Insider threats represent one of the most significant risks to organizational security, encompassing both malicious actors and unintentional mistakes made by employees within the network. Shadow IT — the unauthorized use of devices, software, or services outside of established IT processes — is a closely related risk that can quietly undermine an organization's security posture.
Insider Threat
One of the things that I have found is that what puts the company more at risk than anything else is insider threat.
When it comes to threats, we have both internal threats and external threats. External threats are those threats that are found outside the organization, and we have got to protect our perimeter and have a really strong perimeter against those external threats.
But there are internal threats as well. There are times when there is somebody in the company that is actively trying to hack that network or cause harm in that network. An internal threat could be intentional or unintentional.
An intentional threat would be something like a black hat hacker who is sitting inside of your network and is actively working against the company. There are cases where there has been some sort of espionage, where somebody has been carrying out attacks within the company and they are trying to harm the company. Maybe it is because they are working for somebody else and they are carrying out some sort of espionage. Or maybe it is because they are mad at the company and they feel like this is the way they could get back at the company.
But there is also the unintentional. The unintentional are those that are in your organization that are posing some sort of threat within your organization for some purpose, for some reason. And then there is something called shadow IT, which is kind of in between - something where maybe they know better, but they are still causing a bit of a threat. Maybe it is somewhat innocent, but it is still causing a problem within your network.
Somebody that is within your network could have some unintentional threats. One example might be that maybe they are configuring a piece of equipment. Maybe it is this server, and they misconfigure it, and that server has access to the outside world, and now an attacker can leverage that to get into the network. So there are some misconfigurations that can happen.
Or maybe this is just a regular user on the network, and then this adversary uses social engineering to trick this user into giving access to the rest of the network to that adversary. So that is another example of that.
There are different examples of where this user can pose a threat to the network unintentionally. They are not doing it maliciously or anything like that, but it poses a threat to the network.
An internal threat is a malicious or negligent individual within an organization.
Another internal threat is called shadow IT. This is when somebody on the network starts using a service or starts using equipment. Maybe they purchase equipment that they are not supposed to have on the network, but they put it on the network.
Shadow IT is the use of a device, software or service without IT's knowledge. Essentially, IT has processes in place to safeguard the company, and when a user goes outside of those processes, then that becomes shadow IT and becomes a problem, because now the proper level of security is not placed within that process, within that device or software or service that has been implemented.
You will typically see me have a cowboy hat that kind of represents shadow IT. The reason for this is because the cowboys in the Old West were kind of loners. They did their own thing, they did what they want, they just did it without regard to other people or other things, because they were out on the range. They did not really have those boundaries that most of the people within society had, so they were considered kind of rebels and just did their own thing. That is the same thing with shadow IT: those employees kind of do their own thing. So I represent it with a cowboy hat.
An example of shadow IT is that maybe there is a process to purchase equipment such as printers, and you have to go through the IT department to purchase these printers. The reason for that is because IT might have extra on hand, so the company does not need to purchase a new printer because they can send you one they already have. Or IT might know of certain models that they would like to go with, certain models that really work well. Or maybe they want you to go with laser jet or inkjet, or they have specific parameters for what needs to be purchased. Maybe there are issues with supporting certain pieces of equipment. So by going through IT, you get a better model for the company, one that is designed for the company.
The problem with this is that going through IT sometimes can be slow. You have got to get purchase approvals, and IT has to make sure it is the right model and has to go through their steps, which can slow down the process. This can frustrate the end user and prompt them to just go and buy the equipment and set it up.
Their motivation is not terrible. They are getting stuff done, they are getting work done, so they are doing it for the company. They realize that if I just go and purchase this and charge it to the company credit card, I can set it up and we do not need to really bother IT and it can work fine. But the problem is that it goes outside the security parameters, outside the processes, and actually can cause a lot of harm to the company.
In their thought, it is no harm done. But what I have experienced is that I have had people take their personal email account, go and subscribe to a service and put it on the company card, and then what happens is when that person leaves the company, no one has access to those services, and the company goes offline because the credit card has been cancelled. So it has been done outside the parameters of IT, and now the proper controls have not been put into place, and it causes problems.
So somehow we need to be able to identify when shadow IT is happening within the company and stop it from happening.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →