Shadow IT and Generative AI Drive Cyber Risks in 2025
During Cybersecurity Awareness Month 2025, ESET highlights the growing threat posed by Shadow IT, defined as the use of unsanctioned hardware and software by employees. This practice has become a critical issue in the era of remote and hybrid work, creating significant security gaps that expose organizations to cyberattacks, data loss, and compliance failures. The risk profile is further exacerbated by the increasing adoption of generative AI tools for productivity. While these tools offer convenience, they often lead to a loss of corporate control over how sensitive data is stored, processed, and shared. Tony Anscombe, ESET’s Chief Security Evangelist, emphasizes the need for IT teams to regain visibility and control over these unauthorized technologies. The article serves as part of a broader educational campaign, encouraging businesses to address the human element of cybersecurity, improve authentication methods, maintain rigorous software patching schedules, and build resilience against ransomware. By understanding the dynamics of Shadow IT and the implications of unmonitored AI usage, organizations can better protect their digital assets and ensure regulatory compliance in an evolving technological landscape.
Wire timeline
Shadow IT and Generative AI Drive Cyber Risks in 2025
During Cybersecurity Awareness Month 2025, ESET highlights the growing threat posed by Shadow IT, defined as the use of unsanctioned hardware and software by employees. This practice has become a critical issue in the era of remote and hybrid work, creating significant security gaps that expose organizations to cyberattacks, data loss, and compliance failures. The risk profile is further exacerbated by the increasing adoption of generative AI tools for productivity. While these tools offer convenience, they often lead to a loss of corporate control over how sensitive data is stored, processed, and shared. Tony Anscombe, ESET’s Chief Security Evangelist, emphasizes the need for IT teams to regain visibility and control over these unauthorized technologies. The article serves as part of a broader educational campaign, encouraging businesses to address the human element of cybersecurity, improve authentication methods, maintain rigorous software patching schedules, and build resilience against ransomware. By understanding the dynamics of Shadow IT and the implications of unmonitored AI usage, organizations can better protect their digital assets and ensure regulatory compliance in an evolving technological landscape.
WeLiveSecurity