Rogue SaaS Poses Security Nightmare

By Doug Barney

There have always been rogue end users -- that’s how PCs came to dominate in the first place. The cloud poses a bigger threat to IT as these apps and services are far harder to control.

McAfee is now warning of the onslaught of unapproved SaaS apps, and how they might cause data leakage and open the doors to hackers.

The results are stunning, but maybe not surprising when you think about it. According to the research, actually performed by Frost & Sullivan’s Stratecast division, over 80 percent of workers are using rogue SaaS tools while at work. And for IT workers, the numbers are even higher!

Like PCs decades ago, these SaaS apps fall under the notion of Shadow IT where users and departments take IT initiatives into their own hands. While a boon to productivity, the lack of IT control creates security, data leakage and compliance problems. The trick for IT is to try to be nimble enough to actually support, protect and manage these applications, making end users happy while keeping the enterprise safe. These rogue apps are part of what’s driving the SaaS market, which Frost & Sullivan believes is growing at a CAGR of 16 percent, and poised to hit $23.5 billion in 2017.

“There are risks associated with non-sanctioned SaaS subscriptions infiltrating the corporation, particularly related to security, compliance, and availability,” said Lynda Stadtmueller, program director of the Cloud Computing analysis service within Stratecast. “Without appropriate knowledge, non-technical employees may choose SaaS providers or configurations that do not measure up to corporate standards for data protection and encryption. They may not realize that their use of such applications may violate regulations concerning handling and storage of private customer data, leaving the company liable for breaches.”

The number one rogue SaaS app, Microsoft may be happy to hear, is Office 365 that is used by 9 percent of those polled, even outstripping LinkedIn and Facebook. While some may see unapproved app dangers as an idle threat, some 15 percent of those polled have had a liability or security event occur.

“With over 80 percent of employees admitting to using non-approved SaaS in their jobs, businesses clearly need to protect themselves while still enabling access to applications that help employees be more productive,” said Pat Calhoun, general manager of network security at McAfee. “The best approach is to deploy solutions that transparently monitor SaaS applications and other forms of web traffic, and uniformly apply enterprise policies, without restricting employees’ ability to do their jobs better. These not only enable secure access to SaaS applications, but can also encrypt sensitive information, prevent data loss, protect against malware, and enable IT to enforce acceptable usage policies.” 

Edited by Cassandra Tucker

MSPToday Editor at Large

Related Articles

Key Considerations Before Using Managed Network Services for IoT

By: Special Guest    2/24/2020

While the benefits of IoT managed services are easily identifiable, they don't override the major concerns that are often less tangible.

Read More

Gordon Flesch to Acquire ITP and Create Large Midwest MSP

By: Laura Stotler    2/24/2020

MSP Information Technology Professionals (ITP) will be acquired by Gordon Flesch Company to create one of the largest MSPs in the Midwest. The combine…

Read More

MDR Provider for MSPs Huntress Tracks Down $18 Million Funding Round

By: Laura Stotler    2/21/2020

Huntress, a company that provides SaaS managed detection and response (MDR) solutions for MSPs and VARs to deliver to SMBs, has scored an $18 million …

Read More

Pax8 and Novacoast Announce Security Operations Center Strategic Partnership at ITEXPO

By: Arti Loftus    2/21/2020

With all its benefits, cloud hosting, storage, and computing are increasingly vulnerable to cyber threats, and at ITEXPO this week in Ft. Lauderdale, …

Read More

As Digital Transformation Continues in the Enterprise Cybersecurity World, One Company Reaches for the Cloud to Supercharge Analyst Productivity

By: Arti Loftus    2/21/2020

It's no secret that managing security within enterprises, organizations, and small and medium businesses have become exponentially more complex as mor…

Read More