Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

Shadow IT: The Apps Your Employees Are Using Without Telling You

Cybersecurity
Last updated: August 5, 2026

Shadow IT is any app, account, or cloud service employees use for work that IT never approved and usually doesn’t know exists. Most of it isn’t malicious. Not even close. It’s a project manager who signed up for a free file-sharing tool because the approved system was too slow to grant access that week.

That’s the part people miss. Nobody walks into work planning to create a security hole. They’re chasing a deadline. The sanctioned tool is one login request away from a “yes” that might come Thursday.

What Actually Counts as Shadow IT

Shadow IT covers any technology running inside your business that IT didn’t select, vet, or even see coming. It includes personal cloud storage accounts, messaging apps outside the company’s approved platform, project-management tools someone spun up on a free tier, and browser extensions with broad permissions. AI chatbots too. Just one entry on a longer list, not the whole story.

Want a sense of scale? Here’s what my team typically finds during a cybersecurity review at a business your size, broken down by category and ranked by risk, not by headline.

CategoryCommon ExamplesTypical Risk Level
Personal cloud storage / file sharingPersonal Dropbox, personal Google Drive, WeTransferHigh
Messaging appsWhatsApp, personal Slack workspaces, TelegramMedium
Project management toolsFree-tier Trello boards, personal Notion workspaces, unsanctioned AsanaMedium
Browser extensionsPDF converters, ad blockers, writing assistants with broad tab permissionsHigh
AI chatbotsPersonal ChatGPT, Gemini, or Claude accounts used for work tasksMedium-High

AI tools are one row in a five-row table. Headlines love them right now. Not the only risk here. In a lot of small businesses, not even the biggest one.

IT consultant and small business owner discussing unsanctioned apps found on the network

How Common Is This, Actually

It’s the majority of your software, not the exception. Torii’s 2026 SaaS Benchmark Annual Report, which analyzed live usage and signup activity rather than survey responses, put shadow IT at 61.3% of all apps in use across the organizations it tracked. Only 15.5% formally sanctioned.

The spending picture backs that up. From a different angle. Gartner surveyed over 1,100 manager-level-or-higher respondents in late 2021. 74% of technology purchases were funded, at least partially, by business units outside of IT. Only 26% funded entirely by IT itself. Three out of four dollars. Never fully passed through the department whose job is to secure it.

For businesses your size specifically, Capterra ran a 2023 survey of IT leaders and project managers at companies with up to 1,000 employees, screened for firms that had already experienced a shadow IT incident. Fifty-seven percent had a high-impact shadow IT effort happen outside their official IT department. Seventy-six percent of the ones who found something called it a moderate-to-severe threat, not a nuisance to shrug off.

That last number matters more than the first. Finding shadow IT isn’t the scary part. What it was already doing before you found it, that’s what keeps me up some nights.

Why It’s Riskier Than It Looks

A browser extension with broad tab permissions can read the content of background tabs, cached pages, and session data, capturing information a user never even downloaded or shared on purpose. Standard tools don’t see it happen. Nothing left the building, as far as IT knows.

IBM’s 2025 Cost of a Data Breach Report found that breaches tied to unsanctioned AI tools exposed customer personal data at a higher rate than the average breach, 65% versus 53% globally, and cost more per record once they happened. Twenty percent of breached organizations in the report had been compromised through shadow AI specifically. That’s one in five. Those incidents ran $670,000 more expensive on average than the baseline. Almost all of them, 97%, lacked proper AI access controls at the time.

Compliance doesn’t wait for a breach to get expensive. The Cybersecurity and Infrastructure Security Agency lists shadow IT as a core gap in its Zero Trust Maturity Model. Resources IT never approved also sit outside the access policies and audit trails regulators expect to see documented. An unvetted tool that was never assessed against your industry’s obligations can create exposure the moment it touches sensitive data. No breach required.

Some extensions go further and cache authentication tokens. That means they can hold onto a login session well past the point a normal MFA prompt would have stopped anyone. Not a hypothetical, either. It’s a browser problem that predates the current AI wave by years and just got worse because of it.

Why Employees Actually Do This

Here’s where I’ll push back on the instinct to crack down. Most of the people using shadow IT at your company are not trying to hurt you. Truly.

Hands reviewing printed expense reports to find unapproved software subscriptions

Gartner surveyed 1,310 employees in 2022. 69% had intentionally bypassed a cybersecurity policy in the previous twelve months. Ask them again in a year and seventy-four percent say they’d make the same call. Faster results, same choice, why fight it. Gartner VP Paul Furtado summed it up plainly in the firm’s coverage of the survey: “Friction that slows down employees and leads to insecure behavior is a significant driver of insider risk.”

