← All terms

Shadow IT

Shadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.

Shadow IT is any application, device, cloud service, or account used for work without the knowledge or approval of the IT and security teams — the marketing team's unofficial file-sharing tool, a developer's personal-cloud test environment, a spreadsheet macro doing finance's reporting, or an employee pasting customer data into an unvetted AI chatbot. It is rarely malicious; it is what people do when the sanctioned tool is slower than the job. But every unsanctioned tool is attack surface the security team cannot see, patch, monitor, or include in its incident response.

How it becomes a security problem

Shadow IT breaks the assumptions defenses are built on. Credentials for unsanctioned services sit outside single sign-on and MFA policy, so a password reused from a breached consumer site quietly exposes work data to credential stuffing. Corporate data copied into personal drives or messaging apps survives offboarding, feeding insider risk long after the employee leaves. OAuth connections granted to third-party apps become standing access nobody reviews — the same mechanism consent phishing abuses deliberately. And when an unsanctioned service is breached, the organization often learns about it from the news, because the service never appeared in any asset inventory. IBM's Cost of a Data Breach research has found that breaches involving data spread across unmanaged environments cost more and take longer to contain than average.

The social-engineering angle cuts both ways: attackers impersonate popular unsanctioned tools in phishing lures ("your Dropbox is full"), and employees who are used to adopting tools without asking are also used to entering their credentials in new places without suspicion.

How to defend against it

  • Discover before you punish. Use SSO logs, DNS/CASB data, and expense reports to inventory what people actually use — then ask why. Every shadow tool is a requirements document for a sanctioned one.
  • Make the paved road faster. Approval processes measured in weeks guarantee shadow adoption. Offer a rapid vetting lane and a clear, short allowlist request path.
  • Fold it into human risk. Unsanctioned-tool usage is a measurable behavior, and it belongs in a human risk score beside phishing-simulation results — and in your incident response scoping, because the blast radius of a compromised employee includes every tool they adopted off the books.

Related terms

Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.Account Takeover (ATO)Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.Consent PhishingConsent phishing tricks users into granting a malicious OAuth app access to their cloud account — bypassing passwords and MFA entirely via legitimate consent screens.Credential StuffingCredential stuffing is an automated attack that tries username-password pairs stolen from one breach against many other sites, exploiting password reuse.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo