TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
IT Security

Shadow IT and fragmented data, and why they are a problem

by Mark Rowe

Shadow IT and fragmented data undermine what IT and security need most: a trusted understanding of its environment, argues David Shepherd, SVP EMEA at the cyber firm Ivanti.

Shadow IT includes applications, devices and increasingly AI tools that operate outside IT governance. Fragmented data occurs when information is spread across disconnected management, security and operational systems. Together, they create blind spots that prevent organisations from knowing exactly what assets they have, how theyโ€™re being used and where risks exist.

Our research highlights that nearly half (45 per cent) of IT professionals say they lack sufficient visibility into shadow IT, while 38pc lack adequate data about devices connecting to their organisation’s network. Without reliable visibility, vulnerabilities can go undetected, policies can be inconsistently applied and response efforts become slower.

This challenge becomes even more critical as organisations embrace AI and automation. Autonomous systems can only make sound decisions when they are operating from accurate data. If the underlying data is fragmented or technology exists outside IT’s view, organisations risk automating decisions based on incomplete information.

Reducing shadow IT starts by giving employees secure, approved tools that meet their needs, while establishing continuous visibility across the environment. A trusted data foundation is increasingly the prerequisite for effective security, operational resilience and AI-driven automation.

 

Itโ€™s undeniably tempting for businesses to embrace AI for fast(er) decisions – so what are the risks?ย 

The biggest risk is assuming that faster decisions automatically lead to better outcomes. AI can analyse information and take action at a speed no human team can match, but its effectiveness depends entirely on the quality, completeness and accuracy of the data it receives.

If AI is operating from fragmented, outdated or incomplete data, organisations risk accelerating mistakes rather than improving outcomes. In other words, AI can scale poor decisions just as efficiently as good ones, allowing errors, security gaps, or compliance issues to spread more quickly across the business before they’re identified and corrected. As organisations move toward greater automation, the focus should be on building a trusted system of record before increasing AI autonomy. That means creating a unified view of devices, applications, users, and risks across the environment so AI can make decisions based on an accurate picture of reality.

With that foundation in place, organisations can move toward governed autonomy, where AI continuously identifies risks, prioritises actions based on real-world context, and automatically remediates issues within clearly defined guardrails. The goal isn’t simply faster AI. It’s trusted AI that can act independently while remaining aligned with business policies, security requirements, and human oversight

 

What then can IT, and security, departments, do about fragmentation of data?ย 

IT and security teams must first understand where operational and security data resides and identify the gaps created by disconnected tools. When information is spread across multiple systems, teams are left with an incomplete picture of their environment, making it harder to assess risk, prioritise remediation and make informed decisions.

The solution is to establish a trusted system of record that creates a single, authoritative view of the technology estate. By bringing together asset, application, vulnerability, and security data, organisations can replace fragmented insights with accurate, real-time visibility across their environment. Keeping that data current is equally important. As devices, applications, and threats constantly change, decisions based on outdated information quickly lose value. Real-time visibility ensures IT and security teams are working from the most accurate picture possible.

This becomes even more critical as organisations adopt AI and autonomous operations. AI can only deliver reliable outcomes when it is powered by accurate, complete, and timely data. A trusted data authority provides the context AI needs to identify risk, prioritise actions, and automate remediation with confidence. Ultimately, reducing data fragmentation isn’t just about improving visibility. It’s about creating the foundation for better security, smarter operations, and trusted autonomy at scale.

How does a business stand to gain from doing something about its operational data? ย 

The value comes from turning fragmented information into actionable intelligence. When organisations bring together data from endpoints, applications and security tools into a trusted system of record, they gain a more complete understanding of their technology environment and can make better, faster decisions.

With a strong operational data foundation, teams can identify what matters most, such as which vulnerabilities pose the greatest real-world risk, and prioritise action accordingly. This reduces time spent manually investigating issues and helps focus resources where they will have the biggest impact. It also changes what’s possible with AI. When AI has access to accurate, complete and contextual data, it can move beyond simply identifying problems to helping solve them. Autonomous systems can continuously assess risk, prioritise remediation, and resolve defined issues within governance guardrails, enabling faster response without sacrificing oversight.

The ultimate business benefit is a shift from reactive IT to proactive operations. Organisations can reduce risk, improve efficiency, minimise disruption for employees, and resolve issues before they impact the business. Just as importantly, they establish the trusted foundation needed to scale AI and automation with confidence, rather than building autonomy on incomplete or unreliable data.