Security pros admit to using shadow SaaS

Research reveals one in ten security professionals admit to having suffered a data breach as a result of Shadow SaaS, but still regularly use unauthorised tools.

  • Friday, 12th July 2024 Posted 1 year ago in by Phil Alsop

Next DLP has revealed that nearly three quarters (73%) of security professionals admit to using SaaS applications that had not been provided by their company’s IT team in the past year. This is despite the fact that they are acutely aware of the risks, with respondents naming data loss (65%), lack of visibility and control (62%) and data breaches (52%) as the top risks of using unauthorised tools. Adding to this, one in ten admitted they were certain their organisation had suffered a data breach or data loss as a result.

A survey of more than 250 global security professionals, conducted at RSA Conference 2024 and Infosecurity Europe 2024, also revealed that despite having a laissez-faire attitude towards Shadow SaaS, security professionals have taken a more cautious approach to GenAI usage. Half of the respondents highlighted that AI use had been restricted to certain job functions and roles in their organisation, while 16% had banned the technology completely. Adding to this, 46% of organisations have implemented tools and policies to control employees’ use of GenAI.

“Security professionals are clearly concerned about the security implications of GenAI and are taking a cautious approach,” explains Next DLP’s Chief Security Officer, Chris Denbigh-White. “However, the data protection risks associated with unsanctioned technology are not new. Awareness alone is insufficient without the necessary processes and tools. Organisations need full visibility into the tools employees use and how they use them. Only by understanding data usage can they implement effective policies and educate employees on the associated risks.”

The research also provided a snapshot of how security professionals view their organisation’s training and overall understanding of the risks of Shadow SaaS:

40% of security professionals do not think employees properly understand the data security risks associated with Shadow SaaS and AI.

Yet, they are doing little to combat this risk. Only 37% of security professionals had developed clear policies and consequences for using these tools, with even less (28%) promoting approved alternatives to combat usage.

Only half had received guidance and updated policies on Shadow SaaS and AI in the past six months, with one in five admitting to never receiving this.

Additionally, nearly one-fifth of security professionals were unaware of whether their company had updated policies or provided training on these risks, indicating a need for further awareness and education.

“Clearly, there is a disparity between employee confidence in using these unauthorised tools and the organisation’s ability to defend against the risks,” adds Denbigh-White. “Security teams should evaluate the extent of Shadow SaaS and AI usage, identify frequently used tools, and provide approved alternatives. This will limit potential risks and ensure confidence is deserved, not misplaced.”

Arrow Electronics triumphs at ChannelWatch Awards 2025

Posted 3 days ago by Aaron Sandhu
Arrow Electronics secures four prestigious recognitions, cementing its leadership in the IT distribution sector.
Espria and Sophos unite IT and finance leaders for a cyber simulation event on 7th October at Churchill War Rooms.

Westcon-Comstor takes strides towards carbon neutrality

Posted 2 weeks ago by Aaron Sandhu
Westcon-Comstor's latest sustainability report shows significant progress in renewable energy adoption and emission cuts. The company eyes a...
Zyxel Networks introduces a PAYG billing model via its Circle platform, catering to the varying needs of MSPs and SMBs leveraging the Nebula cloud.
Nebula Global Services launches the Nebulab Verified™ Engineer Ecosystem, setting new benchmarks in engineering excellence and trust.
Abzorb launches a Mobile Masterclass to empower UK channel partners to integrate mobile as a core business offering.

Tool sprawl: The quiet culprit behind MSP burnout

Posted 1 month ago by Aaron Sandhu
A Heimdal study reveals how the proliferation of security tools overwhelms and exhausts North American MSPs, leading to significant operational...
StorONE's platform allows Storage Guardian to consolidate its infrastructure and boost efficiency, dramatically reducing its data centre footprint.