During the turbulent events of recent months, ensuring business continuity without increasing risk has been the big challenge for CISOs and IT managers. Many organisations were faced with an acid-test of their cloud readiness and general operational resilience, and some had to make major changes to established business practices overnight.
Unsurprisingly mistakes were made in some cases, and often with the best of intentions. Individual managers and knowledge workers did their best to remain productive and effective in their roles under dramatically altered circumstances, and while many attempts were noble in effort, inevitably some temporary solutions were far from ideal, and so may even have undermined organisational intent — involving as they did, the use of ‘shadow IT’: individually sourced and implemented applications and programmes, running outside the official business environment, and never intended for enterprise use.
Shadow solutions to the rescue?
As Sébastien Valentini, Chief Technical Officer at Kurmi, explained, “people did not use shadow IT for pleasure or to annoy
[caption id="attachment_30486" align="alignright" width="200"]
Sébastien Valentini[/caption]
IT/security teams. They did it because they had to, to answer the company or customers' requests to provide service continuity during the lockdown. The context may have accelerated these risks because while it increased the need for collaborative or communication tools, it broke down certain barriers between private and professional life. Some official tools of the company may not been available remotely or it may have been more difficult to use due to VPN access over personal Wi-Fi / internet connections. By comparison, tools designed for personal used, generally cloud-based, are immediately available, accessible at any time, from anywhere.”
The intervention of unapproved apps and tools running within the business can easily break carefully-planned security protocols and systems, in application stacks chosen to satisfy requirements in secure and compliant environments.
Outside the secure and managed environment
[caption id="attachment_30487" align="alignleft" width="200"]
Sébastien Le Lourec[/caption]




