GlossarySecurity awareness

Shadow IT

Short answer

Shadow IT is the use of applications, cloud services, devices or AI tools for work without the knowledge or approval of IT or security. It usually starts with good intentions, but it leaves company data in places nobody controls or protects.

Why it happens

Teams need a tool quickly, sign up with a work email and a card, and start working. Free plans, browser extensions, personal file sharing accounts and messaging apps all make this easy. More recently, employees using AI assistants that are not approved, sometimes called shadow AI, has become the fastest growing form.

The risks

Data ends up in services with unknown security, no contract and no data processing agreement. Accounts often stay active after people leave the company. Nobody reviews the configuration, so files can be shared publicly by mistake. A leak from one of these services can be a data breach the company did not know it could have.

How to manage it

Banning everything rarely works and pushes usage further out of sight. A better approach is to discover what is in use through SaaS management and identity logs, approve good tools quickly, offer sanctioned alternatives, assess new providers through TPRM, and use DLP to limit what sensitive data can leave. A clear policy on AI tools is now part of this.

Where it shows up in compliance

Shadow IT undermines the asset inventory, supplier management and access control requirements of ISO 27001, the ENS and SOC 2, and auditors often find it when they compare the official inventory with what is really in use.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub