Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Security Needs Versus Worker Accessibility: The Balancing Act In Evolving Technology
Articles

Security Needs Versus Worker Accessibility: The Balancing Act In Evolving Technology

Alastair PooleyBy Alastair PooleySeptember 12, 2019Updated:December 30, 20215 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Over the last decade, there has been a significant shift in how we work. The explosion of cloud and “as-a-service” technologies has made it easy for anyone within an organisation to both purchase and use preferred applications, often without intervention from IT. Whilst many cloud tools enable enhanced levels of sharing and collaboration, an improvement which has transformed how we all work, it has also affected the dynamic between meeting user needs and ensuring IT department control. This has led to a massive increase in access to technologies not provided by IT, which brings additional challenges to any business wanting to control security and operational risks. A responsive IT department will recognise that they need to enable workers to, wherever possible, access the applications they wish to work with without putting the organisation at risk. A “can do” attitude will encourage workers to continue to involve IT departments. This is critical for businesses and they need expertise from IT when it comes to security, compliance and cost management. 

The relationship between workers and technology

Workers can be significantly invested in the technology they use every day, and those emotional ties can put them at odds with IT and, perhaps more worryingly, the best interests of their organisation. According to a recent survey of global workers, 41% of employees will avoid involving IT when seeking to access to professional software and applications that they feel are essential to doing their job. In addition to this, of those responding to our survey, most have accessed work assets on their personal devices.

Technology is being democratised and decisions are being decentralised. Yet, as with any systemic transfer of power, an organisation’s IT infrastructure can quickly descend into chaos if employees, IT teams and decision-makers don’t collaborate. Unapproved or unauthorized cloud-based applications may open the organisation’s corporate network and sensitive data open to cybercriminals. It is clear that IT professionals must find ways of working in ways which are seen to be supportive to workers and their preferences. It is my view that the negative term “shadow IT” should no longer be used and instead this expansion of technology should be seen as the new normal. 

The impact of seniority vs rank and file

To effectively manage today’s workforce, business leaders need a comprehensive understanding of the different groups of workers and how to best utilise their knowledge and experience.

When looking solely at rank within the organisation, managers or higher are almost twice as likely to use unauthorised professional or personal software or applications. A staggering 93% of executives acknowledged that such behaviour causes issues for the business, but more than half (57%) avoid IT when accessing professional software and apps. Entry-level employees surfaced as the most well behaved, with 38% reporting they never access software or applications on their work device without IT’s consent.

Even though executives admit that they should know better, knowledge clearly isn’t enough. When faced with such risky technology behaviour, visibility and understanding of the scope of the problem is a critical step towards identifying a feasible and efficient solution. 

Preparing the workforce of the future

Broadly speaking, different generations perceive technology, and how they use it in different ways. So called millennials have grown up with technology and are often more adept at incorporating technology into their personal and professional lives than previous generations. These “digital natives” are moving into leadership positions (and more importantly, buying decision roles).

Having grown up with computers, smart devices and a largely connected world this generation naturally expects workplace technologies to mirror the technologies they use in their educational and personal experiences. 81% of millennials admit they have used or accessed unapproved technology or assets on their work device without ITs permission. Millennials are therefore almost twice as likely to adopt unauthorised technology compared to other generations.

Millennials are also exponentially more emotional about asking for permission to access software in the workplace. Compared to older workers, they are more than four times as likely to feel it is beneath them and over three times more likely to believe it is an outdated concept. 

Tech is only part of the issue 

To help manage employee behaviour and encourage proper device usage, best practice would be to rely on a combination of approaches including:

  1. Security awareness education: ongoing training and communication to your organisation’s workforce are required to communicate risks such as browser hijacking, ransomware and malicious software downloads. This helps to educate staff on what is appropriate and what crosses the line. It’s important to make this training tangible and avoid hours of compliance style videos.
  2. Visibility of the organisation’s IT estate: it is important that businesses understand what employees actually use day-to-day and week-to-week in order to spot both unauthorized usage and software installed on end-user devices. If there is an unapproved tool which is being widely used across an organisation, it may be worth the IT team considering investing in the tool or investigating and providing an authorized alternative.
  3. Implement active controls: through the use of unauthorized or unapproved technology, employees can create security issues for an organisation. It is therefore critical that security remains strong. Review your active controls at the network perimeter or with anti-virus vendors to try and prevent malicious downloads or employees visiting known piracy sites.

To summarise: In today’s digital environment, it is clear that our relationship with work and technology has changed and worker expectations are increasing. As the guardians of both the security and reliability of their organisation’s technology ecosystem, it is up to IT to find a balance between empowering a new, more demanding workforce whilst also serving and safeguarding the business’s needs.

Alastair Pooley

Chief Information Officer

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    The Real Cost of Inconsistent Third-Party Access

    December 18, 20255 Mins Read

    What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

    August 7, 20256 Mins Read

    The Evolving Importance of Identity Governance in FinTech

    July 10, 20258 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}