Arcanum’s Festive Stories – Ghosts in the machine: Shadow IT

Arcanum’s Festive Stories – Ghosts in the machine: Shadow IT

In the fourth of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.

In Dickens’ A Christmas Carol, Scrooge is haunted by spirits he cannot see, warnings of consequences lurking in the shadows.  Today’s organisations face similar unseen threats: Shadow IT.  These are the unsanctioned apps, devices and cloud services employees adopt without approval, often with good intentions, but with dangerous consequences.

 

According to UK government stats, over 60% of businesses admit they have no visibility into all SaaS tools employees use, making Shadow IT a silent epidemic.  Shadow IT refers to technology used outside official IT governance, think personal Dropbox accounts for file sharing, unauthorised SaaS tools, or even rogue IoT devices.  Like the Ghost of Christmas Past, these tools often start innocently but return to haunt organisations when vulnerabilities emerge.

 

It’s human nature to look for convenience and speed.  When official systems feel slow or restrictive, people turn to alternatives.  But without oversight, these shortcuts create blind spots in security monitoring, compliance and data protection, so there can be real world consequences.  For example, during COVID-19, NHS staff in Lanarkshire widely adopted WhatsApp for clinical communication. This led to confidentiality breaches, including an ICO reprimand for breach of UK GDPR Articles 5, 25, and 32 after patient data was shared over WhatsApp more than 500 times.

 

It’s not just the Public Sector where shadow IT abounds.  Last year Scattered Spider AKA ShinyHunters accessed customer cloud environments hosted on a cloud-based data warehousing platform provided by Snowflake Inc, an American data storage based in Montana.  It seems that the attackers exploited credentials stolen from personal devices used by third-party contractors for both work and personal tasks without proper security oversight, the classic description of Shadow IT.

 

The lesson from both examples is that Shadow IT assets, personal laptops, unapproved SaaS tools etc are a critical attack surface. Without visibility and control, organisations cannot enforce MFA or monitor for compromise.  Shadow IT is the Ghost of Breaches Yet to Come, silent, invisible, but inevitable if ignored.  Shine a light on these spectres before they drag your organisation into a Bleak House of compliance failures and data leaks.

 

But there are ways to exorcise these ghosts:

 

  • Discover: Use monitoring tools and network scans to identify unauthorised apps and devices.
  • Educate: Train staff on risks and provide secure alternatives.
  • Enforce: Implement policies and technical controls like Network Access Control and Application Whitelisting or even a Zero Trust Network architecture.
  • Engage: Make IT approachable, employees turn to Shadow IT when official channels feel slow.

If shadow IT is a concern or you would like help to find out exactly what is on your network, give us a call.

Read more as part of the Arcanum Festive Stories series:

Arcanum’s Festive Stories – A Dickensian Tale of Cyber Peril in the Age of Legacy

Arcanum’s Festive Stories – Don’t Wait for the Ghost of Breaches Past – Incident Response Readiness

Arcanum’s Festive Stories – Fagin’s Digital Pickpockets – The Art of Phishing & Social Engineering