Shadow IT: How much technology does a company use without the IT department's knowledge?
2026-09-10 | 13 min Cyber Security
Today, a new cloud tool can be put to use within minutes and without the involvement of corporate IT. The marketing team creates an account in a SaaS application, the sales team begins sharing documents via an external service, and an employee uses generative AI to process work-related data.
Each decision may seem practical on its own, but gradually a technology environment emerges that the company does not fully understand.
Shadow IT is therefore not merely a problem of unauthorised applications. It is a problem of losing visibility into where company data is located, who has access to it and what happens to it.
Cloud technology has fundamentally simplified the use of business technology. A department no longer has to wait for a new server, an application installation or a large-scale IT project, because many tools can be purchased by card and put into use the very same day. This is a significant advantage for productivity, but it also shifts some technology decisions outside traditional IT processes.
This is precisely where Shadow IT emerges. It refers to applications, devices or cloud services used for work purposes without the organisation’s knowledge, approval or sufficient oversight. The technology itself does not necessarily have to be the problem. The same SaaS tool can be a completely legitimate part of the company environment when deployed in a managed way.
Shadow IT often does not arise from circumventing rules
The term Shadow IT may evoke the image of an employee who deliberately ignores security rules. In practice, the cause is often much more mundane. A person needs to complete a work task, and an available cloud tool can do it faster than the company’s existing process.
Marketing may need a graphic design tool, sales a CRM add-on, and a project team a space for sharing files with an external partner. If the approval of new software is slow or it is unclear which applications are permitted, creating another account becomes the easiest solution. Shadow IT is therefore often a symptom of the gap between how quickly the business wants to operate and how quickly the organisation can securely provide the necessary technology.
This is also important when setting up security. A purely repressive approach may simply lead users to employ new tools in even less visible ways. It is more effective to understand why a particular service was introduced and what need the department was addressing.
SaaS has changed how IT emerges within a company
In the past, purchasing an enterprise application was a relatively visible process. It required licences, infrastructure, installation or administrator involvement, so IT was generally aware of the new technology. SaaS has greatly simplified this model, because a user often needs only an email address and a payment card.
Small and medium-sized companies in particular can be significantly affected by this phenomenon. Technology purchasing tends to be decentralised, and individual departments have greater freedom when choosing tools, while internal IT has limited capacity to monitor every new account. Over time, several parallel applications may emerge for the same task.
A typical situation may include:
- several document-sharing tools,
- multiple project platforms,
- various videoconferencing tools,
- standalone CRM or marketing applications,
- large-file transfer services,
- generative AI tools,
- cloud storage created by individual employees.
Each service also introduces another user account, additional permissions and another place where company data may end up. As the number of applications grows, it is therefore not only technological diversity that increases, but also the surface area that must be secured and managed.
A personal cloud account may contain company data
One of the simplest examples of Shadow IT is using personal cloud storage for a work document. An employee may need to transfer a larger file quickly, collaborate with a supplier or continue working on another device. They therefore save the document to a personal cloud account they already use.
From the perspective of the work process, this may be a minor shortcut. From the company’s perspective, however, the data has left an environment where the organisation has defined access rules, auditing and a user lifecycle. IT may then have no way of knowing that a copy of the document even exists.
The risk may only become apparent much later. The employee leaves, the personal account remains active, and the work documents on it remain accessible even though the company account has already been deactivated. An employee’s departure therefore may not remove access to data that was never under the company’s management.
AI has created a new form of Shadow IT
Generative AI has greatly expanded the number of tools that users can incorporate into their daily work without IT involvement. Text can be pasted into a chatbot, a document uploaded for analysis, and source code submitted to a tool for explanation or modification. In many cases, these are legitimate efforts to increase productivity.
Without clear rules, however, users may not know which information can be entered into a particular service. This may include, for example, a business contract, an internal financial document, personal data, source code or customer information. Without knowing the service terms, it may also be unclear how the data is processed, stored or used.
