The equipment nobody tested

Imagine walking through your workshop and noticing a machine you have never seen before. Nobody can tell you whether it has been electrically tested, or who has been trained to use it. The workshop manager explains that it was cheap, she bought it online, and a friend recommended it. The team already rely on it.

Most directors would want to know more. Where did it come from? Has it been tested? What happens if it fails, or damages something else on the bench?

You would feel the same about a confident new face in the sales office, taken on because someone recommended them and they looked the part, with no references checked.

Now picture the same thing with software.

How it arrives

Software and online tools come into most organisations exactly this way. Someone finds an app that saves them an hour a week, or an AI tool a friend swears by, and installs it or signs up with a work email address. Now and then it is hardware: a cheap storage drive, a wireless device plugged into the network.

It is usually done with good intentions. The person is trying to get the job done, and the approved route was too slow, too restrictive, or did not exist at all.

The UK’s National Cyber Security Centre made the same point in September, writing about staff using AI tools their employer has not approved. It cited research in which 71% of employees said they had done so, and noted that where policies cannot meet business needs, people adopt new tools before their employer has had time to assess them.

Out of sight, still in use

Some of these tools sit unused and are forgotten. Others quietly become part of how the work is done, holding customer records, shared files or the only copy of something important. Either way, the technology team may have no idea they exist, so nobody is checking them, updating them or backing them up.

The risk grows when the person who brought the tool in leaves. I wrote recently about an organisation that lost access to two years of brand material because the only person with administrator rights had moved on. Tools that arrive informally tend to leave informally too, often taking the only key with them.

Diligence you already have

Boards do not need a new framework for this. Every organisation already has ways of checking people and equipment before trusting them: references and right-to-work checks, electrical testing, safety training, approved suppliers. Software is equipment you cannot see, and it deserves the same care.

Locking every computer down will not do it alone. A ban with no workable alternative pushes the activity further out of sight. The NCSC’s advice is to reduce the risk rather than assume it can be eliminated, by understanding why people turn to unapproved tools and offering approved ones that meet the need.

What a board can ask

Each of these mirrors a check the board would expect for a new member of staff or a new machine:

  • Do we have an approval route for new software and online tools, and is it quick enough that people actually use it?

  • Do we know what is installed and in use, including free tools people have signed up to with work accounts?

  • Which of those tools now hold our data, or the personal data of the people we serve?

  • When someone leaves, does the leaving process cover the tools they brought in and the accounts they administer?

  • Where staff are using tools we have not approved, do we know why?

The people who bring these tools in are usually trying to help. A board that treats software with the same care as its people and equipment can keep that goodwill, and still know what the organisation is relying on.

Previous
Previous

The security setting everyone thought was on

Next
Next

Data hoarding: a board-level courage test