Shadow IT refers to the use of hardware, software, cloud services, or other technology without the organization’s approval or oversight. Since these technologies operate outside IT’s visibility, Shadow IT risks often go unnoticed until a security vulnerability is exploited.
Employees may not intend to use unsanctioned SaaS apps to bypass IT policies. Their intentions are often genuine, such as finding a faster way to complete work, collaborate with remote teams, or access features approved tools do not offer.
The risk is that the business may end up relying on applications and systems that IT does not know about. Think of it like having a door to your valuables that your security team does not even know exists. They cannot monitor it, secure it, or respond quickly if someone uses it to gain access.
Common Shadow IT Examples in Companies Today
A Cisco report says 80% of workers use non-sanctioned applications to get their jobs done. For example, teams may adopt new SaaS applications without going through the IT department to avoid routine, lengthy security checks, often under the excuse of improving productivity. Here are some common shadow IT examples:
Unsanctioned SaaS Tools: Shadow IT risks exist when employees sign up for file-sharing, e-signature, CRM, or project management tools without IT approval. These applications can become part of daily workflows without the organization fully assessing their security or data-handling practices.
Personal Cloud Storage and Consumer Messaging Apps: The IT department may not be able to monitor and protect data in personal Google Drive, Dropbox, WhatsApp, or other services that are not officially administered.
Rogue Integrations, API Keys, Browser Extensions, and Shared Accounts: Shadow IT risks happen when employees connect unauthorized applications to company systems, create API keys, install browser extensions, or share accounts to make their work easier. These connections can create additional access points that IT teams did not approve.
Shadow IT Risk: How Shadow Tools Can Lead to Data Breaches
The same tools employees use to get work done faster can also create an invisible path to company data. Here are three ways shadow IT can increase the risk of a data breach:
1. Weak Security Controls
Your IT department oversees security concerns such as what data an application can access, what permissions it receives, how users authenticate, and whether those permissions can be revoked.
An employee using an unapproved service may link an application that does not meet the organization’s security requirements, such as an app with no multi-factor authentication. Shadow IT risks also exist when a file containing sensitive company information is shared through a publicly accessible link, creating another route to the data that IT does not know exists.
2. Shadow IT Creates Data Sprawl
Personal cloud storage, external file sharing, unapproved project management platforms, and unmanaged developer environments and code repositories are forms of shadow IT. Data breaches are more likely when company information is scattered across services outside the IT department's oversight. An employee may connect an unapproved application to company systems and continue having access long after leaving that role, creating a potential entry point for cybercriminals.
Shadow IT vs. Bring Your Own Device (BYOD)
Shadow IT and Bring Your Own Device (BYOD) can both involve technology outside the organization’s direct control, but they are not the same thing. The main difference is that BYOD uses devices approved by the IT department, while shadow IT uses technology not approved by IT. Overlap can also occur if an employee uses an approved personal laptop to access an unapproved cloud application for work.
Shadow IT | BYOD | |
What it involves | Unapproved software, SaaS applications, cloud services, and other technology | Personal devices, such as smartphones, laptops, and tablets used for work |
Approval | Not approved or managed by the IT department | Approved for work use under an internal BYOD policy |
Concern | IT may not know which apps are being used, what data they hold, or what systems they can access | Company data is accessed or stored on a personal device, requiring appropriate security and management controls |
Shadow AI in the Workplace: The Next Frontier of Shadow IT Risk
One recent survey found that 88% of security leaders admitted to using unapproved AI tools. The statistic is concerning even if the reasons for using these tools seem legitimate. Employees can sign up for an AI tool within minutes and use it to summarize documents, analyze data, write code, and create presentations.
Do these unapproved AI tools increase productivity? The answer is likely yes for many people. However, employees and management need to be sensitized to the possible shadow AI risks as follows:
1.Model Training and Data Exposure
A common shadow IT example is employees pasting information, including confidential data, into AI chatbots. Some consumer AI products, such as OpenAI's ChatGPT, offer data control settings that let users turn off the option to use their chats to improve the model.
The problem is that some employees may not know which data controls apply to the AI tool they are using. Samsung's 2023 data leak, in which an engineer entered confidential source code into ChatGPT, shows how sensitive information can be exposed to an external and unapproved AI service.
2.Hallucinations and Unreliable Outputs
Shadow AI risks are not limited to data exposure. AI tools can also generate inaccurate or unsupported information, even when the tools themselves are approved by the organization.
The risk increases when employees use unapproved AI tools without established human review processes. The organization may have no way of knowing how employees are using the tool or whether AI-generated information is being checked before it is used in customer communications, software, or business decisions.
How to Detect Shadow IT in Your Company
Managing shadow IT is challenging when you do not even know what employees are using. An employee could even use multiple unsanctioned SaaS applications. For example, an employee could sign up for an app with a work email address, connect it to a company account through OAuth, and access it from a personal laptop. Here are four practical ways to detect shadow IT:
Check SSO and OAuth Activity: Look for unfamiliar applications connected to employee accounts, particularly those with access to email, cloud storage, CRM systems, or other sensitive business data.
Monitor Saas and Network Activity: Compare applications and domains appearing in proxy, Domain Name System (DNS), Cloud Access Security Broker (CASB), or Security Service Edge (SSE) logs against the company's approved software list.
Check Corporate Spending Records: Search card transactions and invoices for software subscriptions that have not gone through IT and the normal procurement process.
Search for Inactive or Unmanaged Accounts: Look for old SaaS accounts, personal accounts using company email addresses, and accounts that remain active after an employee changes roles or leaves the organization.
Conclusion: Is Shadow IT an Advantage or a Problem?
According to a 2024 article by Timothy R. Mclleveene on ISACA, a large shadow IT problem may signal that an organization is not adequately meeting employees' technology needs.
If employees repeatedly bypass IT simply to carry out their responsibilities, maybe it is time to ask some serious questions. Are the approved tools too restrictive? Does getting a new application approved take too long? Can the current list of approved tools meet the demands of employees' actual workflows?
Employees may need clear guidance on why they cannot use just any tool for official business matters. However, providing effective software and hardware solutions can greatly reduce shadow IT risks within the organization.

