Ask a small business owner which software their organisation uses and you will get a list of six or eight things. Audit the actual usage and the number is usually several times higher. Staff sign up for tools that solve immediate problems, using work email addresses and sometimes company cards, and nobody records it.
This is shadow IT, and the instinctive response — banning it — is both impractical and counterproductive.
Why it happens
Shadow IT is almost always a symptom rather than a discipline problem. Someone had a job to do, the sanctioned tools did not do it, and a free or cheap service did. The file was too large for email, so it went through a file transfer site. The team needed to coordinate, so they made a group chat. Someone needed to sign a document, so they used whatever came up first.
Treating this as staff misbehaviour misreads it. People adopting tools to do their work better are demonstrating initiative; what they lack is a way to get tools approved quickly enough to bother asking.
The actual risks
Being clear about the risks helps prioritise, because they are not all equally serious.
Data leaving your control. Company information in an account the business does not own, subject to terms nobody read, potentially stored offshore. When the employee leaves, the data goes with them or becomes inaccessible.
No offboarding. Your IT offboarding covers the systems you know about. The seven you do not remain active indefinitely, still holding company data, still logged in on a personal device.
Weak authentication. Shadow tools rarely have enforced two-factor or single sign-on, and are frequently protected by a reused password.
Compliance and privacy exposure. If customer personal information is in an unapproved service, your privacy obligations still apply. You are accountable for data you did not know you were holding.
Silent dependency. A process quietly comes to depend on a free tool with no contract and no support. When it changes its pricing or shuts down, a business function stops.
Finding it
Several approaches work and none are complete on their own. Review card and expense statements for recurring small charges — this finds paid services quickly. Review the sign-in and application consent logs in Microsoft 365 or Google Workspace, which reveals anything staff authenticated with a work account. Check DNS or firewall logs for traffic to services you do not recognise.
Then ask. A survey framed as “what tools do you use to get your job done, including anything you signed up for yourself” collects more than any technical measure, provided the framing is genuinely non-punitive. If people believe they will be in trouble, they will not tell you.
What to do with the list
Sort it into three groups. Adopt the things that are genuinely useful — bring them under company ownership with proper accounts, billing and access control. Replace the ones that duplicate something you already pay for, and make sure people know the sanctioned tool exists and how to use it. Remove the ones that are genuinely inappropriate, and explain why rather than simply blocking them.
The middle category is worth pausing on. Businesses frequently discover they are paying for a capability nobody uses because it was never rolled out properly, while staff pay separately for an alternative.
Prevent the next round
The durable fix is a fast, low-friction approval path. If getting a tool approved takes a fortnight, people will keep going around it. A single form, a named person, and a two-day turnaround stops most shadow IT at the source.
The other half is closing the capability gaps that caused it. Where staff have adopted a dozen small tools to move data between systems by hand, the real requirement is usually an integrated workflow between the systems you already own — build that and the shadow tools disappear on their own, because nobody was attached to them in the first place.
Make it recurring
Shadow IT regenerates. An annual review, plus a check of application consents each quarter, keeps the list manageable. Done once, it is a project; done regularly, it is twenty minutes.