How to Manage Shadow AI, BYOD, and Cloud Risk

18.2K views
•
October 25, 2025
by
IBM Technology
YouTube video player
How to Manage Shadow AI, BYOD, and Cloud Risk

TL;DR

Security teams should provide controlled ways to use valuable technology instead of simply banning it, because users often bypass prohibitions and create less visible, more dangerous arrangements. Vetted alternatives, appropriate security controls, risk assessments, monitoring, and user education allow an organization to take calculated risks while keeping security involved in how new tools are adopted.

Transcript

Security teams, listen up. Don't say no, say how. Because when you say no, your users say how, and you are not going to like their answer. Look, I get it. I'm a security guy myself. I know how risky new tech can be, but I believe it's better to get out in front of this stuff rather than stick your head in the sand to pretend that when you say no, t... Read More

Key Insights

  • A prohibition does not necessarily stop technology use, because employees can devise their own methods when approved access is denied. These workarounds move activity underground, leaving the security team with less visibility, less control, and fewer opportunities to reduce risk.
  • Security is an organizational enabler when it helps the business take calculated risks. Like strong brakes on a high-performance car, effective controls support faster and safer movement, while a security function that constantly blocks activity encourages the business to work around it.
  • BYOD exists even where policy forbids it, according to the video's argument. Employees may connect personal computers through remote-control software, exposing the corporate environment to devices that could also be used by family members, run games, contain viruses, or lack organizational security controls.
  • Corporate email restrictions can produce riskier information flows when employees forward messages to public email services. Although this workaround makes email available on mobile devices, it also places sensitive information on systems where the organization lacks the control and visibility it could maintain through an approved mobile solution.
  • Unapproved wireless access can arise when employees install inexpensive access points on office network ports. An organization that refuses to provide Wi-Fi may therefore receive an unsecured version anyway, whereas a protected corporate hotspot could use appropriate cryptography and remain subject to organizational oversight.
  • Unapproved internet connections can bridge internal and external networks. A workstation connected to the corporate network and simultaneously using a modem for internet access can effectively become a router, creating the precise exposure that the original prohibition was intended to prevent.
  • Cloud-service bans do not eliminate cloud use when employees still need file sharing or application capabilities. Users can upload large files to uncontrolled services, potentially making information accessible to unintended people, especially when the organization provides no approved method for completing the task.
  • The key to managing Shadow AI and related technology is to say how instead of only saying no. Vetted alternatives, risk assessments, monitoring, security controls, and user education keep security involved while helping employees meet legitimate needs through safer, visible channels.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why should security teams say how instead of no?

Security teams should say how because a simple prohibition often drives technology use outside approved and monitored channels. Employees still have work goals, so they may connect personal devices, forward email, install wireless access points, create internet connections, or use cloud services without authorization. A controlled method keeps security involved and allows the organization to apply safeguards, monitoring, and education.

Q: How does banning BYOD create cybersecurity risk?

Banning BYOD can lead employees to connect personal systems without the security team's knowledge. The transcript describes personal desktops or laptops being used from an office, home, trip, or vacation through remote-control software. Such devices may also be used by children, contain games or viruses, and lack corporate protections, yet still gain access to organizational systems.

Q: What is the safer approach to bring your own device programs?

The safer approach is a structured BYOD program that identifies which devices are connecting and puts security controls in place. The video's central argument is that personal-device use happens even when an organization outlaws it. Recognizing the behavior allows security teams to manage access visibly, rather than discovering unmanaged and potentially infected systems after they have already reached the network.

Q: Why can blocking mobile access to corporate email backfire?

Blocking mobile access can prompt employees to forward corporate messages to personal or public email services so they can read them between meetings. That workaround transfers potentially sensitive information to infrastructure where the organization lacks control and visibility. Providing an approved way to download corporate email to mobile devices would address the user's need while preserving more organizational oversight.

Q: How can employees create unauthorized wireless access?

Employees can purchase a relatively inexpensive wireless access point and connect it to an available network port in an office. This gives them the convenience that the organization refused to provide, but it can also create an unsecured direct connection to the corporate network. A secured organizational hotspot using appropriate cryptography would meet the same need with stronger protection.

Q: Why was bring your own internet especially dangerous?

A user could connect a workstation to the internal corporate network while also using a built-in modem and an analog telephone line to reach the external internet. The workstation could then function as a router between the two networks. The transcript presents this as a worst-case result of denying managed internet access instead of providing firewalls, proxies, monitoring, intrusion detection, and education.

Q: How should organizations manage employee use of cloud services?

Organizations should provide an approved method for capabilities employees need, such as sharing large files with several people. If no suitable option exists, users may upload information to public cloud services despite company rules, and unintended people may gain access. Mobile devices can also bypass firewall restrictions, so policy alone cannot provide the visibility and control of a vetted alternative.

Q: What controls can support safer adoption of new technology?

The transcript identifies known devices, security controls, protected wireless hotspots, suitable cryptography, proxy servers, firewalls, intrusion detection systems, monitoring, and user education as ways to enable safer access. The description also recommends vetted alternatives and risk assessments for Shadow AI. Together, these measures let security shape adoption and support calculated risk instead of pushing behavior underground.

Summary & Key Takeaways

  • Security should enable calculated risk instead of acting as a permanent parking brake on the business. When security teams only reject new technology, employees may pursue their goals without approval. The organization then loses visibility and influence, while the resulting workaround may be substantially less secure than a controlled solution.

  • Historical examples show the same pattern across personal devices, mobile email, wireless access, internet connectivity, and cloud services. Employees connected unmanaged computers, forwarded corporate email to public servers, installed unsecured wireless access points, created simultaneous internal and external connections, or uploaded files to uncontrolled services when approved options were unavailable.

  • A stronger approach is to understand what users are trying to accomplish and design a secure method for doing it. Possible measures described include known and controlled devices, protected wireless hotspots, suitable cryptography, firewalls, proxy servers, intrusion detection, monitoring, education, vetted alternatives, and risk assessments for emerging tools such as Shadow AI.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from IBM Technology 📚