On this page
- 01Key takeaways
- 02What is shadow IT?
- 03Why does it happen in small businesses?
- 04What does it cost?
- 05How do you bring it under control?
- 06When is shadow IT useful?
- 07What does duplicate software cost?
- 08Which shadow IT carries the most risk?
- 09What should a simple software register contain?
- 10How do you stop it growing back?
- 11What does this look like in practice?
- 12Shadow IT checklist
- 13Next step
- 14Sources and further reading
- 15Frequently asked questions
Key takeaways
Shadow IT is software, accounts and devices used for work without the business knowing or approving them. In small businesses with no IT function it is normal: staff solve problems with whatever tool is to hand. The hidden costs are duplicate subscriptions, data in places nobody controls, and accounts that survive after people leave.
- Shadow IT: tools used for work that the business has not approved or recorded.
- It grows fastest where nobody owns IT.
- Costs: duplicate subscriptions, data sprawl, orphaned accounts.
- A one-page software register is the first fix.
No idea what software your team really uses? Message us on WhatsApp and we will help you list it.
Chat on WhatsApp →What is shadow IT?
The National Cyber Security Centre describes shadow IT as the unknown IT assets used within an organisation for business purposes. It includes free file-sharing accounts, personal messaging apps used for customer contact, browser extensions, and subscriptions paid on a personal card and claimed back.
Why does it happen in small businesses?
It happens because staff need to get work done and no approved tool exists. With no IT owner, nobody says yes or no, so people choose their own. The NCSC notes that shadow IT is rarely malicious; it is usually a sign that official tools are missing or inconvenient.
What does it cost?
It costs money and control. Three teams paying for three tools that do the same thing is waste. Customer data in a personal account cannot be found for a subject access request or deleted when required. An account created by a former employee may still hold business data that nobody can reach.
- Duplicate and forgotten subscriptions.
- Personal data outside any agreed system.
- No backups and no access control.
- Accounts tied to personal email addresses.
- Loss of access when an employee leaves.
How do you bring it under control?
Bring it under control with visibility first and rules second. Punishing people drives it further underground.
- Ask everyone to list the tools they use for work, without blame.
- Check card and expense statements for subscriptions.
- Record each tool, its owner, cost and data held.
- Choose one approved tool per job and close the rest.
- Make it easy to request a new tool.
When is shadow IT useful?
Shadow IT is useful as a signal. A tool that several people adopted independently is telling you what the business needs. Often the right response is to adopt it officially, with a business account and proper access.
What does duplicate software cost?
Duplicate software costs more than owners expect, because each subscription is small. Ten forgotten or overlapping tools at an average of £15 a month is £1,800 a year. Add licences still being paid for people who have left, and annual plans that renewed without anyone noticing, and a business of 15 people can easily be wasting £2,000 to £3,000 a year. An hour with the card statements usually finds most of it.
Which shadow IT carries the most risk?
Rank by the data involved, not by the tool.
- Customer or employee personal data in personal accounts.
- Business conversations on personal messaging apps.
- Files synced to personal devices.
- Accounts where the only administrator is one employee.
- Tools connected to your email or files with broad permissions.
What should a simple software register contain?
A register needs one row per tool and six columns: what it is for, who owns it, who uses it, what it costs, what data it holds and how you get in if the owner is away. Keep it in a shared place and review it twice a year. It doubles as a leaver checklist, because it shows every account that needs closing or transferring.
How do you stop it growing back?
Make the approved route easier than the workaround. Name one person who can say yes to a new tool within a day, set a small budget they can spend without further sign-off, and ask only that the account uses a business email address and goes on the register. People stop hiding tools when asking is quick and the answer is usually yes.
What does this look like in practice?
A pattern we see when someone leaves: the business discovers that its design files, social media logins or customer list sit in an account registered to that person's own email. Recovering them depends on goodwill.
Shadow IT checklist
Complete this once, then review yearly.
- Run a no-blame tool survey.
- Build the software register.
- Move accounts to business email addresses.
- Cancel duplicates.
- Name an owner for software decisions.
Next step
Send us a rough list of the tools your team uses. We will help you spot overlaps and risks in a 30-minute call.
Message us on WhatsApp about your software register, or book a 30-minute consultation.
Chat on WhatsApp →Sources and further reading
- Shadow IT · National Cyber Security Centre
- Small Business Guide: cyber security · National Cyber Security Centre
- Advice for small organisations · Information Commissioner's Office
Frequently asked questions
What are examples of shadow IT?
Personal cloud storage used for work files, messaging apps on personal phones for customer conversations, free design or survey tools signed up for with a personal email, unapproved browser extensions, and personal laptops used for business data. Most are adopted with good intentions.
Is shadow IT a security risk?
Yes. Tools the business does not know about are not backed up, patched or access-controlled, and may hold personal data. The National Cyber Security Centre advises organisations to find out what is in use and address the unmet needs behind it. Start with a list of what is in use.
How do I find shadow IT in my business?
Ask staff openly, review card statements and expense claims for subscriptions, and check which third-party apps have access to your email and file accounts. A no-blame approach produces a far more complete list. Repeat it once a year. Keep the list as your software register.
Should I ban unapproved software?
A ban alone rarely works. People use unapproved tools because approved ones are missing or awkward. Provide a good approved option for each need, make requests quick, and then set a clear policy. Explain the reason for it. Review the policy yearly.
Written by

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.




