Shadow IT
Shadow IT is the use of applications, cloud services, accounts and tools without the knowledge or approval of the IT team. Employees usually do not bring them in to cause a problem but to get the work done faster: a file needs sharing, a team needs a chat, marketing needs a tool, sales needs a PDF now.
Term
description · examples · notesShadow IT is the use of applications, cloud services, accounts and tools without the knowledge or approval of the IT team. Employees usually do not bring them in to cause a problem but to get the work done faster: a file needs sharing, a team needs a chat, marketing needs a tool, sales needs a PDF now.
Description
The problem is that IT activity spreads beyond the organization's oversight. IT cannot protect a service it does not know exists, cannot switch on MFA for an account that is not registered, cannot back up data that ended up in a private cloud, and cannot enforce rules over a tool that is not part of the system.
Shadow IT is often a symptom rather than merely a breach. If the official tools do not do the job, employees find their own. But the consequence stays the same: data, identities and business processes move into a space with no control, no contract, no records and no recovery plan.
Examples
- A team uses a free online file-sharing service for internal documents, because the official process is slow.
- An employee sends business data through a private messaging app, because it is simpler that way.
- A department buys a SaaS tool on its own and puts client data into it with no risk assessment.
Notes
- Shadow IT is not solved by prohibition alone. If people are not given a usable tool, they will make one themselves.
- The first step is visibility: finding out what is being used, why it is being used, and which data ends up there.
Mentioned in the news
- 22. JUN 2026. Shadow AI više nije samo pitanje curenja podataka, već i pitanje pristupa →
- 28. MAR 2026. Kako bi CISO trebalo da odgovori na shadow AI u organizaciji →
- 4. MAR 2026. Kako piratski softver pretvara zaposlene u distributere malvera →
- 2. APR 2026. Ne blokirati rad, već rizik: zašto pristup Doctor No postaje problem →
- 23. MAR 2026. CISO-i menjaju pristup zaštiti podataka zbog AI talasa →
Techniques
carried out with 3Techniques used to carry it out. Select one to open its page.
Defenses
countered by 7How it is defended against. Select one to open its page.