The solution is therefore not to ban all AI tools automatically. The organisation needs to know which services employees use, what types of data they enter into them and which use cases are acceptable. AI governance is thus gradually becoming part of the same issue as Shadow IT. Without visibility, security rules cannot be set sensibly.
The biggest problem is that the company does not know what it does not know
The security team may protect Microsoft 365, the company cloud, ERP and other known enterprise systems very well. However, if the sales department uses five additional applications that no one has recorded, the security policy may not apply to them at all. This creates a blind spot that cannot be protected in the same way as the known environment.
Shadow IT therefore raises several fundamental questions:
- Which SaaS applications are actually used in the company?
- Which of them contain company data?
- Who created the administrator accounts?
- How do users authenticate?
- Who can share data externally?
- Does the same data exist in multiple services?
- What happens to an account when an employee leaves?
If the company cannot answer even the first question, the remaining security controls are very difficult to configure.
Visibility is therefore the first step in addressing Shadow IT, not its ultimate goal.
One new SaaS application also means new identities
Each standalone application may create its own user account. If the service is not linked to the company’s central identity, this creates another password, another way to reset access and another process that must be handled when an employee joins or leaves. With dozens of tools, identity gradually becomes fragmented.
This also complicates security policies. A company may have MFA properly configured for its main systems, but a new SaaS application may use only a password or its own authentication mechanism. At the same time, it may remain outside the central overview of active users.
The principle of least privilege and continuous verification, which forms the basis of Zero Trust security, therefore applies not only to internal applications. It is equally relevant to cloud services, where corporate identity is increasingly becoming the main boundary between users and data.
An employee’s departure is a practical test of control over SaaS
In managed company systems, the account of a departing employee can be deactivated according to a defined process. However, if an employee created their own SaaS accounts, some services may remain active even after they leave. Moreover, the company may not know that the account exists.
The problem may be even more serious if the departing employee used a personal email address or was the service’s only administrator. The department may then lose access to data, or conversely, the former employee may retain access to information they no longer need. Shadow IT thus changes from an abstract security issue into a practical problem of company data ownership.
It is therefore important that the access lifecycle does not end when a domain account is deactivated. Protecting company infrastructure must also include identity and permissions across cloud services, because they now provide access to a significant proportion of enterprise information.
Shadow IT can also create a financial problem
Security is not the only reason a company needs visibility into SaaS. Decentralised purchasing may result in several departments paying for different applications that perform a similar task, while some licences remain unused. Individual costs may appear negligible when monthly fees are small, but they gradually accumulate across dozens of services.
Contract ownership and administration also become a problem. Some services are tied to a particular employee’s payment card, while others are linked to the email address of someone who no longer works at the company. The organisation may therefore be using a critical work tool without a clear owner and without central control over the subscription. Shadow IT is therefore not merely a security concept. It is also a matter of technology management, costs and responsibility for business processes.
Not every unapproved application is automatically dangerous
The mere fact that IT did not originally approve an application does not mean that the service poses an unacceptable risk. It may be a high-quality tool that addressed a genuine departmental need and, after a security assessment, can be added to the company’s standard technologies. Shadow IT should therefore not be understood merely as a list of tools that need to be banned.
It is more important to determine:
- why the application was introduced,
- what data it processes,
- who uses it,
- what security options it offers,
- whether access can be centralised,
- whether an approved alternative exists.
This approach also reduces conflict between IT and users. Security stops being an obstacle to work and becomes a way to use a legitimate tool with appropriate oversight.
How to determine whether Shadow IT exists in the company
For most organisations, the best question is not whether Shadow IT exists, but how extensive it is. Even a simple review of the tools in use can reveal a significant difference between the official application catalogue and actual day-to-day work. It is important not to focus only on paid licences.
Possible indicators include:
- company email addresses registered with unknown SaaS services,
- software payments on separate company cards,
- files shared through personal cloud accounts,
- OAuth permissions granted to external applications,
- accounts created outside the central identity system,
- the use of public AI services for work purposes,
- non-standard cloud services visible in network traffic.
