Advisory & Innovation

Shadow IT Risks: The Apps Your IT Team Can't See

Affix Center · · 7 min read

Person typing on a laptop, representing shadow IT risks from unapproved apps at work

Picture this. A sales executive leaves the company, and three weeks later a client calls to ask why their price list is still open on a public file-sharing link. Nobody in IT knew that link existed. The file was on a personal cloud drive, shared from a personal account, and the company has no way to take it down.

This is what shadow IT looks like in practice. It is rarely an attack. It is ordinary staff using tools the company never approved, because those tools get the work done faster. This guide explains the real shadow IT risks, why banning everything fails, and a step-by-step way to bring it under control without slowing your teams down.

What Is Shadow IT?

Shadow IT is any software, cloud service, device or account used for company work without the knowledge or approval of the IT team or management. Common examples in Indian offices include:

  • Personal email and personal cloud drives used to send or store office files
  • Customer data shared in personal messaging groups
  • Free online tools for PDF conversion, file transfer or translation
  • Project boards, CRM trials and form builders started by one team on a credit card or free plan
  • Public AI chatbots used to summarise contracts, draft emails or review code
  • Personal laptops, pen drives and home Wi-Fi routers plugged into the office network

The newest form is often called shadow AI: staff pasting company or customer information into AI tools that the organisation has not reviewed.

Why Staff Go Around IT

Before treating shadow IT as indiscipline, look at why it happens. In most cases the reason is practical:

  • The official tool is slow, outdated or missing a needed feature.
  • Getting a new tool approved takes weeks, and the deadline is tomorrow.
  • Nobody told the team that an approved option already exists.
  • There is no written rule, so staff assume it is allowed.

Shadow IT is a signal. It shows you where your official systems are not meeting real needs. That is useful information, if you choose to use it.

The Real Shadow IT Risks

1. Data you cannot see, protect or delete

When files sit in personal accounts, the company loses control of them. You cannot back them up, apply access rules, or remove access when someone resigns.

The fix: give staff an approved, easy way to store and share files, and make company-owned accounts the rule for all work data.

2. Compliance gaps

The Digital Personal Data Protection Act, 2023 expects organisations that handle personal data to protect it with reasonable security safeguards. That is hard to show when customer or employee data is spread across tools you have never assessed. The same problem appears in ISO 27001 audits and in client security questionnaires.

The fix: keep a register of every tool that touches personal or confidential data, with a named owner for each. Our DPDP Act compliance checklist covers the wider steps.

3. Weak accounts and no exit control

Unapproved tools usually sit outside your single sign-on and multi-factor authentication. Passwords are reused, and accounts stay active long after an employee has left.

The fix: bring important tools under company login, and add every approved app to your offboarding checklist.

4. Wasted money

Different teams often pay for separate tools that do the same job, on personal cards claimed through expenses. Renewals continue because nobody owns the subscription.

The fix: review expense claims and card statements for software subscriptions, then consolidate.

5. Business knowledge trapped in one person's account

If the only copy of a customer tracker or a process document lives in one employee's private workspace, it leaves when they leave.

The fix: require that business records live in shared, company-owned workspaces with at least two administrators.

Why a Blanket Ban Does Not Work

The first reaction of many managements is to block everything. This usually fails. Staff move to mobile data, personal phones and home computers, where you have even less visibility. Work slows down, and the IT team is seen as an obstacle.

The aim is not zero shadow IT. The aim is that anything touching important data is known, assessed and owned.

How to Solve It: A 7-Step Plan

  1. Discover what is in use. Combine several sources: firewall and DNS logs, sign-in records from your email platform showing which third-party apps staff have connected, expense claims, and a short, blame-free staff survey. Announce that the purpose is to help, not to punish. You will get more honest answers.
  2. Sort every tool into three groups. Approved (safe to use), Allowed with conditions (for example, no customer data), and Not allowed (with the approved alternative named next to it).
  3. Offer a good alternative for each blocked tool. If you block personal file sharing, the official sharing tool must be just as easy. A rule without an alternative will be ignored.
  4. Create a fast approval path. A one-page request form and a promised response time of a few working days removes the main reason staff go around IT. Check four things: what data the tool will hold, where it is stored, how users log in, and how data can be exported or deleted.
  5. Write it into a short policy. State what is allowed, what is not, and how to ask. Include a clear rule for AI tools: what must never be pasted into them. See our guide to creating an IT policy for employees.
  6. Add technical guardrails. Use company login with multi-factor authentication for approved apps, restrict which third-party apps can connect to company email and storage, and apply web filtering for clearly risky categories. Larger organisations can add data loss prevention and cloud access security tools.
  7. Review every quarter. New tools appear constantly. Repeat the discovery step, update the approved list, and remove subscriptions nobody uses.

Quick checklist for management

  • Do we have a list of every cloud tool that holds customer or employee data?
  • Does each tool have a named owner and at least two administrators?
  • Are all of them on company-owned accounts?
  • Do staff know how to request a new tool, and how long it takes?
  • Do we have a written rule on using AI tools with company data?
  • Are these tools part of our employee exit process?

If the answer to two or more is "no", shadow IT is already a live risk in your organisation.

Shadow AI Needs Its Own Rule

AI assistants are useful, and staff will use them whether or not a policy exists. The risk is in what gets typed into them: customer lists, contract text, source code, salary data or tender documents.

A practical approach has three parts:

  1. Name the AI tools that are approved for work, and under which account type.
  2. Define the data that must never be entered: personal data, client confidential material, credentials and unpublished financial or tender information.
  3. Train staff with real examples from their own work, not a generic slide deck.

Frequently Asked Questions

Is shadow IT illegal?

Using an unapproved tool is not illegal by itself. The legal and contractual exposure comes from what happens to the data: personal data that is not properly protected, or client information shared in breach of a confidentiality agreement.

How do we find shadow IT without spying on staff?

Look at company systems, not private activity: network logs, apps connected to company accounts, and software purchases. Tell staff in advance what is being reviewed and why. An open survey often reveals more than any tool.

Should small companies worry about this?

Yes. Small firms often depend more on free and personal tools, and usually have no one tracking them. A simple approved-tools list and company-owned accounts solve most of the problem at low cost.

Who should own this: IT, HR or management?

Management should own the policy, IT should run discovery and controls, and HR should cover it in induction and exit. Department heads should own the tools their teams use.

How Affix Center Can Help

Affix Center helps enterprises, SMEs and government offices review how technology is really being used and put practical governance around it. Our enterprise advisory team can run a shadow IT discovery, prepare an approved-tools register and draft a short, usable policy. Our cybersecurity team can then set up access controls, multi-factor authentication and monitoring so the policy is supported by the systems.

If you are not sure which apps hold your company's data today, contact Affix Center for a shadow IT review.