Shadow IT is the software, cloud accounts and devices your team uses for work that nobody responsible for your technology knows about. The UK’s National Cyber Security Centre calls these “the unknown assets that are used within an organisation for business purposes.” No approval, no record, no oversight. If an insurer’s questionnaire or a vendor pitch put the term in front of you, the real question is whether your approved software list is the whole picture.
It might not be. Company information can end up in places your access controls and backups never reach, and you can’t manage a risk you don’t know exists. The same gap shows up when someone asks you to prove how your business handles data, and again when you find you’ve been paying for a tool nobody remembers buying.
Finding out what’s in use isn’t a big project. It’s a look at what you’re paying for, a conversation your team won’t get punished for, and a standing way to hear about the next tool before it holds client data.
What Counts as Shadow IT?
It’s anything doing work for your business that your technology setup doesn’t account for. Someone signs up for a trial with a work email. Client files land in a personal cloud storage folder. Contract language gets pasted into an AI chatbot. Hardware counts too — a personal laptop, or a device plugged into the office network that nobody configured.
Software and Cloud Accounts
Signing up for these takes a work email and a password, which is why they’re the part of the picture worth starting with. A few shapes it takes:
- A free trial that quietly became a paid subscription on someone’s personal card, reimbursed as an expense.
- A file-sharing or cloud storage account created to send a client something too large for email.
- A task tracker one department adopted because the company system didn’t fit how they work.
- A messaging or video tool a client preferred, now holding conversations about active work.
- A spreadsheet exported to a personal account so someone could finish it from home.
AI Tools That See Your Information
AI assistants follow the same pattern with higher stakes. Someone pastes a customer list or a contract clause into a chatbot to get a usable draft back faster. If the account is personal, that information left your business through a door you can’t see, and you’d have no answer if a client asked where their data went. The tool isn’t the problem. Not knowing it’s in use is.
Why Do Employees Use Tools Nobody Approved?
Because the approved path was slower than the work. Someone had a client waiting. The sanctioned tool couldn’t do what was needed, and a free account solved it in the moment. Nobody set out to create a risk. They were routing around friction, which is what capable people do when a process gets in the way.
Sometimes there was no approved path at all. A new hire brings the tool they used at their last job and assumes it’s fine. Someone asks a coworker instead of asking you, because asking you means waiting. None of that is a discipline problem, and treating it as one guarantees you’ll hear about the next tool even later than this one.
That framing matters for what comes next. If people expect consequences, they won’t tell you what they use, and you’ll keep finding out the hard way — from a departing employee, a security review, or a questionnaire you can’t answer honestly.
How Do You Find Out What Your Team Is Already Using?
Three places give you an honest picture without special tools. Look at recurring charges on your card and bank statements for names nobody recognizes. Ask your team directly, and say plainly that nothing anyone admits will come back on them. Then check what’s connected to your core business systems, because access granted once can outlive the reason for it.
Start with the money. Recurring charges are the closest thing to an inventory you already own. Scan card and bank statements for subscription names nobody in the room can place, then check expense reimbursements for the same thing bought on a personal card. Free accounts won’t appear anywhere in there, which is exactly why the next step matters.
Ask, without making it an interrogation. The question that works is “what do you use to get your work done?” — not “what did you install without permission?” Ask what problem each tool solves, too. That answer tells you whether your approved setup has a gap, and a gap you close is a gap that stops generating workarounds.
Check what already has access. Look at what’s connected to your email, your file storage, your accounting system and your customer records — things that were granted access at some point and kept it. A forgotten connected app can hold a live connection to a core system long after anyone remembers using it.
What Do You Do After You Find Something?
Pick one of two outcomes for each thing you find: approve and secure it, or retire it. Approving means a company account, a named owner and the same protections the rest of your systems get. Retiring means getting the data back, closing the account, and confirming it’s closed rather than dormant. Limbo is the one outcome that helps nobody.
Because O&O’s IT asset management service is built to give a business a clear view of every asset from hardware to software, our recommendation is to treat a newly found app or account the same way: decide whether to approve and secure it or retire it, then add it to that record so it doesn’t disappear again.
Without someone inside the business tracking it, that record is worth handing off. IT asset management that covers hardware and software is built for that, down to managing which employees can access specific devices or software instead of leaving that to whoever created the account.
Some of what you turn up is a money question more than a security one. Duplicate subscriptions, an account still billing for a project that ended, software licenses nobody uses — that side deserves its own pass once the security decisions are made.
If what pushed you here was a compliance review or a questionnaire you couldn’t answer, a cybersecurity and compliance assessment is the closer fit. Uncovering what’s exposed and keeping written security policies current is what turns audit-readiness into a standing condition instead of a scramble.
Then keep the door open, or you’ll be doing this again. Give people one obvious place to ask for a tool and a yes that doesn’t require a committee. If asking is easier than working around you, you’ll hear about the next tool before it holds client data. Revisit the picture when something changes — a new hire, a new client contract with security terms, a departure, a security review.
Frequently Asked Questions
Is shadow IT always a security problem?
No. Some of what you find will be useful — a tool that solves a real gap in how your team works. The problem is judgment. You can’t weigh the risk of something you don’t know exists, and you can’t account for where your data sits when part of it is invisible to you.
Should we block employees from installing software themselves?
Restrictions alone can push the workaround somewhere you see even less, like a personal device or a personal account. If you tighten what can be installed, pair it with a fast way to request what people need. Visibility plus a reasonable yes beats a wall nobody tells you they climbed.
What if a tool is free and never shows up on a statement?
That’s the part a financial review misses. Free accounts, browser extensions and trial signups leave no billing trail, so the way to find them is to ask — and to make it safe to answer. Handoffs and departures are another moment where free tools surface on their own.
What happens to company data in an account after that person leaves?
If the account was personal, the data can leave with them, and you may have no way to recover or delete it. Offboarding is a good moment to ask what someone used and where the work lives, while they’re still there to answer. Asking after they’re gone leaves you guessing.
How often should we look for tools nobody approved?
Tie it to events rather than a date on the calendar. A new hire, a new client contract with security terms, a departure, a compliance review — each is a reason to ask again. Between those moments, a standing request path does the work, because new tools announce themselves instead of hiding.
Find Out What’s Running in Your Business
You don’t need every answer before you start. A look at recurring charges and one honest conversation will tell you more than your approved software list does. If you’d rather not sort it out alone, contact O&O Systems about a technology assessment.