stratecast and Frost & Sullivan asked 300 IT staff and 300 "line of business" (LoB) employees at large companies that employ at least 1,000 people in the UK, North America, Australia and New Zealand about the use of "shadow IT" in their businesses. It defined "shadow IT" as "SaaS applications used by employees for business, which have not been approved by the IT department or obtained according to IT policies".

The study (13-page/842KB PDF) found that 83 per cent of IT staff and 81 per cent of line of business staff have used at least one non-approved "software-as-a-service" (SaaS) application personally and added that it was likely that more than a third of all software within organisations has been bought and been put to use "without oversight".

"Thanks to the ease of access to Software-as-a-Service applications, even nontechnical employees feel comfortable and entitled to choose their software – and they are doing so in droves," the survey report said. "In many cases, IT departments and security officers are unaware of the extent of 'shadow IT,' and therefore unprepared to deal with it."

The survey responses suggested that companies may not be clearly communicating IT policies to staff, the report added.

"Both IT and LoB respondents indicate a broad range of policies [are in place]," the report said. "This reflects confusion in the market over the best way to approach the issue of shadow IT ... Responsibility for such confusion falls squarely on the company’s shoulders: you can’t expect employees to adhere to a policy that they are unclear about."

Employee's familiarity with certain software and slow, bureaucratic sign-off procedures for approved applications are among the main drivers behind widespread "shadow IT" use, the survey said.

"The top drivers cited by both LoB and IT respondents are related to gaining access to the right tools, fast," the report said. "Nearly half of respondents indicate a comfort level with their preferred software package. While whimsical personal preferences may play a role, it is equally likely that respondents’ familiarity with a package means they can avoid a learning curve and thus get their work done more quickly.

"Users also cite slow approval processes for new software, and inadequacies of 'approved' software."

Fewer than half of respondents said that they had "high concern" that their use of unapproved software would lead to sensitive commercial or personal data being accessed or stolen or accidentally exposed.

Fewer than a third of LoB staff surveyed raised "high concern" about whether their activity would place their company in breach of regulatory obligations, whilst just 40 per cent said that they had high concern about whether their company's reputation would suffer as a result of a security breach stemming from their use of unapproved software.

However, approximately 15 per cent of all employees have either experienced or perceived incidents such as malware infection, data loss or unauthorised or blocked access when using particular software packages, the report said. "Despite their experiences and expressions of deep concern, more than 80 per cent of respondents presumably feel justified in continuing to use the non-approved services without ensuring that protective IT policies are applied," the report said.

"IT and business leaders need to work together to create and support policies that enable employees to use the apps they need to be productive, with controls in place to protect data and minimise corporate risk," it said.

Copyright © 2014, Out-Law.com

Out-Law.com is part of international law firm Pinsent Masons.

Secure remote control for conventional and virtual desktops

More from The Register

next story
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
Microsoft: Azure isn't ready for biz-critical apps … yet
Microsoft will move its own IT to the cloud to avoid $200m server bill
Oracle reveals 32-core, 10 BEEELLION-transistor SPARC M7
New chip scales to 1024 cores, 8192 threads 64 TB RAM, at speeds over 3.6GHz
US regulators OK sale of IBM's x86 server biz to Lenovo
Now all that remains is for gov't offices to ban the boxes
Flash could be CHEAPER than SAS DISK? Come off it, NetApp
Stats analysis reckons we'll hit that point in just three years
Object storage bods Exablox: RAID is dead, baby. RAID is dead
Bring your own disks to its object appliances
Nimble's latest mutants GORGE themselves on unlucky forerunners
Crossing Sandy Bridges without stopping for breath
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.