Shadow IT. Dangerous or an opportunity?

4:21 · Watch on YouTube ↗

Transcript 752 words · about 5 min to read

Auto-generated captions from YouTube, not hand-corrected, so names and technical terms may be imperfect. The video is authoritative.

I saw a headline recently talking about Shadow it and how it was good for careers but not good for business (link in the description) and it got me thinking about Shadow it because Shadow it has always been there started back when I still had here with people taking floppy discs home in order to be able to work on things at home that they really ought to have been working on at work it carried on with things like the internet and the rise of AWS we saw

individual developers using AWS accounts because corporate it couldn't provide them a development environment and progressed onwards we've seen Dropbox and most recently we've seen the rise of large language model AIs like chat GPT freely available anybody can use it that means that the person using it is probably the product and so information submitted into chat GPT gets used to train GPT and we've seen leakage of corporate data that's uh Ur through this and this is why this Shadow it is a risk to business it's our

data and our business processes that are dependent on something that is not a sanctioned it product uh one of the things that I have as a perspective on this is that shadow I is always going to be here and it can be a way of identifying how we an IT are failing to service the business that is our whole purpose for existing if business units feel or staff and business units feel that they can't achieve what they want using sanctioned IT services and have to turn

to unsanctioned Services it probably means we're doing something wrong possibly we're not delivering the right Services possibly we haven't told them that we're delivering a perfect service for their needs so I definitely have this perspective that shadow it is not something that should be ignored swept under the bushes uh or treated as a a punitive punish M kind of uh situation where you're punished for using unsanctioned it if you punish people for doing something that that requ is enabling them to complete their job they're likely

to Simply hide the fact they're using it or hide it better I like a very open discussion around it and the use of non-sanctioned it products because essentially these tools are a risk to a business about our business processes and our data and it's a business decision to take that risk or not to accept that risk now if we haven't got any idea that these unsanctioned tools are being used we have no idea what our risk is but if we have a culture of openness to

discussion that we might be using unsanctioned it tools they might be a part of a business process that requires them we can then start managing that risk and of course follow that with some education around what the risk is and if there are sanctioned it tools that can be used to fulfill the requirement some education about those as well of course it could EXP Expos us to recognizing that there are Technologies on the horizon that we should be considering using AWS is no longer just a

tool that some developer or some in some business unit is using it's often a significant corporate it environment that is now a sanctioned it environment and I saw the same thing with virtualization my first uh esxi host was a machine I was given to build a management server so I built a virtualization host and ran the management server one of the year widespread adoption of some of these Technologies follows others not so much but it is useful to have that open discussion around what shadow it

business units are using and why they're using them and to have some conversations around those risks because managing those risks choosing to take risks is not an IT decision it's a business decision risk is a part of business and it is normal to choose which risks to take we and it are really the implemented of the policies and decisions that are being made by business we will also usually be people informing them of those risks and how they can be managed I'm Alastair Cooke stay tuned

to the CTO advisor for more CTO dose also stay tuned to the CTO advisor website and of course the Futurum group website as well I'll see you on the next do