Rogue SaaS Poses Security Nightmare

By Doug Barney

There have always been rogue end users -- that’s how PCs came to dominate in the first place. The cloud poses a bigger threat to IT as these apps and services are far harder to control.

McAfee is now warning of the onslaught of unapproved SaaS apps, and how they might cause data leakage and open the doors to hackers.

The results are stunning, but maybe not surprising when you think about it. According to the research, actually performed by Frost & Sullivan’s Stratecast division, over 80 percent of workers are using rogue SaaS tools while at work. And for IT workers, the numbers are even higher!

Like PCs decades ago, these SaaS apps fall under the notion of Shadow IT where users and departments take IT initiatives into their own hands. While a boon to productivity, the lack of IT control creates security, data leakage and compliance problems. The trick for IT is to try to be nimble enough to actually support, protect and manage these applications, making end users happy while keeping the enterprise safe. These rogue apps are part of what’s driving the SaaS market, which Frost & Sullivan believes is growing at a CAGR of 16 percent, and poised to hit $23.5 billion in 2017.

“There are risks associated with non-sanctioned SaaS subscriptions infiltrating the corporation, particularly related to security, compliance, and availability,” said Lynda Stadtmueller, program director of the Cloud Computing analysis service within Stratecast. “Without appropriate knowledge, non-technical employees may choose SaaS providers or configurations that do not measure up to corporate standards for data protection and encryption. They may not realize that their use of such applications may violate regulations concerning handling and storage of private customer data, leaving the company liable for breaches.”

The number one rogue SaaS app, Microsoft may be happy to hear, is Office 365 that is used by 9 percent of those polled, even outstripping LinkedIn and Facebook. While some may see unapproved app dangers as an idle threat, some 15 percent of those polled have had a liability or security event occur.

“With over 80 percent of employees admitting to using non-approved SaaS in their jobs, businesses clearly need to protect themselves while still enabling access to applications that help employees be more productive,” said Pat Calhoun, general manager of network security at McAfee. “The best approach is to deploy solutions that transparently monitor SaaS applications and other forms of web traffic, and uniformly apply enterprise policies, without restricting employees’ ability to do their jobs better. These not only enable secure access to SaaS applications, but can also encrypt sensitive information, prevent data loss, protect against malware, and enable IT to enforce acceptable usage policies.” 

Edited by Cassandra Tucker

MSPToday Editor at Large

Related Articles

MSPs Need to Get Ahead of Ransomware Attacks

By: Laura Stotler    12/6/2019

Ransomware attacks are on the rise and MSPs and their customers are increasingly becoming targets. Service providers can take some important security …

Read More

Orange Selects Ericsson for Managed Services, AI & Automation

By: Laura Stotler    12/5/2019

Orange has once again selected Ericsson as its MSP in five countries and will also deploy the Ericsson Operations Engine to incorporate AI, automation…

Read More

Datto Selects Aligned Energy Salt Lake City Data Center to Support Growth

By: Maurice Nagle    12/4/2019

Datto Inc is expanding, and as part of these efforts announced the selection of Aligned Energy's Salt Lake Metro data center. The selection should sup…

Read More

Building a Field Service Business by Going Direct to Technicians

By: Erik Linask    11/22/2019

A recent trend towards a direct-to-contractor model is helping MSPs, VARs, and service providers increase their services revenues.

Read More

Axcient Announce Axcient X360 at IT Nation

By: Arti Loftus    11/7/2019

Denver-based Axcient Inc., an award-winning leader in business availability and cloud migration solutions for Managed Service Providers (MSPs), last w…

Read More