Shadow IT Discovery: Finding the Systems Nobody Approved

Shadow IT — the SaaS, cloud and dev environments nobody approved — is a common source of breaches. Here's why it accumulates and how to find yours.

Shadow IT is technology used inside your organisation without IT's knowledge or approval: SaaS subscriptions, cloud accounts, dev environments, file shares, automation tools. It accumulates because it solves someone's problem quickly, and it's a security risk because nobody patches, monitors or offboards what nobody knows exists. Here's how it builds up, why it matters, and how to actually find it.

How shadow IT accumulates

Shadow IT is rarely malicious. It's velocity meeting friction:

  • SaaS is one credit card away. A team needs a tool this week; procurement takes months. The card wins.
  • Free tiers don't even need the card. Sign up with a work email and company data starts flowing the same afternoon.
  • Developers prototype on personal cloud accounts. The prototype works, other things become urgent, and it quietly becomes production.
  • Agencies act in your name. Marketing partners register domains and stand up microsites under your brand, on infrastructure you'll never log into.
  • Acquisitions import entire unknown estates. You inherit every unofficial system the acquired company ever created.
  • People leave. Departed staff take the only credentials to accounts that still hold company data.

Because the cause is structural, fighting shadow IT with policy alone doesn't work. A ban you can't enforce just drives usage further underground.

Why shadow IT is a security risk

  • It sits outside SSO, MFA and patching, making it the weakest door into your environment — and attackers deliberately look for the forgotten, unloved systems first.
  • Company data lives in places your breach response and offboarding processes will never touch.
  • There's no logging or backup, so incidents in shadow systems are invisible until the damage is external.
  • It undermines compliance: data sovereignty commitments and the asset management expectations in frameworks like ISO 27001 assume you know what you have. If you're working towards certification, see our ISO 27001 penetration testing service.

How to find shadow IT

Effective discovery combines an inside view and an outside view — each finds things the other can't.

From the inside

  • Follow the money. Expense reports and card statements are a remarkably good shadow SaaS inventory — subscriptions leave a paper trail.
  • Check OAuth grants. Your identity provider's admin console lists third-party apps staff have connected to their corporate Google or Microsoft accounts. This list is almost always longer than expected.
  • Search email. Welcome, verification and invoice emails to corporate addresses reveal sign-ups nobody declared.
  • Review egress. DNS and proxy logs show which services your network actually talks to; a CASB formalises this if you have one.

From the outside

External discovery finds what internal telemetry can't — the personal cloud account, the agency-built microsite, the subsidiary's forgotten app — because it looks at the same public data attackers use: certificate transparency logs, DNS datasets, public code search, and corporate naming or branding on third-party platforms. This is the attacker's view of your organisation, and it's the core of external attack surface management. We run this kind of discovery on OSINT and reconnaissance engagements, and cloud-focused follow-up — working out what's in those unofficial tenants and how they're configured — is where a cloud penetration test earns its keep.

Make it easy to come clean

Amnesty beats punishment. If admitting to shadow IT gets people in trouble, it stays hidden and you lose your best discovery channel: the people using it. Pair discovery with a fast, low-friction path to get tools sanctioned, so the official route stops being the slow one.

What to do with what you find

Triage each discovery into one of three outcomes: adopt it (bring it under SSO, MFA, patching, backup and an owner), replace it with a sanctioned equivalent that actually meets the need, or retire it and migrate the data out. Then add everything to your asset inventory and monitoring — otherwise the same systems drift straight back into the shadows.

FAQ

Is shadow IT always bad?

No. It's usually a signal that sanctioned tooling has a gap — the risk isn't the tool, it's the invisibility. The healthiest response is to govern what works rather than reflexively banning it.

Whose job is shadow IT discovery?

It's shared. IT and security run technical discovery, finance surfaces the spend trail, and leadership sets a tone that makes disclosure safe. External assessments add the attacker's perspective none of those internal views provide.

How often should we look for shadow IT?

External monitoring should be continuous, because exposure appears continuously. Internally, sweep expense data and OAuth grants at least quarterly. An annual audit alone means shadow systems run unmanaged for months before anyone notices.

Want to see your organisation the way an attacker does — including the parts nobody approved? Our OSINT and reconnaissance team maps shadow infrastructure for clients globally, with a fixed quote within one business day of a free scoping call — get in touch.

Need cybersecurity expertise?

Drop your email and we'll be in touch within one business day.