Skip to content
Consultancy · · 3 min read

Shadow IT: the apps your employees use without you knowing

Free apps, personal cloud storage and AI tools nobody ever approved. Why shadow IT happens, what the real risks are, and how to fix it without a witch-hunt.

By Limburg Cyber Group

An employee puts a large file for a client on a free file-transfer site. Another keeps their schedule in an app they also use at home. A third pastes a client email into a free AI chatbot to turn it into a tidy reply. Nobody means any harm, but none of those tools was ever chosen by the business. This is called shadow IT: software and services used for work outside the organisation’s view.

Why it happens

Shadow IT is rarely a matter of bad intent. Usually people are simply trying to get their work done faster or more easily. The official route is cumbersome, nobody knows who decides on software, or what the business provides does not do what they need. Setting up a free account then takes a minute.

That matters for how you approach it. Treat shadow IT as an offence and you get a game of hide-and-seek. See it as a signal and you learn where the real needs are.

The real risks

The problem is not that such a tool is necessarily bad, but that you have no control over it.

  • Client data outside your control. You do not know where it is stored, who can reach it or how long it is kept.
  • The GDPR. If a service processes personal data on behalf of your business, you need a data processing agreement, among other things. With a free account an employee set up themselves, your business has usually not made those arrangements. With AI tools, text you enter may also be stored or used to train the model, depending on the service and its settings. See using ChatGPT at work and the GDPR.
  • No offboarding. When an employee leaves, you block their work account. But the personal account with that shared client folder keeps working.
  • Lost files. Whatever sits in someone’s own storage is not in your backup and is gone when that account disappears.
  • Weak security. No MFA, a reused password, and nobody who notices when the account is taken over.

Finding out what is in use, without a witch-hunt

Start by asking, not checking. Explain in a team meeting why you are doing this and ask: which apps and sites do you use for your work, and what is missing from what we have now? Make clear that nobody will get into trouble. You get more honest answers when people know the aim is a better way of working.

Add to that what you can already see yourself:

  • expense claims and bank statements showing small subscriptions;
  • in Microsoft 365 or Google Workspace: which third-party apps employees have given access to their work account;
  • depending on your network equipment and security software: an overview of the cloud services used from the office.

How to fix it

  1. A short list of approved tools. One choice per need: sharing files, sending large files, notes, scheduling and AI. Choose business versions with sound arrangements for your data.
  2. An easy way to request something new. One point of contact and a quick answer. If a request takes weeks, people will go and find something themselves again.
  3. Clear rules for AI tools. Which tools are allowed, which data never goes in and who checks the output. How to fit that on one page is covered in drawing up an AI policy.
  4. Clean up. Move business data out of tools that do not make the list and close those accounts.
  5. Write it down. Add the list and the rules to your IT policy and review them every year.

Technical measures help too, such as preventing employees from connecting third-party apps to their work account on their own. But without a good alternative, the problem simply moves elsewhere.

Control without slowing down

The aim is not to lock everything down, but to make sure the tools that genuinely help your team are also safe. We work with you to map what is in use and draw up a workable list and clear agreements. See our consultancy & advice service or book a conversation.

Read more

Consultancy ·

Cyber insurance for SMBs: necessary or not?

Cyber insurance can soften the blow of an incident, but it covers far from everything. What it is and is not for, and what to watch in the small print.

Read more 2 min read

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.