GLOBAL BRIDGE LABS
← All posts/BPO & Operations

Shadow IT in a small business: risks and fixes

Shadow IT in a small business: the apps and accounts staff set up themselves, what they cost in money and risk, and a light-touch way to regain control.

By Hojitha Weerasinghe, Co-founder / DirectorPublished 6 min read
Shadow it small business: key takeaways infographic by Global Bridge Labs
Key takeaways from this article. Share it with the link and credit Global Bridge Labs.
On this page

Key takeaways

Shadow IT is software, accounts and devices used for work without the business knowing or approving them. In small businesses with no IT function it is normal: staff solve problems with whatever tool is to hand. The hidden costs are duplicate subscriptions, data in places nobody controls, and accounts that survive after people leave.

  • Shadow IT: tools used for work that the business has not approved or recorded.
  • It grows fastest where nobody owns IT.
  • Costs: duplicate subscriptions, data sprawl, orphaned accounts.
  • A one-page software register is the first fix.

No idea what software your team really uses? Message us on WhatsApp and we will help you list it.

Chat on WhatsApp →

What is shadow IT?

The National Cyber Security Centre describes shadow IT as the unknown IT assets used within an organisation for business purposes. It includes free file-sharing accounts, personal messaging apps used for customer contact, browser extensions, and subscriptions paid on a personal card and claimed back.

Why does it happen in small businesses?

It happens because staff need to get work done and no approved tool exists. With no IT owner, nobody says yes or no, so people choose their own. The NCSC notes that shadow IT is rarely malicious; it is usually a sign that official tools are missing or inconvenient.

What does it cost?

It costs money and control. Three teams paying for three tools that do the same thing is waste. Customer data in a personal account cannot be found for a subject access request or deleted when required. An account created by a former employee may still hold business data that nobody can reach.

  • Duplicate and forgotten subscriptions.
  • Personal data outside any agreed system.
  • No backups and no access control.
  • Accounts tied to personal email addresses.
  • Loss of access when an employee leaves.

How do you bring it under control?

Bring it under control with visibility first and rules second. Punishing people drives it further underground.

  • Ask everyone to list the tools they use for work, without blame.
  • Check card and expense statements for subscriptions.
  • Record each tool, its owner, cost and data held.
  • Choose one approved tool per job and close the rest.
  • Make it easy to request a new tool.

When is shadow IT useful?

Shadow IT is useful as a signal. A tool that several people adopted independently is telling you what the business needs. Often the right response is to adopt it officially, with a business account and proper access.

What does duplicate software cost?

Duplicate software costs more than owners expect, because each subscription is small. Ten forgotten or overlapping tools at an average of £15 a month is £1,800 a year. Add licences still being paid for people who have left, and annual plans that renewed without anyone noticing, and a business of 15 people can easily be wasting £2,000 to £3,000 a year. An hour with the card statements usually finds most of it.

Which shadow IT carries the most risk?

Rank by the data involved, not by the tool.

  • Customer or employee personal data in personal accounts.
  • Business conversations on personal messaging apps.
  • Files synced to personal devices.
  • Accounts where the only administrator is one employee.
  • Tools connected to your email or files with broad permissions.

What should a simple software register contain?

A register needs one row per tool and six columns: what it is for, who owns it, who uses it, what it costs, what data it holds and how you get in if the owner is away. Keep it in a shared place and review it twice a year. It doubles as a leaver checklist, because it shows every account that needs closing or transferring.

How do you stop it growing back?

Make the approved route easier than the workaround. Name one person who can say yes to a new tool within a day, set a small budget they can spend without further sign-off, and ask only that the account uses a business email address and goes on the register. People stop hiding tools when asking is quick and the answer is usually yes.

What does this look like in practice?

A pattern we see when someone leaves: the business discovers that its design files, social media logins or customer list sit in an account registered to that person's own email. Recovering them depends on goodwill.

Shadow IT checklist

Complete this once, then review yearly.

  • Run a no-blame tool survey.
  • Build the software register.
  • Move accounts to business email addresses.
  • Cancel duplicates.
  • Name an owner for software decisions.

Next step

Send us a rough list of the tools your team uses. We will help you spot overlaps and risks in a 30-minute call.

Message us on WhatsApp about your software register, or book a 30-minute consultation.

Chat on WhatsApp →

Sources and further reading

Frequently asked questions

What are examples of shadow IT?

Personal cloud storage used for work files, messaging apps on personal phones for customer conversations, free design or survey tools signed up for with a personal email, unapproved browser extensions, and personal laptops used for business data. Most are adopted with good intentions.

Is shadow IT a security risk?

Yes. Tools the business does not know about are not backed up, patched or access-controlled, and may hold personal data. The National Cyber Security Centre advises organisations to find out what is in use and address the unmet needs behind it. Start with a list of what is in use.

How do I find shadow IT in my business?

Ask staff openly, review card statements and expense claims for subscriptions, and check which third-party apps have access to your email and file accounts. A no-blame approach produces a far more complete list. Repeat it once a year. Keep the list as your software register.

Should I ban unapproved software?

A ban alone rarely works. People use unapproved tools because approved ones are missing or awkward. Provide a good approved option for each need, make requests quick, and then set a clear policy. Explain the reason for it. Review the policy yearly.

Written by

Hojitha Weerasinghe
Hojitha Weerasinghe
Co-founder / Director

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.

Share this article

Reading is good.
Fixing is better.

30 minutes with our team and you'll leave knowing which of the three problems to fix first.

Book a 30-Minute Consultation →
Keep reading