TechKnowSurge
VideoSecurityFree

Bloatware

Legitimate software can still create serious problems on enterprise networks, from resource drain to fragmented communications and unsanctioned IT deployments. Cybersecurity professionals need to account for these risks even when no malware is involved.

Complete this video to capture a CTF flag worth 1 point.

About this video

Cybersecurity professionals must account for risks that go beyond malware, including the problems created by legitimate software running without organizational oversight. Crypto mining applications are one example: though not inherently malicious, they consume significant system resources and energy, reducing productivity and creating operational costs when installed on company-owned devices. The software itself may be entirely lawful, but its presence on a business network introduces concerns that still fall within the scope of security and IT governance. A more systemic version of this problem emerges through shadow IT, the practice of individual teams or departments adopting tools outside of official IT approval. When multiple departments independently deploy different messaging platforms, for instance, the result can be a fragmented communication environment where information fails to reach the right people during critical incidents. Licensing exposure, inconsistent security standards, and an inability for IT to provide reliable support are additional consequences that compound over time. Regardless of whether software is malicious by design, organizations need enforceable policies and visibility into what is running across their networks. Keeping legitimate but unsanctioned applications in check is as much a part of enterprise security as defending against external threats.

What you'll learn

What's covered

Enterprise Software Concerns

Key terms

Shadow IT
The use of unauthorized software, systems, or services within an organization without IT department knowledge or approval. Shadow IT creates security blind spots because unmanaged assets fall outside standard patching, monitoring, and access controls.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Software Governance
The set of organizational policies and controls that regulate which software applications are approved, deployed, and supported on enterprise systems.

Topics

Bloatware Shadow It Software Governance Endpoint Security Enterprise Networking Network Security

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →