Shadow IT: How to Find and Manage Unapproved Tools

Shadow IT is technology used for work outside the organisation’s approval or oversight. It can include apps, personal accounts, devices, browser extensions and integrations. The risk depends on what data they handle, what access they have and whether the business can manage ownership, security and continuity.

 

The aim is to discover what is being used, understand the need it meets, and decide whether to approve, replace or retire it. This guide covers how to find shadow IT, how to weigh the risk of each tool, how to retire tools safely and how to make the approved route easier than the workaround.

The National Cyber Security Centre describes unsanctioned IT as an ordinary problem: people adopt tools to work faster or to get around a gap the approved tools leave, not to cause harm. Treating it as a discipline problem can push it further out of sight, while understanding the gap it fills points to a better approved option.

What counts as shadow IT?

It covers any technology used for work that the business has not approved or cannot oversee. Common examples include:

  • Personal accounts. Work files shared through personal email, messaging apps or personal cloud storage.
  • Unapproved cloud apps. Teams running projects, notes or customer lists in free or paid apps signed up for without approval.
  • AI tools. Staff using personal or free AI accounts with business information.
  • Browser extensions. Add-ons that can read pages, email or calendars in the background. Our guide to browser security covers the risks.
  • Devices. Personal laptops, phones or USB drives used to store or move business data.
  • Integrations and app consents. Third-party apps that staff connect to business accounts, granting access to mailboxes or files.

Approval and risk are different questions

An approved app used badly is not automatically shadow IT, and an unapproved app is not automatically insecure. A stale account for a former staff member in an approved system is an access-management issue. It becomes part of shadow IT when the underlying tool or use sits outside the organisation’s oversight.

Keeping the two questions separate makes the response more precise. Visibility tells you what exists. Risk depends on what each tool holds, what it can reach and whether the business can control it.

How does shadow IT relate to SaaS sprawl?

SaaS sprawl is the accumulation of cloud applications across the business, approved or not. Shadow IT overlaps with it, but it also includes devices, extensions and other technology, so it is not simply a subset of SaaS sprawl. Subscription and licence control belongs to SaaS management; this guide focuses on discovering and deciding what to do with unapproved technology.

What risks does shadow IT create?

Unapproved tools do not remove every control. Existing device or network protection may still apply. The gaps are more specific: the business may not know who owns the account, what it shares, how long it keeps data or whether it can be recovered.

  • Ownership. The account may belong to one person, so the business loses access when they leave.
  • Access. A tool connected to a mailbox or file store may reach far more information than its users realise.
  • Sharing and retention. Files may be shared publicly or kept long after they are needed.
  • Sign-in. The account may not use multi-factor authentication or business sign-in.
  • Recovery. Work stored in the tool may not be backed up or exportable.
  • Cost and renewals. Subscriptions on personal cards or expense claims are hard to track and cancel.

Risk depends on the tool rather than the count. One tool with broad mailbox access or sensitive records can matter more than many low-risk apps used for harmless tasks.

What about privacy obligations?

Your business remains responsible for how it handles personal information when staff use cloud services. Review what is collected or uploaded, who can access it, how it is used and how it can be retrieved or deleted. A provider’s own responsibilities depend on its role and use of the information.

Offshore storage is not automatically a breach. The Privacy Commissioner distinguishes a provider that processes information on your behalf from one that uses it for its own purposes. Our guide to NZ Privacy Act compliance covers your obligations in more detail.

Does shadow IT affect cyber insurance?

Cover depends on your policy wording, disclosures and the circumstances of the incident. Unapproved systems may create issues where they conflict with policy conditions or information supplied to the insurer. Ask your broker or insurer how your policy treats them.

How do you find shadow IT?

No single source finds everything. Combine several and record what each one cannot see, so the gaps in your picture are known rather than assumed.

Where to look for shadow IT and what each source misses: staff conversations, purchasing and expenses, device and software lists, browser extensions, sign-ins and app consents, and network logs

  • Staff conversations. Ask each team what they use and why. This finds the need behind a tool, but depends on what people remember.
  • Purchasing and expense records. These show paid subscriptions, but miss free apps and personal accounts.
  • Device and software inventories. These show what is installed on managed devices, but miss unmanaged ones.
  • Browser extension inventories. These cover managed browsers only.
  • Sign-ins and app consent records. These show third-party apps connected to business accounts. A Microsoft 365 permissions audit reviews them in detail.
  • Network logs. These show contact with a service on traffic the business can see, but not which account was used or what was uploaded.

Specialist discovery tools rely on the same sources. Microsoft documents how its cloud discovery works through specific integrations and a catalogue of known apps, so check what a tool covers before relying on it for a full picture. Endpoint protection is not automatically a complete discovery service.

