Posts

Showing posts with the label Governance

Shadow IT Explained: Discovery, CASB and Shadow AI for Security+

Shadow IT is technology used inside an organization without the approval, knowledge, or oversight of the IT department. A team signing up for a project management SaaS on a corporate card. An engineer spinning up a cloud instance on a personal account. A department sharing files through a consumer storage service because the sanctioned one is slow. Shadow IT is the only item on CompTIA's threat actor list that involves no attacker. The people creating the risk are trying to do their jobs. That is what makes it genuinely different from the other threat actor types , and why treating it as a discipline problem produces worse outcomes than treating it as a signal. Why It Happens Almost always for the same reasons, and none of them are malice: The approved tool is inadequate or genuinely unpleasant to use. Procurement is slow. A tool needed this week cannot wait three months for review. IT said no without offering an alternative. Cloud services are trivially easy to a...