Representative image 
Technology

'Shadow IT' use by employees put more Indian firms at cyber attack risk

Companies are at the high risk of becoming targets of cyber incidents due to the use of shadow IT by their employees amid the growing trend towards a distributed workforce, a study by cyber-security firm Kaspersky showed.

IANS

NEW DELHI: About 89 per cent of companies in India suffered cyber incidents in the last two years, and 20 per cent of these were caused by the use of shadow IT, according to a new report.

Companies are at the high risk of becoming targets of cyber incidents due to the use of shadow IT by their employees amid the growing trend towards a distributed workforce, a study by cyber-security firm Kaspersky showed.

In the last two years, 11 per cent of companies worldwide have suffered cyber incidents due to the use of shadow IT by employees.

Shadow IT is the part of the company’s IT infrastructure that is outside the purview of the IT and Information Security departments, i.e. applications, devices, public cloud services etc. but that is not being used in accordance with information security policies.

"Employees who use applications, devices or cloud services that are not approved by the IT department, believe that if those IT products come from trusted providers, they should be protected and safe," said Alexey Vovk, Head of Information Security at Kaspersky.

However, in the 'terms and conditions', third-party providers use the so-called 'shared responsibility model'.

"It states that, by choosing 'I agree' users confirm that they will perform regular updates of this software and that they take responsibility for incidents related to the use of this software (including corporate data leakages)," Vovk said.

But, at the end of the day, business needs tools to control the shadow IT when it’s used by employees.

Deployment and operating shadow IT can lead to serious negative outcomes for businesses. Many instances were found in the Kaspersky study, which revealed that the IT industry – had been the hardest hit, suffering 16 per cent of cyber incidents due to the unauthorised use of shadow IT in 2022 and 2023.

Other sectors hit by the problem were critical infrastructure and transport and logistics organisations, which saw 13 per cent attacks, said the report.

2026 TN elections | AIADMK releases second list of candidates; 127 faces in fray

2026 TN elections | Nainar Nagenthran opts for Sattur, exits Tirunelveli stronghold

Eight killed as pickup truck carrying devotees rams into trailer in UP's Kaushambi

2026 TN elections | Puthiya Tamilagam to go it alone in Assembly election

Excise duty cut on petrol, diesel; hike in export duties to cost exchequer Rs 5,500 cr in fortnight