# What do you think is the most overlooked risk in Cybersecurity?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">With cyber threats seeming to grow more sophisticated every day, we hear a lot about the big, obvious risks: ransomware attacks, phishing, data breaches, etc. But with all of the attention given to these high-profile threats, are there any lesser-known risks that are flying under the radar?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">I’m curious to hear the thoughts of all of our cybersecurity folks: what might be the most overlooked security risks in today's IT environment. These could be things that are misunderstood or simply not getting enough attention from organizations.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Looking forward to the discussion!</p>

##### Post Metadata
- Posted at: over 1 year ago
- Author title: Community Manager | Event Marketer | Metrics Guru
- Net upvotes: 3


## Comments
### Comment 1

&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;Hi Brett,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;Another great topic.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;I would say ‘Shadow IT’ where IT functions are carried out by individuals or departments without the approval of IT’s approval or recommendation.&amp;nbsp; In many cases, those users will derive immediate benefits in terms of convenience, increased productivity, and simplifying processes or working practices, but to the detriment of secure practices, which can easily lead to compromises and increased risks.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;Those using ‘Shadow IT’ do it secretly, and the approach is usually, ‘I don’t need to bother IT, as they will create restrictions and make life more complicated.’ They are not usually concerned with the detrimental effects of their actions.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;To counteract this, robust IT policies/standards (principle of least privilege, segregation of duty etc.) allied with greater Asset awareness and hands-on, clear Administration practices need to be implemented.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: over 1 year ago
- Author title: CISM | CRISC | CEH Cyber Security Professional
- Net upvotes: 1

#### Reply 1

&lt;p&gt;I figured you would have thoughts on this one!&lt;/p&gt;&lt;p&gt;Wow, I did not know that this was called Shadow IT. Most place that I&#39;ve worked really don&#39;t allow employees to download much of anything without permission, so I assumed that this was pretty much the norm everywhere. Apparently, it&#39;s not?&lt;/p&gt;

##### Reply Metadata
- Posted at: over 1 year ago
- Author title: Community Manager | Event Marketer | Metrics Guru

#### Reply 2

&lt;p&gt;Hi Brett,&lt;/p&gt;&lt;p&gt;If someone can find a way to make a job process easier they would do it.  It&#39;s probably human nature - who wants complexity when simplicity will suffice?  At the same time, if security controls are weak and flexible and there is little or no accountability/capability, people will take advantage and be encouraged to follow these behaviours.  The expression &#39;give someone an inch, and they will take a mile&#39; comes to mind.&lt;/p&gt;&lt;p&gt;I have observed &#39;Shadow IT&#39; in a number of previous places where I have worked.  If someone in HR or Production can use personal email accounts or personal cloud storage, they will have little consideration for security, unless it affects them directly.  Another example is the bypassing of whitelisted software on company firewalls by using applications that are not approved by IT.  In spite of fortified endpoint protection software, downloading noncompliant software is a major issue at many organisations.&lt;/p&gt;

##### Reply Metadata
- Posted at: over 1 year ago
- Author title: CISM | CRISC | CEH Cyber Security Professional




## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: about 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: about 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: about 13 years ago
  - Comments: 4


