Shadow IT becomes shadow attack surface
Systems adopted without going through anybody are still systems, and they are still yours when something goes wrong.
The team that signed up for a tool with a corporate card, the department running its own server, the integration somebody built to save time. None are visible to security, all hold company data, and none are patched, monitored or inventoried. Prohibiting it drives it further underground; the practical answer is making the sanctioned route faster than the unsanctioned one.
More on Attack surface management
- The Internet sees what you expose, not what your CMDB remembersCounted three. Answering six
- A new subdomain can create a new perimeterThe fence just got longer
- Acquisitions merge attack surfaces before inventoriesThe wire arrives first
- Internet exposure is a property that changesThe tide does not read your map
- A forgotten test system can be a production entry pointThe shed is still joined to the house
- Third-party hosted assets still carry your nameTheir building, your name over the door
