Shadow IT
IT systems, solutions, and activities carried out within an organization without IT department approval.
Shadow IT refers to all applications, cloud services and hardware used within an organisation without IT approval or oversight. A SaaS subscription bought on a marketing team's company card, a file transfer tool adopted by one office, a free account opened to work around a blocker: all of it is Shadow IT.
The phenomenon is widespread and systematically underestimated. Gartner estimates that 30 to 40% of IT spending in large enterprises falls outside the IT budget, and field audits routinely uncover three to five times more applications than IT believed it managed.
One important point: Shadow IT is not a discipline problem. It is a signal. It appears wherever the official offering is too slow, too rigid, or missing entirely.
Where Shadow IT comes from
Four dynamics feed it:
- •Friction in internal processes.: When getting a tool takes six weeks and a free trial takes two minutes, the trade-off makes itself.
- •The democratisation of SaaS.: Every serious application is now available by credit card, with no installation or technical involvement.
- •Hybrid work.: Teams adopt their own collaboration tools when the provided ones fall short.
- •Generative AI.: The most recent and fastest wave: consumer AI assistants are used at scale in the workplace, often with internal data. This is now known as Shadow AI.
The forms Shadow IT takes
- •Unlisted SaaS applications: project management, design, e-signature, transcription.
- •Personal accounts used for work: cloud storage, email, shared drives.
- •Browser extensions: , often highly permissive about the data they can read.
- •Business-built solutions: business-critical spreadsheets, no-code automations, scripts.
- •Cloud resources: provisioned outside procurement.
- •Personal devices: connected to corporate systems (BYOD).
The real risks
Security. An unknown application is neither audited, patched, nor monitored. It bypasses SSO and strong authentication, widening the attack surface in ways nobody can measure.
Compliance. GDPR requires knowing where personal data is processed. NIS2 and DORA mandate an up-to-date map of assets and suppliers. An unlisted tool is a pre-documented breach.
Cost. Functional duplicates, forgotten subscriptions, unit pricing with no volume discount: Shadow IT mechanically degrades application TCO.
Continuity. A critical tool held by one person becomes a single point of failure the day they leave. Data is neither backed up nor portable.
Data quality. Parallel repositories produce diverging figures, and trust in reporting erodes.
How to detect Shadow IT
No single method is sufficient on its own: reliable visibility comes from combining them.
- •Network traffic and DNS analysis: — effective in the office, blind for remote work.
- •SSO portal logs: — precise, but only sees applications already connected to the directory.
- •Installed program and extension inventory: via an endpoint agent.
- •Expense analysis: — company card statements and expense claims, remarkably effective for SaaS subscriptions.
- •Employee surveys: — the simplest method, often the most revealing, provided it is run without a punitive framing.
Continuous automated discovery, across both endpoints and spending, remains the only approach that holds up over time.
How to manage Shadow IT rather than endure it
Banning does not work: it pushes the phenomenon out of reach. An effective approach unfolds in four stages:
- Make it visible. Establish the real inventory before making any decision. You cannot govern what you cannot see.
- Qualify by risk. Not all applications are equal. Three tiers — critical, to be supervised, tolerated — are enough to prioritise.
- Decide. Three possible outcomes per tool: bring it into the official catalogue, replace it with an approved alternative, or eliminate it. Bringing it in is often the best choice: if a tool is being used, it meets a real need.
- Reduce friction at the source. A readable catalogue, a short lead time and a simple request channel do more against Shadow IT than any blocking policy.
From Shadow IT to Shadow AI
Generative AI is replaying the same pattern, faster. Employees use consumer assistants to write, code and analyse — sometimes with confidential data, in services that may reuse it.
The same principles apply: detect actual usage, assess real risk, then offer a governed alternative rather than a ban. The topic is covered in detail in our Shadow AI definition.
Detecting and governing Shadow IT with Kabeen
Kabeen automatically discovers the applications actually in use — including those IT does not know about — by combining signals from endpoints, browsers and the directory. That is the purpose of our Shadow IT detection module.
Every discovered application is qualified and linked to its real usage, cost and owner. You move from a blind spot to a governed portfolio, without blocking your teams.
Questions fréquentes
What is Shadow IT?
Shadow IT refers to all applications, cloud services and hardware used within an organisation without IT approval or oversight: SaaS subscriptions bought on company cards, personal accounts used for work, browser extensions, business-built solutions. Gartner estimates that 30 to 40% of IT spending in large enterprises falls outside the IT budget this way.
What are the risks of Shadow IT?
The risks fall into five categories: security (an unknown application is neither audited, patched, nor covered by SSO), compliance (GDPR, NIS2 and DORA all require knowing where data is processed), cost (duplicates and forgotten subscriptions degrade TCO), business continuity (a critical tool held by one person is a single point of failure) and data quality (parallel repositories produce diverging figures).
How do you detect Shadow IT in a company?
Five methods complement each other: network traffic and DNS analysis, SSO portal logs, inventory of installed programs and browser extensions via an endpoint agent, expense analysis across company cards and expense claims, and employee surveys. None is sufficient alone: reliable visibility comes from combining them continuously.
Should Shadow IT be banned?
No: banning pushes the phenomenon out of reach without removing it. Shadow IT is primarily a signal — it appears where the official offering is too slow or missing. The effective approach is to make actual usage visible, qualify applications by risk level, then decide between bringing them into the catalogue, replacing or eliminating them — while reducing the friction that caused the workaround in the first place.