Shining light on dark data, shadow IT and shadow IoT

The answer is: Yes, they are.
If you’re an IT pro, security specialist, c-level executive, manager or leader in your organization (and if you’re reading this, you almost certainly are), people in your organization are hiding information from you, and also installing hardware and software and using cloud services without company authorization.
These hidden resources represent a massive and growing security risk. Gartner says that by the end of next year, one-third of all successful attacks on enterprises will take place on shadow IT resources.
And these resources can create other, less obvious problems as well.
Here’s what’s new and urgent about dark data and shadow IT, with an extensive look at shadow IoT — and what to do about it.
Dark data is unstructured, untagged, unclassified and unknown to IT. We’re talking about dark documents, shadow spreadsheets, secret censor logs and other content.
Are employees keeping you in the dark?
The answer: Yes, they are.
If you’re an IT pro, security specialist, c-level executive, manager or leader in your organization (and if you’re reading this, you almost certainly are), people in your organization are hiding information from you, and also installing hardware and software and using cloud services without company authorization.
These hidden resources represent a massive and growing security risk. Gartner says that by the end of next year, one-third of all successful attacks on enterprises will take place on shadow IT resources.
And these resources can create other, less obvious problems as well.
Here’s what’s new and urgent about dark data and shadow IT, with an extensive look at shadow IoT — and what to do about it.
Dark data is unstructured, untagged, unclassified and unknown to IT. We’re talking about dark documents, shadow spreadsheets, secret censor logs and other content.
Much of this data resides on public cloud services or on mobile devices or both.
A Veritas Technologies survey of IT decision makers and data managers in the U.K. found that almost half of the data at organizations in that country is “dark data” — unclassified or untagged. That means this data, which includes assets valuable to the company, can’t be managed, protected or accessed the way it should be.
Cloud data is a special problem. Many falsely believe that data protection and regulatory compliance for data stored on cloud service providers is the responsibility of the provider, according to a Veritas report.
Dark data is not a black-and-white issue. It’s very common, for example, for employees to email a document to themselves to work from home. The copy on the network is authorized, but the copy on Gmail and the copy on their home MacBook are dark data. They still contain the same sensitive information; they’re just beyond the protection of the organization‘s security systems. Worse, they may modify the document at home, email it back to work and replace the authorized copy with one that could now be infected with malware.
Dark data creates four problems. The first is that it represents an enormous opportunity for cyberattackers. Because it’s unknown, it’s unprotected. Hackers may use dark information to gain insights into the organization, its employees, the location of assets and who knows what else.
The second is that dark data may contain organizational insights that never reach leadership. In aggregate, the company is operating with 100 percent of the data. But if half the data is dark, then leaders are basing decisions on only half the data that should be available to them.
The third is that dark data is wasteful and inefficient. Without knowledge about or access to a necessary data set, employees may re-create information that already exists, duplicating effort.
And finally, dark data is illegal. Or, at best, dark data complicates regulatory compliance with Sarbanes-Oxley, GDPR and other regulations.


