Cloud & SaaS

Shadow IT discovery: how to find and govern the apps IT cannot see

Key takeaways
  • Shadow IT emerges to solve real needs quickly, not out of bad intent.
  • Its risks: data leakage, non-compliance, orphaned accounts and duplicated costs.
  • It is discovered through DNS and proxy logs, CASB, SSO sign-ins and spend analysis.
  • The goal is not to block everything but to classify: approve, tolerate with controls or retire.

In almost every organization there are cloud apps and services the technology team does not know about: a file-sharing tool, a project manager paid for with a corporate card or, increasingly, AI assistants where staff paste company information. This is Shadow IT, and its newest form, Shadow AI.

What Shadow IT is

It is the use of software, cloud services, devices or accounts without the approval or oversight of IT and security. It is not always malicious; often it is the fastest way a team found to solve a real problem.

The risk appears because what cannot be seen cannot be protected: no contract was reviewed, there is no access control, no backup, and no one knows which data left the organization.

Business risks

  • Data leakage: customer data, contracts or intellectual property stored in unassessed services.
  • Non-compliance: contractual, privacy or industry obligations that cannot be demonstrated.
  • Orphaned accounts: access that remains active after a person has left.
  • Duplicated costs: several departments paying for tools that do the same thing.
  • Attack surface: integrations and permissions granted to third-party apps without review.

How to discover it

Discovery combines technical and business sources. None is enough on its own:

  1. DNS and proxy or secure web gateway (SWG) logs: show which services devices connect to and how often.
  2. A cloud access security broker (CASB): identifies SaaS apps, rates their risk and detects data uploads.
  3. Single sign-on (SSO) and email logs: reveal apps connected with corporate accounts.
  4. Spend analysis: corporate cards and expense claims expose subscriptions that never went through procurement.
  5. Talking with departments: a short, blame-free survey often reveals what technology cannot see.
The goal of discovery is not to punish, but to decide with information.

From discovery to governance

With the inventory in hand, every app should receive an explicit decision:

  • Approved: added to the official catalog, with a contract, SSO and an owner.
  • Tolerated with controls: allowed with restrictions, for example no confidential data or read-only use.
  • Retired: blocked, with an approved alternative offered and data migrated if needed.

Then come the permanent controls: an acceptable use policy for apps and artificial intelligence, web gateway filtering, data loss prevention (DLP) and periodic inventory reviews.

Indicators for leadership

  • Number of apps discovered versus approved.
  • High-risk apps holding sensitive data.
  • Share of apps integrated with single sign-on.
  • Savings from consolidating duplicate subscriptions.

Conclusion

Shadow IT is a sign that the business needs to move faster than its processes. The mature response is not to prohibit, but to see, classify and offer safe paths. That way productivity and protection stop competing.

Find out what your organization uses without IT knowing

We inventory apps, rate their risk and define a cloud and artificial intelligence usage policy.

Reference: original LandoHOUSE editorial article, developed from the topic covered in Cloudflare — Shadow IT discovery (SASE use case). It is not a literal translation and implies no affiliation with the source.