Security and Compliance Risks of Faculty Shadow IT
Faculty shadow IT results in considerable security and compliance risks.
A major risk, Kwong says, involves the potential exposure of sensitive data without proper controls in place. That’s a significant concern with AI tools, which more faculty members are using and which often request more access than they actually need, leading to greater exposure.
“The biggest challenge we have today around shadow IT is really with AI,” Kwong says.
If a faculty-installed solution involves student data, that data falls under the Family Educational Rights and Privacy Act, which protects the privacy of students’ education records, Larson says. “If there’s a breach, the institution is still responsible, regardless of whether it knew there was a system that was vulnerable.”
When they download software on their own, faculty sign off on the consumer terms of agreement, which can carry legal ramifications for the institution, Larson says. There’s also an operational risk, he adds: A faculty member might install a tool and later leave the institution, so that a process becomes dependent on a tool no one can support.
“You can’t assess, protect and respond if you don’t know the solution exists,” Larson says. “With shadow IT, you don’t know it exists until it’s a problem, which is the scary part.”
READ MORE: Ask these five questions before adopting an AI tool.
Creating a Faculty-Centered, Frictionless Digital Experience
Given the risks, higher ed institutions have a clear stake in creating a digital workplace that keeps faculty from looking for quick fixes in the first place.
“A faculty-centered digital workplace should be a safe, institutionally supported path,” Larson says. “It should be the easiest path — a path that faculty want to use and have confidence in using.”
The first step in that path should be a single point of contact for faculty requests; an individual who communicates with all the relevant teams, such as IT, procurement and instructional design. “Faculty shouldn’t have to know the entire organizational chart to know whom to ask for things,” Larson says.
Critically, IT must reach out to faculty to understand their tech needs. “We can’t just sit at our computers waiting for support tickets to come in,” Larson says. “The IT department needs to be a department not of ‘no’ but of ‘know.’ They need to be connected with their end users and understand what their needs are.”
UP NEXT: AI risk frameworks help guide governance and tool adoption.
As a department of “know,” IT should ask faculty why and when they need a requested solution, then respond in a timely fashion. Often, IT can inform faculty that the university already has access to the solution or a similar, sufficient solution — vetted tools with data protections that faculty won’t get from free software.
When DeVry faculty want a tech solution, they submit a simple online request form, Kwong says. The IT department responds usually within half a day, letting faculty know if the request is approved or if the solution is already in the university’s software library. DeVry also leverages committees that include IT leaders, school deans and faculty members who assess and prioritize technologies for faculty and students.
