Rogue SaaS Poses Security Nightmare

Rogue SaaS Poses Security Nightmare

By Doug Barney

There have always been rogue end users -- that’s how PCs came to dominate in the first place. The cloud poses a bigger threat to IT as these apps and services are far harder to control.

McAfee is now warning of the onslaught of unapproved SaaS apps, and how they might cause data leakage and open the doors to hackers.

The results are stunning, but maybe not surprising when you think about it. According to the research, actually performed by Frost & Sullivan’s Stratecast division, over 80 percent of workers are using rogue SaaS tools while at work. And for IT workers, the numbers are even higher!

Like PCs decades ago, these SaaS apps fall under the notion of Shadow IT where users and departments take IT initiatives into their own hands. While a boon to productivity, the lack of IT control creates security, data leakage and compliance problems. The trick for IT is to try to be nimble enough to actually support, protect and manage these applications, making end users happy while keeping the enterprise safe. These rogue apps are part of what’s driving the SaaS market, which Frost & Sullivan believes is growing at a CAGR of 16 percent, and poised to hit $23.5 billion in 2017.

“There are risks associated with non-sanctioned SaaS subscriptions infiltrating the corporation, particularly related to security, compliance, and availability,” said Lynda Stadtmueller, program director of the Cloud Computing analysis service within Stratecast. “Without appropriate knowledge, non-technical employees may choose SaaS providers or configurations that do not measure up to corporate standards for data protection and encryption. They may not realize that their use of such applications may violate regulations concerning handling and storage of private customer data, leaving the company liable for breaches.”

The number one rogue SaaS app, Microsoft may be happy to hear, is Office 365 that is used by 9 percent of those polled, even outstripping LinkedIn and Facebook. While some may see unapproved app dangers as an idle threat, some 15 percent of those polled have had a liability or security event occur.

“With over 80 percent of employees admitting to using non-approved SaaS in their jobs, businesses clearly need to protect themselves while still enabling access to applications that help employees be more productive,” said Pat Calhoun, general manager of network security at McAfee. “The best approach is to deploy solutions that transparently monitor SaaS applications and other forms of web traffic, and uniformly apply enterprise policies, without restricting employees’ ability to do their jobs better. These not only enable secure access to SaaS applications, but can also encrypt sensitive information, prevent data loss, protect against malware, and enable IT to enforce acceptable usage policies.” 




Edited by Cassandra Tucker
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

MSPToday Editor at Large

SHARE THIS ARTICLE
Related Articles

Foxit Brings AI to Document Analysis with New Research Agent

By: Erik Linask    7/3/2025

PDF and eSignature solutions provider unveils an intelligent tool designed to transform how users extract actionable insights from dense, complex docu…

Read More

OpenMSP Brings New Profitability to MSPs Driving an Open Source Revolution

By: Erik Linask    7/3/2025

OpenMSP, a community-driven platform seeks to liberate MSPs from unsustainable software licensing costs by leveraging open-source alternatives and AI-…

Read More

TD SYNNEX's Apptium Acquisition a Win for MSPs.

By: Erik Linask    7/3/2025

TD SYNNEX's acquisition of Apptium will simplify complexities of the XaaS, economy, offering MSPs new agility, accelerated time to revenue, and stream…

Read More

Real Estate Forecast 2025: Emerging Developments and Market Shifts

By: Contributing Writer    7/1/2025

Buying or selling property can be challenging. Rising mortgage rates and fluctuating home prices leave many uncertain about their next move. Business …

Read More

Protecting Business Assets with Smarter Security Frameworks

By: Contributing Writer    7/1/2025

Protecting your business is more challenging than ever. Cyber threats are increasing every day. Hackers target small and large businesses alike, searc…

Read More