Next DLP has released the results from a survey of more than 250 global security professionals conducted at RSA Conference 2024 and Infosecurity Europe 2024, which looked at shadow SaaS and shadow AI threats.
Nearly three-quarters (73%) of security professionals surveyed admit to using SaaS applications that had not been provided by their company’s IT team in the past year. This is despite the fact that they are acutely aware of the risks, with respondents naming data loss (65%), lack of visibility and control (62%), and data breaches (52%) as the top risks of using unauthorized tools.
The research also provided a snapshot of how security professionals view their organization’s training and overall understanding of the risks of shadow SaaS and AI:
- 40% of security professionals do not think employees properly understand the data security risks associated with shadow SaaS and AI. Yet, they are doing little to combat this risk. Only 37% of security professionals had developed clear policies and consequences for using these tools, with even less (28%) promoting approved alternatives to combat usage.
- Only half had received guidance and updated policies on shadow SaaS and AI in the past six months, with one in five admitting to never receiving this.
- Additionally, nearly one-fifth of security professionals were unaware of whether their company had updated policies or provided training on these risks, indicating a need for further awareness and education.
Clearly, there is a disparity between employee confidence in using these unauthorized tools and the organization’s ability to defend against the risks. Security teams should evaluate the extent of shadow SaaS and AI usage, identify frequently used tools, and provide approved alternatives. This will limit potential risks and ensure confidence is deserved, not misplaced.
Chris Denbigh-White, Chief Security Officer, Next DLP