The result should not be the immediate blocking of everything unknown. The first objective is to map the technologies actually in use and determine which of them handle sensitive or critical information.
Shadow IT reveals the limits of the traditional concept of a corporate network
With cloud applications, the data, the user and the service itself may all be located outside the traditional corporate network. An employee works from home, signs in directly to a SaaS platform, and the company firewall may not be involved in the communication. A security model based primarily on protecting the network perimeter therefore cannot cover all modern work scenarios.
Identity, the device, the access context and the data itself therefore become all the more important. The company needs to decide who may use a particular service, from which device and with what information. The cloud has not only moved applications outside the company; it has also shifted where security policy must be applied.
This is also why the standard combination of traditional security measures may not be sufficient in a modern environment. Protection must follow users and data beyond the physical boundaries of the office.
Seven questions that reveal the extent of Shadow IT
A basic assessment does not need to begin with the purchase of additional technology. Much of the problem can be uncovered simply by comparing the official list of applications with how individual teams actually work. It is important not to focus only on the IT department.
Useful questions include:
- How many SaaS applications does the company officially use, and how many do individual departments use?
- Which services contain personal, customer or commercially sensitive data?
- Which accounts are not linked to the company identity?
- Are personal cloud accounts used for work documents?
- Which AI tools receive company data?
- Who owns and administers the individual SaaS services?
- What happens to accounts and data when an employee leaves?
If there are no reliable answers to these questions, the problem is not necessarily the cloud itself. The problem is insufficient control over its use.
The goal is not to stop the cloud, but to eliminate blind spots
SaaS and cloud applications have given companies speed, flexibility and the ability to use high-quality tools without extensive infrastructure of their own. Shadow IT therefore cannot be addressed by returning to a model in which every new application is automatically considered a problem. It is more important to create a process that allows new services to be used securely while maintaining visibility into data and access.
The first step is visibility. The company needs to know which services are used, the accounts, the owners and the types of data that pass through them. Only then can it decide which applications to permit, which to restrict and which to replace with a more secure alternative.
Shadow IT is not primarily a problem of employees using too much technology. The problem arises when the company does not know which technologies they use and what happens to company data within them.
From Shadow IT to managed cloud use
Completely blocking all unknown services may limit productivity and prompt further attempts to circumvent the rules. The opposite extreme—allowing every department to use any application it chooses—leads to a loss of control over identities and data. The practical goal is therefore a managed cloud environment that can distinguish between a legitimate business need and an unreasonable risk.
Such a model combines technology visibility with clear rules for users, identities and data. The company gains visibility into services without automatically blocking every new way of working. This shift from prohibition to controlled use is the foundation for the next phase of cloud security.
Frequently Asked Questions
Shadow IT refers to technologies used for work purposes without the organization's knowledge, approval, or adequate oversight. This can include SaaS applications, personal cloud accounts, AI tools, or other online services. The application itself is not necessarily dangerous; the primary risk lies in the lack of visibility and management.
It most often arises because a user needs to quickly complete a specific work task. Cloud services can be put to use within minutes, whereas the internal approval process for new technology can take significantly longer. The problem is therefore often linked to the way internal processes are structured.
It can be, if the tool is used for work purposes without approval or without clear rules for handling corporate data. It depends primarily on the type of service, the method of deployment, and the data users input into it. Therefore, a managed enterprise AI solution is not automatically Shadow IT.
The company may not have control over the access to, storage of, or deletion of work documents stored in a personal account. The risk increases when an employee leaves, as deactivating the corporate identity may not affect the personal service. Consequently, corporate data may remain outside the organization's management.
Not always. A purely restrictive approach can hinder legitimate business needs and lead to further circumvention of the rules. A more effective first step is to gain visibility, assess the risk associated with individual services, and establish a clear process for their approval and use.
Small and medium-sized enterprises often purchase SaaS in a decentralized manner, with individual departments using their own tools. At the same time, they may lack a large security or IT team to continuously manage all these services. Consequently, even a relatively small organization can end up using a surprisingly extensive ecosystem of cloud applications.