Shadow IT becomes shadow attack surface

Systems adopted without going through anybody are still systems, and they are still yours when something goes wrong.

The team that signed up for a tool with a corporate card, the department running its own server, the integration somebody built to save time. None are visible to security, all hold company data, and none are patched, monitored or inventoried. Prohibiting it drives it further underground; the practical answer is making the sanctioned route faster than the unsanctioned one.

More on Attack surface management