Think about how that plays out on an actual Tuesday, hypothetically. A salesperson needs to send a fourteen-gigabyte video file to a client and the approved system caps uploads at two. A bookkeeper needs a second opinion on a spreadsheet formula and pastes a sample into whatever’s open in another tab. Neither thought about IT policy. Not for a second. They thought about the deadline in front of them.

It’s the same instinct behind weak, reused password habits. More about convenience than carelessness. Capterra’s survey found the same pattern from the employer side. 57% of SMBs reported employees using unapproved software or services at work, typically to fill a gap in an approved tool or route around a slow approval process rather than out of any bad intent.

I’d rather you read that as a signal about your approval process than a character flaw in your staff. If getting the right tool takes three business days and getting the wrong one takes ninety seconds, most people will make the same choice. Every time.

How to Actually Find Out What’s Running

Nobody secures a tool they don’t know is running. The good news? You probably already own more discovery tools than you think.

  • SSO log review. If your team uses “Sign in with Google” or “Sign in with Microsoft” for anything, those identity logs show you every app someone authorized, including free-tier signups nobody mentioned.
  • Recurring five-to-five-hundred-dollar charges buried under “software” or “office supplies” on expense reports and card statements are one of the fastest ways to find a subscription nobody routed through you.
  • DNS and firewall traffic review. Every cloud app resolves a domain before it loads, so this catches tools even when they’re not tied to single sign-on at all.
  • A Cloud Access Security Broker, or CASB, is a dedicated layer that scores cloud services against a known catalog and flags anything risky.
  • Microsoft Defender for Cloud Apps. Included at no extra cost in Microsoft 365 E3, it checks traffic logs against a catalog of more than 30,000 cloud apps and scores each one on over 90 risk factors. A lot of businesses already own this and have never turned it on.

None of that requires ripping anything out on day one. The goal isn’t zero tools. It’s zero invisible ones.

Office coworkers discussing a printed report about apps employees use for work

Banning outright usually backfires. Block a tool with no sanctioned replacement and people don’t stop needing what it did. They just hide the next one better. The model that actually holds up, offer an approved alternative that solves the same real problem, build a fast lane for new tool requests so the answer doesn’t take three days, and keep discovering on a schedule instead of waiting for an incident to force the question.

That’s the kind of gap my team walks through during a managed IT engagement, mapping what’s actually running against what’s approved before it becomes the reason a renewal gets denied or an audit gets ugly. If your business hasn’t had that conversation yet, reach out to our team and we’ll walk you through what a first-pass review actually looks like.

Questions Business Owners Ask Us About Shadow IT

So what actually counts as shadow IT?
Any app, account, or cloud service your employees use for work that IT never approved or reviewed, whether that’s a free file-sharing tool, a personal messaging app, or a browser extension. Nothing exotic about most of it. Just boring software that never went through a sign-off.
Is a personal Gmail account really a security problem?
It can be, yes, especially once client files or internal spreadsheets start getting forwarded there for convenience. The issue isn’t Gmail itself. It’s that data leaves your controlled environment and now lives somewhere you can’t apply your retention rules, your access controls, or your breach response plan.
Isn’t this really just about ChatGPT and AI tools?
No, and that’s the most common misread of the topic. AI chatbots are one category among several, alongside file-sharing apps, messaging platforms, project tools, and browser extensions, and in a lot of small businesses they’re not even the largest exposure. AI-specific risk deserves its own conversation, but treating shadow IT as an AI-only problem misses most of what’s actually running.
Do we need to ban every unapproved app the second we find it?
Banning outright rarely works alone. Cut off a tool with no approved replacement and the underlying need doesn’t disappear, people just get quieter about it. Pairing discovery with a fast, real approval process for new tools tends to hold up a lot better than a blanket ban ever does.
How fast could you actually tell us what’s running across our network?
Faster than you’d guess. A first-pass discovery review, covering SSO logs, DNS traffic, and expense records, usually surfaces the biggest exposures within days, not weeks. Once you’re an active client, my team’s average response time on anything flagged urgent is under 15 minutes, which matters more than people expect once something turns up that actually needs attention that day.
Find Out What’s Actually Running Before Your Insurer or Auditor Does

A free IT assessment from VJNetworks maps the sanctioned and unsanctioned tools already living on your network. No obligation, no jargon-heavy report you’ll never read.

Get Your Free IT Assessment →

Or call (845) 440-5000