The Hidden Risks of Shadow IT

Image: Pixabay via Pexels
It usually starts with good intentions. Someone on your team discovers a handy app that makes their job easier — maybe it’s a slick AI writing tool, a free file-sharing service, or a project management platform a colleague recommended. They sign up with their work email, start uploading documents, and get on with things. No IT ticket raised. No approval sought. No one else in the organisation knows it’s happening.
This is shadow IT, and it’s far more common than most managers realise.
Why It Happens
Shadow IT isn’t usually born out of carelessness — it’s born out of friction. When the approved tools feel clunky, slow to procure, or simply don’t exist for a particular task, staff find their own solutions. It’s a natural human response to wanting to do good work. The challenge is that these workarounds can quietly introduce serious risks to your organisation, often without anyone realising until something goes wrong.
The problem has grown significantly with the rise of AI tools. A recent feature in Infosecurity Magazine highlights how “shadow AI” is emerging as one of the next big governance headaches for security leaders — staff experimenting with AI assistants and automation tools outside of any sanctioned framework, often feeding sensitive data into platforms with unknown privacy and data retention policies.
What’s Actually at Risk
For organisations in sectors like law, health, or government — where data sensitivity is high — the stakes are real. When staff use unapproved cloud services, you lose visibility and control over where your data is going. Common risks include:
- Data sovereignty concerns — files stored on overseas servers may not meet your legal or regulatory obligations
- Licensing and compliance exposure — using tools outside your procurement process can create audit and liability issues
- Security vulnerabilities — unsanctioned apps may lack the security controls your IT team would normally require
- No backup or recovery — if data lives in an app your IT team doesn’t know about, it won’t be included in your backup strategy
Managing It Without Playing the Villain
The answer isn’t to lock everything down so tightly that people can’t do their jobs — that just drives shadow IT further underground. The better approach is to understand why people are reaching for outside tools, and use that insight to improve what you officially offer.
Start by having open conversations with your team about what tools they’re using and what gaps they’re trying to fill. Pair that with a clear, simple process for requesting new software — one that doesn’t take months. CERT NZ’s guidance on application control is a useful reference for building a practical framework around this.
Regular audits of cloud service usage, combined with a pragmatic acceptable use policy, go a long way. The goal is visibility and trust — not surveillance.
If you’re not sure where to start or want help reviewing what’s running across your environment, our team is always happy to help.
Chris Drowley
General Manager, Resolve Technology
Outside the office, Chris runs a highly organised empire of model trains — where the schedules are always on time, unlike the real thing.
Need help with this?
Resolve Technology can help. Learn more about our Cyber Security Services services, or get in touch to discuss your needs.