Keep the review authorised and proportionate

Treat discovery as an authorised review of relevant business records and logs. Define its purpose, who has access to the findings and what is in scope, and explain the monitoring to staff. Personal accounts are not part of a routine discovery exercise.

Give staff a no-blame way to declare the tools they already use. People are more willing to describe their workarounds when the aim is to support the work rather than punish the shortcut.

Can a firewall find all shadow IT?

No. It can reveal some activity on traffic it sees, but it does not provide a complete inventory of personal accounts, off-network activity or data stored inside every app.

How do you decide what to do with each tool?

A short record for each tool turns a long list into decisions. Start with the tools that hold sensitive information or have broad access to business systems.

Six things to record for each shadow IT tool: purpose and owner, information and access, controls, commercial dependency, decision, and follow-through

Record Question to answer
Purpose and owner Who uses it, why, and who owns the business account?
Information and access What data is held or uploaded? What mailbox, files or other systems can it reach?
Controls Which sign-in, sharing, logging and recovery controls are actually configured?
Commercial dependency Who pays, when does it renew, and what work stops if access is lost?
Decision Approve with conditions, replace, retire, or investigate further?
Follow-through Who acts, by when, and when will any temporary approval be reviewed?

Weigh the business value of each tool against the sensitivity of the information it holds and the access it has. A useful tool that holds little sensitive data may need only a named owner and business sign-in, while a tool connected to customer records or a shared mailbox needs a fuller review before any decision.

Approving a tool brings it under the same ownership, sign-in and recovery arrangements as other business systems. Replacing it means moving the work to a tool you already support. Retiring it means removing it safely, as described below. Where the answers are unclear, investigate further before deciding.

What about temporary exceptions?

An interim exception needs an owner, a permitted use and a review date. Multi-factor authentication or central monitoring may not be available on a personal or free account, so do not assume they can be enforced. Where acceptable controls are unavailable, restrict or stop the affected use.

How do you retire a shadow IT tool safely?

Cancelling a subscription is the last step, not the first. Retiring a tool too quickly can lose records the business needs or break work that depends on it.

Retiring a shadow IT tool safely: map dependencies, keep required records, move and verify, remove access, then cancel billing and confirm data deletion

1

Map the dependencies

Identify the work, people and integrations that rely on the tool.

2

Keep the records you need

Export and store any business records the business must retain.

3

Move and verify

Move the work to the replacement and confirm it works before going further.

4

Remove access

Remove users and integrations, and revoke tokens or app consent as appropriate.

5

Cancel and confirm

Cancel billing and confirm the data deletion arrangements with the provider.

Urgent exposure may require containment before migration is complete. If a tool is leaking sensitive information, restrict access first and recover the work afterwards. Our guide to identity and access management covers removing access cleanly.

How should you handle shadow AI?

Shadow AI is AI use that sits outside the business’s approval or oversight. Before approving a tool, check the account and plan, how inputs and outputs are used and retained, what connected systems it can access, and whether those arrangements fit the information involved. Set clear rules on permitted data and give staff a straightforward way to request access.

Plans, settings, retention, integrations and terms differ between AI products, so check each one rather than relying on a general rule. Business branding alone does not establish that a tool is approved for a particular type of information. An AI acceptable use policy sets out what staff may use and for what.

What if sensitive information has already been uploaded?

If sensitive information has already been uploaded, stop further sharing and report it through the business’s incident process. Record the tool, account, information and access involved so the response can be assessed. Do not assume that deleting a chat removes every retained copy. Our incident response plan guide covers how to prepare that process, and AI data security covers the technical controls.

How do you make the approved route easier?

Workarounds grow where the approved route is slow, unclear or does not meet the need. Making the approved path easier reduces the reasons to go around it.

  • Publish an approved list. A short list of approved tools by category, so staff can find what is already available.
  • Offer a simple request route. One form or contact for new tool requests, with a named person who responds.
  • Decide with agreed criteria. Use the same questions as the triage record, so decisions are consistent and explainable.
  • Explain the outcome. When a request is declined, say why and suggest an approved alternative.
  • Revisit the list. Add tools that meet a real need, and remove ones nobody uses.

Technical controls help where they can be applied. Endpoint security can limit what is installed on managed devices, and zero trust security controls access to business systems. Neither governs personal accounts in external services, which is why the approved route and the policy matter.

What should a shadow IT policy cover?

