Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How To Keep Shadow IT From Costing You In The GDPR Era
Articles

How To Keep Shadow IT From Costing You In The GDPR Era

ISBuzz TeamBy ISBuzz TeamNovember 15, 2018Updated:December 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Shadow IT — the use of IT systems within an organization without the knowledge or approval of corporate IT — has long been an issue for businesses across industries. From risking the unauthorized leaking of proprietary information to exposing unintended attack vectors to hackers, shadow IT can subvert the efforts of an IT department to keep a company’s systems secure.

Now, with the newly imposed regulations of General Data Protection Regulation (GDPR) and more legislation on the horizon, the fallout of an uncontrolled shadow poses an even greater risk — fines up to four percent of a businesses’ revenue in penalty for even a single infraction. Now, more than ever, it is imperative to understand how ‘unapproved software’ impacts your organization. These can range from the benign use of a personal Gmail account, to the heavy usage of efficiency platforms such as Trello or Asana.

While these tools might boost employee productivity and improve overall team communication, their unauthorized use is problematic. Businesses today need to balance the constraints of enabling employees to perform their best while complying with regulations. Using a SaaS platform requires clarity into how data is stored and processed to ensure it meets the strict guidelines set forth by GDPR. When it comes to controlling shadow IT, here are four steps any business can take to make sure that shadow IT doesn’t drag business down:

  1. Putting Process in Place

The first step in taking control of your IT is to promote standardization. Regardless of whether or not GDPR requires your company to assign a data privacy officer (DPO), having an established chain of command — an entity or hierarchy from which all decisions on IT will emanate — to maintain responsibility for necessary changes taking place efficiently. Shadow IT often arises due to a company’s inability to provide employees with the tools they need, when they need them. Whether DPO, CIO or otherwise, a person dedicated to a leadership position will work to discern current practices, establish effective guidelines, implement necessary tools and perform enforcement measures moving forward.

  1. Shine a Light on Shadow IT

The next step is to perform a full audit of all technology being used by your employees, which may take more than simply asking. Examine network traffic and identify any external tools that employees may be using without consent. In this modern era of cloud-based SaaS, employees may not even realize that the tools they are using are a threat. This is not, however, an attempt on your part to discipline employees for using external tools, but rather to identify what tools are being used and why. Shadow IT most often exists to fill in the gaps where authorized tools fail to provide needed functionality.

If employees are relying on Dropbox, for example, you may need to identify an enterprise file sharing solution (EFSS) that meets your needs and implement it companywide. Your job here is to assist your employees in performing their duties, and that may come first and foremost by observing their current methods, rather than simply imposing top-down restrictions and forcing them to use tools that fail to meet their needs.

  1. Set Standards

Once you have properly assessed your employee needs and taken a full inventory of current practices, you need to make some decisions. As we noted, shadow IT arises out of need, and once those needs are identified, they need to be met with standardized solutions that are company-based. In choosing these solutions, you should strive for a balance of privacy and operational tools, but don’t make it too complicated. If your tool set is too confusing for the end user, mistakes will be made and you may find yourself in violation of GDPR guidelines. In this post GDPR era, enterprise organizations must make an overreaching decision to restrict personal information and employ solutions that offer mechanisms for control of information sharing. One simple step you can take in choosing tools is to ensure that they are themselves GDPR compliant.

  1. Educate, Enforce and Empower

Finally, proper training is key in the GDPR era. Employees need to be made aware of implications of these new regulations and what they mean for their workplace practices. Employees can take care to handle information more carefully if they understand the implications of doing otherwise. Beyond education, however, enforcement is also necessary. This means that employees require clarity around any IT sidestepping, what exactly unauthorized use is and how to go about asking for solutions that they want to use.

Long-standing No More

Shadow IT is no longer simply a security risk, but also one that can bring about severe financial repercussions to your business. With the strict regulations of GDPR, unapproved software and ill-informed users can damage your bottom line. To tackle this issue once and for all, now is the time to implement workplace guidelines that focus on the important threats while educating employees about their responsibilities to the bigger picture.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}