Shadow IT and how it is changing the landscape of Office IT
Shadow IT is the software and devices employees use without IT approval. Here's why it's growing and how to manage it without stifling productivity.
Let’s say you’re driving home from work, you get an email message from your office, and you got it on your phone. It looks important, so you park your car and check the message. It has an unrecognized attachment that your mobile phone is not pre-equipped to handle. You pop into the Play Store and look for a reader. In a few minutes you were able to open a 3D image of a birthday greeting. Great. Not only have you wasted five minutes and some phone data, you also just took a walk into the shadows—Shadow IT.
What Is Shadow IT?
Just to give you the gist of it: Shadow IT is when an employee or team makes use of a technological solution for a problem connected to their work that has not been officially approved by the IT team.
When the world was simpler, Shadow IT was just a simple Excel macro, or software bought from a local store. Now, with the internet and cloud computing, the types of Shadow IT have grown dramatically, and IT teams are struggling to cope.
Why Is There Shadow IT?
Why is there Shadow IT? Simply because there is a need, there are resources, and it makes the lives of the workforce easier. Everyone who has ever worked a desk job knows: no one calls the office supply department for paper clips. You bring one on your own, or you ask a co-worker. It’s the same with Shadow IT. You need something done now, ticketing the IT team would take at least 30 minutes, and your boss is chewing your head off. It’s so much easier to find a tool online and take care of the matter on your end. Let’s bullet these needs:
- No system internally has the solution.
- The internal solution is not a perfect fit.
- A solution online is available and it is easier to use.
- Approval and provision of a new solution will take time.
What Kinds of Shadow IT Are Being Used?
There are a lot of ways that Shadow IT can rear its head in the office (or even remotely, in the case of remote workers). Here’s a glimpse:
- Cloud services and internet services. The internet is filled with ideas and solutions for nearly every kind of issue there is. A simple search and you get what you need—free, ad-supported, open-source, paid, subscription-based. Small web-based programs or downloadable applications. Big integrated software solutions to enterprise-level systems.
- Local software, off the shelf. They’re still alive and kicking. Although struggling against online tools, there is still over-the-counter software out there from established big-wigs in the software game. Sometimes just the name alone makes your team want to use them.
- Hardware such as smartphones, printers, tablets, laptops, and computers. Chances are, employees have their own laptop or computer at home, their phones are smart and can connect to the office equipment, and a boss can bring in a printer or a projector, just because.
Is It Safe? The Pros and Cons of Shadow IT
Is Shadow IT safe? Can we use Shadow IT in the workplace? Almost every CTO we know hates Shadow IT because of the risk factors involved. Whether it’s a small program that converts a Doc to a PDF or a way for users to interact on a project remotely, there are still risks that come with Shadow IT that may hinder its true potential as an office solution.
Shadow IT Cons
- Data loss. Everything in a company is data; it really needs to be safeguarded.
- No IT control, tracking, or visibility. Once you use a solution that is not controlled by the IT team, there is no accountability, and no way to track where your data passes, ends up, or how it gets back to you.
- Creating a possible opening for attack. Since you are moving from a private closed network (your office) to a public one (the internet), you are now more exposed, and any Shadow IT you use may open up vulnerabilities you may not have had before.
- Integration is inefficient or not possible. Some tools and solutions online will try to keep their system away from others so that you will need to purchase something extra or find it difficult to leave their service.
Is Shadow IT All Bad? Can We Still Use It?
Not everything about Shadow IT should be avoided. It is a symbol of innovation and quick reactions in the workplace. Here are the pros of Shadow IT:
- Immediate solutions. Your team is on top of the situation; they are thinking on their feet and have a quick solution to your problems.
- Change is constant. Some solutions in your system may no longer be up to date. There may be a need to improve the current system, and Shadow IT is giving you a hint.
- Ideas come from everywhere. The employees or team are providing solutions for tasks that only they fully understand. These are ideas that should never be ignored.
The office workspace, the company, is an organism on its own, and the employees are a part of it. Although the risk of Shadow IT will always be weighed greater for the good of the company, the benefits and realizations Shadow IT brings cannot be overlooked. It would be up to your IT team to find the good and the bad of Shadow IT so it can be embraced as a tool for improvement.
The Boom Logic team continually integrates with and learns from your system to find whether there are better solutions out there for you and your company—not only by looking at the needs system-wise, but also by melding them with the needs people-wise. If you think it’s time for a change, drop us a line for a quick conversation about better IT.
More from the blog. Security, infrastructure, and the business of IT.
CMMC 2.0 Compliance Checklist: What Defense Contractors Must Have Before Phase 2
A CMMC 2.0 compliance checklist for defense suppliers: scoping decisions, the 14 NIST SP 800-171 control families, the documents assessors open first, and the…
Read article →What Is a Written Information Security Plan (WISP)? A Guide for Accounting and Tax Firms
A WISP is the FTC Safeguards Rule document every accounting and tax firm must keep. Here are the nine required elements, what the plan…
Read article →Cybersecurity for Law Firms: The 2026 Incident-Response Checklist
What cybersecurity for law firms requires in 2026: the ethics duties, the controls that matter, and a step-by-step incident-response checklist for partners.
Read article →Have a question this article didn’t answer?
Talk to the engineers directly. Get a free security assessment and a clear, flat-rate plan from one accountable team.