The policy should be short, in plain English and easy for any staff member to follow. It should cover:

  • What approved means. The tools staff can use and where to find the list.
  • How to request something new. The route, who decides and what information to provide.
  • Information rules. Which types of business and personal information can go into which tools.
  • Personal accounts and devices. When they can be used for work, if at all.
  • AI tools. Which AI tools are approved and what can be entered into them.
  • Declaring tools. A no-blame route for staff to declare tools they already use.
  • Reporting. How to report a mistake, such as uploading sensitive information to the wrong place.

Explain why it matters in business terms: protecting customer information, keeping access to the work when people leave and knowing what the business pays for. Security awareness training can reinforce the policy with practical examples.

How do you keep shadow IT under control over time?

Discovery is not a one-off project. New tools appear as the business changes, staff join and leave, and suppliers add features to the products you already use. Build checks into normal routines so new tools are found while they are still easy to deal with.

  • Regular reviews. Check sign-ins, app consents, expense records and renewals at an interval that suits the business.
  • Joiners and leavers. Include tool access in employee IT onboarding and offboarding, so accounts are created and removed deliberately.
  • An asset register. Record approved tools, owners and renewal dates alongside devices in your IT asset management records.
  • Exceptions. Review temporary approvals on their due date rather than letting them become permanent.

Measure progress by the share of tools with a named owner, the decisions completed and the exceptions that are overdue. These show whether unapproved technology is being managed, rather than whether it has disappeared.

Managing shadow IT with Exodesk

Not sure which tools your staff rely on? Exodesk can help you identify unmanaged apps, prioritise the risks and put a workable approval process in place. Exodesk has supported businesses in Christchurch, Dunedin and across New Zealand since 1989.

See our managed IT services or talk to us about what you want to bring under control.

Frequently Asked Questions

What is shadow IT in simple terms?

Shadow IT is technology used for work outside the approval or oversight of the business. It includes apps, personal accounts, devices, browser extensions and integrations that staff adopt to get their work done.

Is shadow IT illegal?

Shadow IT is not illegal in itself. It can create problems with legal obligations, such as privacy duties, when personal information is handled in tools the business cannot oversee. Liability depends on the facts and the applicable law.

Can a firewall find all shadow IT?

No. It can reveal some activity on traffic it sees, but it does not provide a complete inventory of personal accounts, off-network activity or data stored inside every app.

What is the difference between shadow IT and SaaS sprawl?

SaaS sprawl is the accumulation of cloud applications, approved or not. Shadow IT overlaps with it but also includes devices, browser extensions and other technology outside the oversight of the business.

How do I find out what shadow IT exists in my business?

Combine several sources: staff conversations, purchasing and expense records, device and software inventories, browser extension lists, sign-in and app consent records, and relevant network logs. Each source misses something, so record what each one cannot see.

Should we ban all shadow IT?

A blanket ban can push use further out of sight. Discover what is in use, understand the need each tool meets, and decide whether to approve it with conditions, replace it or retire it.

Who is responsible for shadow IT in a business?

The business is responsible for the information it handles and the decisions it makes about tools. Day-to-day roles, such as who approves tools and who reviews access, should be set out in the policy and assigned to named people.

Does cyber insurance cover incidents involving shadow IT?

Cover depends on your policy wording, disclosures and the circumstances of the incident. Unapproved systems may create issues where they conflict with policy conditions or information supplied to the insurer. Ask your broker or insurer how your policy treats them.

How do AI tools fit into shadow IT?

AI tools used outside the approval or oversight of the business are a form of shadow IT, sometimes called shadow AI. Check each tool for how inputs are used and retained and what it can connect to, then set clear rules on permitted information.

What should we do if staff have uploaded sensitive information to an AI tool?

Stop further sharing and report it through your incident process. Record the tool, account, information and access involved so the response can be assessed, and do not assume that deleting a chat removes every retained copy.

Can we approve a shadow IT tool temporarily?

Yes, with an owner, a permitted use and a review date. If acceptable controls such as business sign-in are not available on the account, restrict or stop the affected use instead.

Are browser extensions shadow IT?

They can be. Extensions installed without approval can read pages, email or calendars in the background, so include them in discovery and approve only the ones the business needs.

How long does it take to get shadow IT under control?

It depends on how many tools are in use, how sensitive the information is and how quickly decisions can be made and acted on. Start with the tools that hold sensitive information or have broad access, and keep reviewing as new tools appear.

NEXT STEP

Not sure which tools your staff rely on?

Talk to us about the tools you want to bring under control. We can help identify unmanaged apps, prioritise the risks and set up a workable approval process.

Or see our managed IT services.

Start typing and press Enter to search

Remote work IT: a protected laptop set up for working from homeNZ Privacy Act and cybersecurity: a personal information record protected by a shield and padlock Call Us Now