What is Shadow IT? Special circumstances during the summer vacation period
Basic Concepts of Shadow IT
Shadow IT refers to IT equipment and cloud services used by employees for work without being aware of and managed by a company's IT department.
Typical example:
- Personal work file sharing in Google Drive
- Team contact on Slack or Discord that is not approved by the company
- Work email access on personal smartphones
- Operational efficiency using free software
Why Shadow IT Increases Dramatically During Summer Vacation
1. Diversification of Work Environments
During the summer vacation period, the place where employees work changes significantly.
Continuing to work in a resort area, working remotely from home, and working while caring for children can create a situation that is very different from a normal office environment.
2. Reduced IT support
IT personnel also take time off, which reduces emergency support systems.
Formal approval for new tool deployment is not received in time, and employees are more likely to choose alternatives at their own discretion.
3. Employee Psychological Factors
There are an increasing number of cases where carelessness that "it's okay because it's temporary" or impatience to continue business leads to taking measures that would normally be avoided.
Typical Shadow IT Scenarios During Summer Vacation
Scenario 1: "Emergency Response from Family Destinations"
The sales manager was traveling with his family when an emergency case occurred from an important business partner.
Let's consider a case where you need to respond using the hotel's Wi-Fi.
- Check your business email on your personal smartphone: Leave your company-provided device at home
- Sensitive data access on hotel free Wi-Fi: risk of information leakage in unencrypted communication
- File sharing with personal cloud storage: Share proposals with Google Drive
- Writing on a child's tablet: work on a shared family device
Risk Details:
- Data leakage: Sending sensitive information in unencrypted communication
- Malware infection: Business access on unmanaged devices
- Account takeover: Stealing login credentials via weak Wi-Fi
Scenario 2: "System Failure Response During the Obon Holiday"
Many IT personnel experienced access to critical systems while returning home
This is a case where a small number of employees on site need to respond.
- Teams calls on personal phones: Use personal lines with dead batteries on company-provided mobile phones
- System access on family PCs: Admin access on old PCs at home
- Information sharing with free tools: Password sharing on LINE, sending system settings on WhatsApp
- Emergency code fix on personal GitHub: Using personal accounts with legitimate repository access permission issues
In these cases, it's easy to skip the usual security steps due to the urgency, which creates a significant risk.
Specific Risks Posed by Summer Vacation Shadow IT
1. Data Breach and Information Breach Technical Risks:
- Plaintext data transmission over unencrypted public Wi-Fi
- Generation of unmanaged data due to the storage of corporate data in personal accounts
- Access on personal devices with delayed security updates
Specific examples of victims:
- Storing and leaking customer information lists to personal Google Drive
- Information leakage due to sending important contracts to messaging apps
- Stealing sales strategy materials via hotel Wi-Fi
2. Malware Infection and System Breach
The risk of malware infection on shared family PCs, malware disguised as business efficiency apps, and infection via tourist information sites at travel destinations increases.
These infections can have serious consequences, such as intrusion from personal devices into corporate networks, encryption and ransom demands of business data, and secondary infection of business partners.
3. Regulatory and Compliance Violations
There is a risk of violating the Personal Information Protection Act due to the processing of personal information on devices that are not properly controlled, improper handling of confidential information in the financial and medical industries, and poor management of overseas customer data such as GDPR and CCPA.
Shadow IT Measures During Summer Vacation
Preparation: Preparations Before Summer Vacation
1. Conducting a Risk Assessment
We identify the need for business continuity during the summer vacation, remote access requirements, analyze employee work patterns, and conduct a fact-finding survey of existing Shadow IT.
As for the implementation procedure, it is important to proceed step by step with the implementation of employee questionnaires, system access log analysis, risk assessment and prioritization, and formulation of countermeasure plans.
2. Developing a Secure Remote Access Environment Technical Measures:
- Enhanced VPN connection: multi-factor authentication, split tunneling settings
- Zero Trust Network: Device authentication, application-level access control
- Cloud security: comprehensive protection with CASB, SWG
- Endpoint protection: Enhanced MDM and DLP capabilities
Operational measures:
- Approved tool list: Specify the tools and services available during the summer vacation
- Emergency response procedures: Contact system and response flow when the IT department is absent
- Data backup: Regular backup and recovery testing of important data
3. Employee Education and Awareness Activities
We provide education using e-learning, video manuals, and checklists on summer vacation-specific risk descriptions, specific examples and dangers of Shadow IT, how to use approved tools, and incident reporting procedures.
Monitoring and Management During the Period
1. Real-time Monitoring System
Monitor for unusual access patterns, unauthorized applications, and signs of data exfiltration.
Leverage tools such as SIEM, UEBA, and DLP to maintain 24-hour monitoring.
2. Incident Response System
Build a rapid response system by forming an emergency response team, establishing an escalation system, and leveraging external vendors.
It's important to clarify step-by-step response procedures, from incident detection to root cause analysis and permanent action.
Inspection and improvement after summer vacation
1. Shadow IT Fact-finding Survey
Perform a detailed analysis of unauthorized tools and services used during the period, the occurrence of security incidents, changes in employee behavior patterns, and system access logs.
We provide a comprehensive understanding of the actual situation through employee interviews, technical surveys, and third-party audits.
2. Continuous Improvement Activities
Based on the Plan-Do-Check-Action cycle, we will continue to plan for the next long vacation, implement and pilot improvement measures, measure and evaluate the effect, and implement and standardize them in earnest.
Measures by Company Size
Measures for Small and Medium-sized Businesses
As an efficient measure with limited resources, it is effective to maximize the use of the security functions of Microsoft 365 and Google Workspace, outsource the 24-hour monitoring system using external SOC services, and use free and low-cost security tools.
Measures in Large Companies
A comprehensive governance system is required, including continuous management of dedicated personnel by establishing a dedicated Shadow IT team, introducing an automatic detection system using AI and machine learning, and establishing a unified management system including overseas bases.
Summary: How to Deal with Shadow IT Wisely During Summer Vacation
Shadow IT during the summer vacation period is not practical to completely eliminate it.
The key is to understand the risks and control them properly.
Success Points:
- Realistic policy development: feasible rules that take into account the actual work style of employees
- Balance between technology and operation: A comprehensive approach not only in technical measures but also in terms of operation and education
- Continuous improvement: Continuous review and improvement, not just a one-time measure
- Employee cooperation: Providing safe usage, not prohibition
The summer vacation period is also a valuable opportunity to understand the actual situation of Shadow IT, which is not visible in normal times.
Let's use the knowledge gained through this period to build a more effective security system.
Colorkrew Security provides integrated monitoring of Zero Trust security.
Leverage Microsoft products to detect and respond to unusual access.
If you are a company that would like to help you manage the security risks of your employees, please contact us.