How to keep shadow IT and its costs under control

Admit it. You’ve used WeTransfer to send company files. Maybe stored something on your Google Drive. Or worked on a confidential spreadsheet on your personal laptop.

You are not alone.

More than half of global organisations now experience “improper data sharing” according to the State of SaaS 2025 report published by BetterCloud. Gartner, the research giant, believes that by 2027, 75% of employees will install and use applications that are beyond the visibility of their IT departments.

This is expensive; Gartner has found that shadow IT accounts for between 30% and 40% of IT spend in big companies. Spend that isn’t directly controlled by IT budget holders, that introduces a financial risk alongside the obvious security risk.

Shadow IT – the use of unsanctioned technology – is keeping 60% of IT execs up at night. With good reason: more apps and unauthorised accounts leads to a greater attack surface for cybercriminals, and could make organisations uncompliant with rules such as GDPR.

So, how can businesses better manage shadow IT? And in doing so keep control of spending? We asked the experts.

Check your speed

Most people only use shadow IT when the usual tools are too slow or lack functionality, says Guy Levine, founder of digital agency Return. “When team members are asked why they use shadow IT, the biggest reason is due to the fact that the company has provided inferior technology, which has just ended up causing frustration,” he said.

People are increasingly under pressure to deliver at pace, so Guy wonders whether company culture is partly to blame for the proliferation of outside tools. “Trying to understand why team members are moving to use IT we don’t supply has been key to our security efforts,” he told TechFinitive.

But trying to go too fast can lead to a crash, says Hone John Tito, Co-Founder of Game Host Bros, which hosts gaming servers. “I have experienced cases where developers implement their own programs or scripts without bringing it to the leadership level, thinking that they were going to save some time,” he said. “A seemingly good Discord bot triggered unexpected server behaviour, exposing us to exploits that we would not have expected. It took time to regain the confidence of our clients.”

Don’t punish the perps

The worst thing you can do is make an example of staff who dabble in shadow IT, warns Simon B, security researcher at the UK’s National Cyber Security Centre (he prefers not to share his full name). “It’s important to acknowledge that shadow IT is rarely the result of malicious intent,” he explained.

“If you blame or punish staff, their peers will be reluctant to tell you about their own unsanctioned practices, and you’ll have even less visibility of the potential risks.”

Instead, organisations must embrace an open approach to shadow IT, “so that staff are able to communicate openly about issues,” he said. “Including where current policy or processes are preventing them from working effectively.”

The NCSC has published a guide to good cybersecurity culture, which Simon B says can help to banish shadow IT.

People Like You Take Control of Digital and Recurring Spend with Soldo 

Digital payments are surging – but so are the risks. From unmonitored SaaS subscriptions to runaway ad spend, today’s finance teams face mounting complexity, fragmented budgets, and a lack of visibility.

See how your peers are tackling digital and recurring spend – and winning. Download the eBook now to get inspired and take back control.

Use specialist tech

Shine a light in the shadows by investing in tools that can spot rogue behaviour. Nic Adams, Co-Founder of ethical hacker Orcus says that businesses need “full-spectrum visibility”.

“Shadow IT thrives in opacity,” he explained. “You need real-time telemetry across users, apps and data flow to expose it.”

Nic recommends five technical tools: “Network traffic analysis to uncover unknown domains and IP destinations; endpoint detection tools that flag unapproved software installations; CASBs [cloud access security brokers] to monitor cloud app usage outside official channels; firewall and proxy logs to reveal irregular SaaS access patterns; and behavioural analytics to identify deviations in user activity tied to unsanctioned tools.”

Levine agreed: “Using security to detect and monitor cases has allowed our IT team to stay on the front foot, and give training to individual team members.”

Make this a cross-departmental priority

As a corporate legal counsel, advising companies on cybersecurity and data privacy, Maryam Meseha, Founding Partner at Pierson Ferdinand, has seen firsthand the impact of shadow IT. She says the only way to tackle this pervasive problem is work as a team to figure out where the weaknesses lie.

“Legal, IT, and department heads need to map out regular ‘app audits’ across teams,” she recommends. “This means identifying which tools are in use, whether officially approved or not, and conducting a risk assessment based on data handling, user access and storage locations.”

The impact of AI

Shadow AI is the latest nightmare stalking corporate corridors. According to Greg Shove, the CEO of Section, 32% of employees in companies that have explicitly banned AI still use it in their work.

“Companies that ban AI have a ‘Shadow AI’ problem with workers who secretly use it,” he said. “Worse yet, 53% of AI users in companies with AI bans are experimenter or novice level users, but nearly 20% of them think they’re intermediate or advanced users.”

Depending where in the world you organisation is headquartered, and the compliance, regulatory and even ethical constraints, having staff using ChatGPT, DeepSeek or another AI platform could breach multiple rules. “One unauthorised AI chatbot can ingest confidential data and make the company legally liable within seconds,” said Orcus’ Adams.

Be proactive

If you want your people to use authorised tools, keep the conversation going. “Try ‘Approved Tool’ lists that are regularly updated, a formal intake process for new technology requests, and training that emphasises not just the rules but the reasons behind them,” said Pierson Ferdinand’s Meseha. “When people understand why a tool might be risky they’re more likely to comply.”

This is how Tito effected change in his own organisation. “We established an open process to evaluate new tools, making sure that anybody could suggest tech,” he said. “Instead of the heavy-handed ban, we perform short-duration sessions on what can go wrong when tools go under the radar.”

Levine adds that snappy training with a focus on the ‘why’ works best: “Security training for the team is essential but rather than hours of technical training, we have found giving a short list of the most important aspects has worked best. Then at least the team remembers.”

You can’t stop people using shadow IT – the phenomenon is here to stay. But organisations that see shadow IT as an opportunity to understand the tech their people need to do a great job, rather than just as a threat, will be more successful in the long run.

Bex Burn-Callandar
Bex Burn-Callander

Bex Burn-Callander is a freelance journalist, editor and podcaster specialising in small businesses, entrepreneurs, finance and economics. Former enterprise editor of The Daily Telegraph and Sunday Telegraph, she is currently the host of Sound Advice: Entrepreneurs Unfiltered, a UK Top 10 business podcast, sponsored by Sage.