A marketing team frustrated by slow IT procurement signs up for a third-party analytics SaaS using a corporate credit card and uploads customer contact lists to it. The security team only learns about the service after a data protection audit. Which risk category does this situation most directly illustrate?
- AShadow IT, where business units adopt unsanctioned technology that bypasses security and governance review. Correct
- BAn advanced persistent threat campaign carried out by a sophisticated external nation-state intrusion set.
- CA malicious insider deliberately exfiltrating sensitive records to harm the employer's reputation and revenue.
- DHacktivism in which ideologically driven outsiders pressure the organisation by leaking confidential customer details online.
Why A is correct: Marketing procured and used a SaaS outside the formal IT process, which is the textbook definition of shadow IT and the source of unmanaged data exposure.
Why B is wrong: APT campaigns involve covert external attackers exploiting systems, not authorised employees openly buying a SaaS subscription with corporate funds for daily marketing tasks.
Why C is wrong: Tempting because data left the perimeter, but the marketing team's intent was operational efficiency rather than sabotage, which distinguishes shadow IT from a malicious insider.
Why D is wrong: No external ideologically motivated party is involved and no public leak has occurred, so the scenario does not match hacktivist behaviour or motivation.