Security staff should talk to end users more, says Red Hat

Not listening to users forces them to bypass security

IT security departments need to improve their relationships with their users by going out and talking to them, Red Hat's security strategist Josh Bressers has advised.

Bressers warned that in order to stop the spread of 'shadow IT' within the enterprise, security professionals need to make a bigger effort to understand staff in other departments, warning that "we don't listen very well".

Advertisement - Article continues below

Shadow IT has become an increasing problem for corporate IT managers, as employees use non-approved tools and technologies at work, rather than the systems provided by the in-house team.

"Security is often seen as the industry of 'no'," Bressers said. "We're reaching a point where people are running their own shadow IT, they're spinning up their own internal services. In some cases, they're downloading open source without telling anyone and putting it into their products because it solves their problems."

Part of this, he said, is the ongoing communication problem that enterprise IT suffers from. When employees feel like IT ignores their needs or hampers their progress, they often simply ignore it. "They have a job to do, they want to get their job done," Bressers said, "and if you're in the way, they'll just go round you."

Advertisement
Advertisement - Article continues below

He added that in order to stop users circumventing the IT department, security staff need to become more receptive to the needs of their users. "It's time for the security folks - people like me - to really make a point of working with these organisations," he said.

"Once you understand what people are trying to do, and the problems they're trying to solve, it changes a lot of things."

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Recommended

Visit/security/cyber-security/355267/zoom-hires-ex-facebook-cso-to-boost-platform-security
cyber security

Zoom hires ex-Facebook CSO Alex Stamos to boost platform security

8 Apr 2020
Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/security/cyber-security/355271/microsoft-gobbles-up-corpcom-domain-to-keep-it-from-hackers
cyber security

Microsoft gobbles up corp.com domain to keep it from hackers

8 Apr 2020
Visit/server-storage/servers/355254/a-critical-flaw-in-350000-microsoft-exchange-remains-unpatched
servers

A critical flaw in 350,000 Microsoft Exchange remains unpatched

7 Apr 2020