I had an argument with a 24-year-old systems administrator last week about whether it was acceptable to use a personal Gmail account for work-related communication. His position was that the corporate email system was slow, had limited storage, and lacked the search capabilities he needed to be productive. My position was that sending proprietary information through a third-party email service violated our acceptable use policy and created data governance risks. We were both right, which is what made the conversation so frustrating.
This exchange crystallized something I have been observing for the past two years: there is a genuine technology generation gap in enterprise IT, and it has significant security implications that most organizations are not addressing effectively.
Digital Natives in the Enterprise
The workforce entering enterprises today grew up with always-on internet access, social networking, instant messaging, and cloud-based applications. They are accustomed to choosing their own tools, sharing information freely, and working from wherever they happen to be. Their mental model of technology is fundamentally different from the model that enterprise IT policies were built on.
When a 24-year-old encounters a corporate IT environment that blocks personal webmail, restricts instant messaging, mandates a specific browser, and requires a VPN connection to access anything remotely, their instinct is not to comply - it is to find workarounds. And they are technically competent enough to do exactly that. Shadow IT is not a new phenomenon, but the current generation of employees is better equipped to practice it than any previous cohort.
The workarounds are creative and often invisible to IT security. Personal smartphones tethered to laptops to bypass web filtering. Dropbox accounts used to sync files between home and work. Google Docs used for collaboration because the corporate SharePoint instance is unusable. Skype calls because the enterprise VoIP system does not work well outside the office. Each of these workarounds represents a data flow that the organization does not control and often does not even know about.
The Policy Response Problem
The traditional IT security response to this situation is to write stricter policies and deploy more controls. Block Dropbox at the proxy. Disable USB ports. Restrict application installation privileges. This approach has two problems.
First, it does not work. A sufficiently motivated user can circumvent almost any control that does not involve physically disabling hardware. And the users who are most motivated to circumvent controls are often the ones who are most productive and technically capable - exactly the people you do not want to alienate.
Second, it creates an adversarial relationship between IT security and the user community. When security is perceived as an obstacle to productivity rather than an enabler of safe work, users stop reporting incidents, stop asking for guidance, and start solving problems on their own in ways that create more risk, not less.
A Different Approach
The organizations I have seen handle this well share a common characteristic: they focus on securing the data rather than controlling the tools. If a user wants to use Dropbox, the question is not "how do we block Dropbox" but "how do we ensure that sensitive data is classified and protected regardless of where it lives."
This requires a shift in thinking from perimeter-based controls to data-centric security. Encryption, data loss prevention, classification schemes, and policies that focus on outcomes rather than methods. "You must not transmit customer PII over unencrypted channels" is a better policy than "You must not use personal email" because it addresses the actual risk while leaving room for the user to choose their tools.
It also requires investment in enterprise IT that is actually competitive with consumer alternatives. If your corporate email system has a 100 MB mailbox limit and your search function takes 30 seconds to return results, you are pushing users toward Gmail. If your file sharing solution requires a VPN connection and three approval steps, you are pushing users toward Dropbox. Making the sanctioned tools usable is the most effective security control you can deploy.
Looking Ahead
This tension is not going to resolve itself. The incoming generation of workers is going to continue bringing consumer technology expectations into enterprise environments. The volume of data and the number of communication channels will continue to grow. And the traditional model of controlling security by controlling the technology stack will continue to erode.
The security organizations that thrive will be the ones that adapt their approach - embracing the tools that make people productive while implementing controls that protect what actually matters. The ones that dig in on restrictive policies and perimeter controls will find themselves fighting an increasingly futile battle against their own workforce.
The 24-year-old sysadmin and I eventually found common ground. I approved a project to evaluate cloud-based email alternatives with proper security controls. He agreed to stop using Gmail for work in the interim. It was a compromise, but it was the beginning of a conversation that every enterprise security team needs to be having.