A Kaspersky survey on cybersecurity in the workplace found that shadow IT cybersecurity gaps expose organizations across Saudi Arabia to significant operational risks. The study, conducted by Toluna research agency in 2025, surveyed 2,800 employees and business owners across seven countries including Saudi Arabia, the UAE, Turkey, South Africa, Kenya, Pakistan, and Egypt.
The findings reveal a disconnect between corporate security policies and employee compliance. Forty-five percent of Saudi professionals surveyed consider their company’s cybersecurity rules excessive or inappropriate, while 8.5% reported their organizations lack cybersecurity policies entirely or they are unaware of them. This gap signals a fundamental challenge in implementing effective security governance.
Device Usage and Policy Enforcement
Device management policies show inconsistent enforcement across Saudi organizations. Nineteen percent of respondents said their companies have no policies governing non-corporate device usage. Meanwhile, 42% of employees acknowledged they can use personal devices to access business information if they have some form of cybersecurity protection, even consumer-grade software. Only 20% reported stricter requirements, where personal devices must pass corporate IT security checks before use. Another 19% work in organizations that restrict work access to company-provided devices only.
The situation improves regarding software installation controls. Forty-two percent of organizations restrict installation privileges to IT specialists, while 38% limit access to top management or designated users. However, 11% of respondents work in environments where all users can install any software without IT approval, creating direct exposure to malware and unauthorized applications.
Shadow IT Remains a Persistent Challenge
Despite policy frameworks, cybersecurity enforcement remains weak in practice. Twenty-five percent of professionals admitted installing software on work devices without IT supervision during the past year. This behavior reflects the broader shadow IT problem, where employees use unauthorized software, devices, or cloud services to bypass perceived productivity constraints. Hybrid work environments, increased reliance on cloud-based tools, and the proliferation of artificial intelligence tools have accelerated this trend, creating blind spots for IT departments and exposing organizations to ransomware attacks, data leaks, and regulatory penalties.
Toufic Derbass, Managing Director for the META region at Kaspersky, stated: “Shadow IT is now a mainstream operational risk. When one in five employees installs software without IT oversight, it signals a policy gap. Many organizations already have security policies in place, but employee perception must also be considered. Organizations should move beyond restrictive controls and instead implement intelligent, user-centric cybersecurity strategies that combine technology with employee awareness and responsible use.”
Kaspersky Recommendations for Organizations
To address shadow IT risks, Kaspersky recommends organizations take several concrete steps. First, conduct a comprehensive audit to identify all unauthorized software, cloud services, and personal devices accessing corporate data. Second, implement robust monitoring solutions such as Kaspersky Next with EDR and XDR capabilities to gain visibility into unsanctioned app usage and device behavior.
Third, if personal device usage is permitted, organizations should define clear minimum security requirements and enforce them through mobile device management (MDM) or endpoint management tools. Fourth, complement user-friendly security policies with training programs that demonstrate real-life risks and mitigation strategies. Solutions such as Kaspersky Automated Security Awareness Platform can support this effort.
Guidance for Employees
Kaspersky also provided recommendations for individual employees. Workers should understand their company’s cybersecurity policies and seek clarification when needed. They should use only applications approved by their IT department and request access to specific resources through proper channels. When personal devices are permitted, employees must verify they meet all required security standards and have appropriate protection installed. Finally, work files should be stored and shared exclusively through approved platforms.
The survey underscores that effective cybersecurity requires alignment between organizational policy, technical controls, and employee behavior. As organizations across Saudi Arabia continue digital transformation initiatives, addressing shadow IT through balanced governance and user education remains critical to protecting sensitive business data and maintaining regulatory compliance.





