Part 2 of 12 — The New IT Reality
A series for CEOs and business leaders examining how IT challenges don't replace each other — they accumulate.

You called everyone back to the office. Desks are occupied again. The coffee machine is earning its keep. Problem solved, right?

Wrong.

Your infrastructure is permanently distributed now, whether you acknowledge it or not. And the gap between what your IT environment looks like on paper and how your organisation actually operates is probably the biggest unmanaged risk on your balance sheet.

The Office Came Back. The Perimeter Didn't.

Even the most committed "back to office" companies operate in a fundamentally different technological reality than they did in 2019. Your employees use mobile phones that access corporate email. They connect to cloud services from home, from cafés, from client sites. They store files in OneDrive, share documents via Teams, and collaborate on platforms that didn't exist — or weren't used — before March 2020.

The physical office is no longer the boundary of your IT environment. It's just one node in a distributed network. And most organisations haven't updated their security architecture to reflect this.

The old security model — firewall as castle wall, everything inside is trusted, everything outside is suspect — is dead. It died in 2020, and no amount of pretending everyone is "back to normal" will resurrect it. Your data doesn't live inside a perimeter anymore. It lives everywhere.

The Shadow IT Explosion

During the pandemic, your employees discovered tools. Slack for communication. Notion for project management. Personal Dropbox accounts for file sharing. Trello boards for task tracking. And more recently, ChatGPT for everything from drafting emails to analysing spreadsheets.

They're not giving them up.

This is shadow IT — technology used within your organisation without the knowledge or approval of your IT department. And it has exploded. Gartner predicts that by 2027, 75% of employees will acquire, modify, or create technology outside IT's visibility. This isn't a future problem. It's a current reality.

Every unauthorised app is a potential data leak. Every personal cloud account is a compliance gap. Every AI tool that employees feed with company data is a security incident waiting to happen. And you can't control what you can't see.

Your Data Is Everywhere. Do You Know Where?

Consider this: GDPR requires you to know where personal data is stored, who has access to it, and how it's protected. Can you answer that question with confidence?

Client files in WhatsApp groups. Financial data in personal email accounts. HR documents in shared Google Drives with no access controls. Strategic plans in Notion workspaces that the employee who set them up has since left the company — and nobody changed the password.

IBM's Cost of a Data Breach 2024 report puts the average cost of a data breach at $4.88 million. But beyond the financial impact, consider the regulatory exposure. Under GDPR, you're not just responsible for data in your official systems. You're responsible for data wherever it exists within your organisation's operations — including that WhatsApp group, that personal laptop, that unauthorised cloud storage.

If you don't know where your data is, you can't protect it. And if you can't protect it, you can't comply with the regulations that require you to.

Zero Trust: Not a Buzzword, a Necessity

The security model that makes sense in this reality is called Zero Trust. The core principle is simple: never trust, always verify. Every access request — whether it comes from inside your office or from a café in Thessaloniki — is treated the same way: authenticated, authorised, and encrypted.

Zero Trust isn't a product you buy. It's an architecture you build. It means identity-based access instead of network-based access. It means continuous verification instead of one-time login. It means micro-segmentation so that a breach in one system doesn't cascade across your entire environment.

For most Greek SMEs, the full Zero Trust architecture is a journey, not an overnight change. But the direction of travel is non-negotiable. Every month you operate on the assumption that "inside the office equals safe" is a month of accumulated risk.

Three Times the Complexity, Same Resources

Here's what rarely gets discussed in boardrooms: your IT team — if you have one — is managing roughly three times the complexity they handled before 2020, with the same headcount and often the same budget.

Pre-pandemic, they managed an office network, desktop computers, and a few servers. Now they manage an office network, remote access infrastructure, cloud platforms, mobile devices, collaboration tools, video conferencing systems, and an ever-growing constellation of SaaS applications — while simultaneously dealing with a threat landscape that has intensified dramatically.

Microsoft's Work Trend Index found that 87% of employees consider themselves productive working remotely, but only 12% of managers fully agree. This disconnect isn't just about productivity perception — it reflects a fundamental gap in how organisations understand their own operations. Your people are working in ways your infrastructure doesn't fully support, your security doesn't fully cover, and your IT team doesn't fully see.

The Greek Market: Pretending Nothing Changed

In Greece, the dominant response to the end of pandemic restrictions was to simply "go back." Employees returned to offices. The hasty solutions of 2020 were left running in the background. And everyone tacitly agreed to pretend that the digital transformation hadn't happened.

But it had. The Microsoft 365 licences bought in a panic? Still active — and still misconfigured. The user accounts created hastily? Still there — some for employees who left two years ago. The security policies that were relaxed "temporarily"? Never reinstated.

Most Greek SMEs never completed a proper post-pandemic IT assessment. They never asked: "What changed in our technology landscape, what risks did we introduce, and what do we need to fix?" The answer to that question isn't comfortable. But ignoring it doesn't make the risks disappear. It just means they compound in silence.

The Question You Should Be Asking

The question isn't whether your people work remotely. Some do, some don't — that's a management decision. The real question is: does your infrastructure acknowledge the reality of how your organisation actually operates today?

If your employees access corporate email on personal phones — and they do — your infrastructure needs to account for that. If your data lives in cloud services — and it does — your security needs to cover that. If your people use AI tools — and they do — your policies need to address that.

Pretending the world went back to 2019 is not a strategy. It's a vulnerability.

Key Takeaway

Your IT perimeter dissolved in 2020 and never reformed. Whether employees work from the office or from home, your data, tools, and access points are distributed. The organisations that acknowledge this reality and adapt their infrastructure accordingly will survive what comes next. Those that don't are running on borrowed time.

Previously: How the Pandemic Revealed Your IT Was a Castle Built on Sand

Next in the series: Your Employees Know More Than a 1996 IT Manager — and Less Than They Think


Want to understand the real state of your distributed infrastructure? Let's have an honest conversation about what your IT environment actually looks like — not what you assume it looks like.