Cybersecurity ‘disconnect’ leaves firms exposed as staff bypass rules, Kaspersky warns

  • A growing mismatch between corporate cybersecurity policies and everyday working practices has been noted
  • Kaspersky's findings discovered that employees think employers are going too far
  • The survey found that 21 per cent of respondents installed software on a work device without IT approval over the past year

A growing mismatch between corporate cybersecurity policies and everyday working practices is increasing risk for organisations across the META region, according to new research from Kaspersky.

The study, carried out by Toluna and based on responses from 2,800 employees and business owners in seven countries, including South Africa and Kenya, found that nearly two in five professionals view their organisation’s cybersecurity rules as excessive or out of step with operational reality.

The survey found that 21 per cent of respondents installed software on a work device without IT approval over the past year, despite policies often explicitly banning the practice.

A further 7 per cent said their organisations either lack cybersecurity rules entirely or that staff are unaware of them.

The findings also point to inconsistent controls around personal device use. Nineteen per cent of respondents said their companies have no policies governing non-corporate devices, while 35 per cent reported they can access business data on personal devices as long as some form of cybersecurity protection is in place.

Only a quarter of respondents said their workplace restricts professional use strictly to IT-issued devices. Another 21 per cent said personal devices are permitted but must first pass formal IT security checks.

Controls on software installation appear more widely enforced, though gaps remain. Half of respondents said only IT specialists are authorised to install software, while 31 per cent said permissions are limited to senior management or designated users. However, 8 per cent reported having no restrictions at all.

“Shadow IT is now a mainstream operational risk. When one in five employees installs software without IT oversight, it signals a policy gap,” said Toufic Derbass, Managing Director META at Kaspersky.

Kaspersky describes shadow IT as the use of unauthorised software, devices or services outside formal IT oversight. The company said the shift to hybrid working, rapid adoption of cloud tools and the rise of AI applications have accelerated the trend, reducing visibility for IT teams.

The consequences can be significant. Organisations allowing unmanaged devices and software face increased exposure to ransomware attacks, data leaks and potential regulatory breaches.

Toufic Derbass said organisations must move beyond restrictive controls and instead build “intelligent, user-centric cybersecurity strategies” that combine technology with employee awareness programmes.

Kaspersky recommends that organisations conduct audits to identify shadow IT across software, cloud services and personal devices connected to corporate systems. It also advises deploying endpoint detection and response (EDR) or extended detection and response (XDR) tools, alongside enforcing minimum security standards on personal devices through mobile device management solutions.

Employees, meanwhile, are urged to follow internal policies, use only approved applications and devices, and ensure work-related files are handled exclusively through authorised platforms.

Tags:
,
No Comments

Sorry, the comment form is closed at this time.

1