Shadow IT
Managing 'unknown assets' that are used within an organisation.

This guidance helps you to better identify and reduce the levels of ‘shadow IT’ in your organisation. It’s been written for system owners and technical staff, so that they can better mitigate the presence of unknown (and therefore unmanaged) IT assets within their organisation.
What is shadow IT?
The term ‘shadow IT’ (also known as ‘grey IT’) refers to the unknown assets that are used within an organisation for business purposes. Since these are not accounted for by asset management, nor aligned with corporate IT processes or policy, they’re a risk to your organisation. This could result in the exfiltration of sensitive data, or spread malware throughout the organisation.
Shadow IT is often associated with devices, but it can also include cloud technologies. For example, users might store sensitive organisational data in personal cloud accounts so they can access it from another location or device. This would be considered shadow IT because personal cloud storage is unlikely to be covered by your organisation's risk management processes.
Shadow IT can also include AI technologies used without permission, often referred to as shadow AI.
Most organisations will have some level of shadow IT, but if shadow IT is prevalent, risk management becomes more difficult because you won’t have a full understanding of what you need to protect, and what you value most.
It’s important to acknowledge that shadow IT is rarely the result of malicious intent. It’s normally due to employees struggling to use sanctioned tools or processes to complete a specific task, so they’ll adopt unofficial measures to help them complete their work.
Some common reasons that lead to shadow IT include:
- not having enough storage space
- not being able to share data with a third party
- not having access to necessary services (for example development tools)
- not having a sanctioned video conferencing (or instant messaging) tool
- not being able to request assets or services through a corporate system (or the process for doing this being ineffective/slow)
- approved tools or SaaS services not providing the required functionality (for example, AI that helps employees with administrative tasks such as rewriting documents, compiling information, or summarising meetings)
- not realising that use of devices or personally managed SaaS tools might introduce risk
Shadow IT is not BYOD
With an effective BYOD policy, your organisation has ownership and some level of control of corporate data and the resources permitted on the users device, allowing the risk to be managed. This is not the case with shadow IT. There might not be a risk, there might be a critical risk. The organisation simply doesn’t know. Shadow IT is therefore an unmanaged risk.
What can you learn from shadow IT?
Though clearly not desirable, the existence of shadow IT presents your organisation with learning opportunities. If employees are having to resort to insecure workarounds in order to ‘get the job done’, then this suggests that existing policies need refining so that staff aren’t compelled to make use shadow IT solutions. Security people should focus on finding where shadow IT exists, and where possible, bring it above-board by addressing the underlying user needs that shadow IT is seeking to address.
Most importantly, you should always take a positive and no-blame approach to people who have been forced into adopting shadow IT. If you blame or punish staff, their peers will be reluctant to tell you about their own unsanctioned practices, and you’ll have even less visibility of the potential risks.
Types of shadow IT
This section covers the main ways that shadow IT is most likely to manifest in your organisation, and the threats this may introduce.
Unmanaged devices
A widely understood area of shadow IT is unsanctioned devices on a network. This can include:
- personal devices belonging to employees on the core enterprise network
- equipment providing a critical service that is incorrectly configured
- IoT or other smart devices employees have introduced without security approval (smart doorbells, digital assistants, printers, etc.)
- Wi-Fi access points to provide coverage or types of access that the organisation has not provided
- servers or VMs brought in by an employee (or contractor) to provide a service without approval
Any device or service that’s not been configured by your organisation will probably fall short of the required security standards, and could damage the network and your services (by introducing malware, for example). They could also be added into botnets or become cryptominers, causing additional damage.
Unmanaged services
Less well understood are shadow cloud services. This can include:
- unapproved messaging or video conferencing services with no monitoring in place
- external cloud storage services to share files with third parties (or to allow staff to work from home using an unauthorised device)
- using third-party tools that could be gathering corporate information
- unmanaged cloud tenancies used by developers as testing environments
- project management or planning services used as an alternative to corporate tooling
- code stored in unmanaged repositories
- unmanaged AI services, such as chatbots, being used with corporate data
Threats posed by shadow IT
Shadow IT can introduce threats not present on corporate IT. This can include:
- 1
Data theft
Many of the controls that organisations apply to devices and services (such as encryption and allow/deny listing) are unlikely to be applied effectively on shadow IT. Protecting data is a concern as you can’t be certain where your data is, where it is being processed, or where it ends up. If you don’t have control of the services processing data (or devices that hold data), you can’t be sure appropriate backups are being made. This can expose an organisation to threat of ransomware, legal issues around data handling, reputational damage and recovery costs.
- 2
Exploitation of services or devices
Controls such as well-configured firewalls, application allow listing, antivirus software and multi-factor authentication (MFA) can help to reduce the risk of compromise. For shadow IT, you can’t assume that these controls are in place. This applies not to just traditional work devices (such as phones, laptops and PCs), but also embedded devices that have an internet connection that have been set up (for example) by a building manager. This can expose an organisation to the threats from malware (including ransomware), network monitoring, and lateral movement.
Mitigations for shadow IT
At all times, you should be actively trying to limit the likelihood that shadow IT can or will be created in the future, not just addressing existing instances.
Organisational mitigations
It is important to re-iterate that most shadow IT is typically not the result of intentional rule-breaking, rather the result of staff trying to ‘get their job done’ where corporately-provided equipment and services are not adequate. In many cases, staff may not realise that they are placing the organisation at risk.
More specifically, organisations should:
- Avoid unnecessary lockdowns of enterprise IT, such as preventing external collaboration with cloud storage, or not having an instant messaging platform. If you can anticipate your users’ needs, you may be able to prevent shadow IT from starting.
- Implement an effective and simple process for addressing users' requests, which should be put in place as quickly as possible. Again, if users don’t feel their needs are being addressed promptly, it encourages them to implement their own solutions.
- Have processes whereby users can quickly get access to services that might be outside what is normally available, in a controlled way, and that can be brought under increasingly tight control as needed.
- Introduce processes that can bring the unsanctioned service under control, such as by migrating data into corporately supported platforms.
- Develop a good cyber security culture so that staff will be able to communicate openly about issues, including where current policy or processes are preventing them from working effectively. A healthy cyber security culture makes it more likely for people to report instances of shadow IT. They will be reluctant to come forward if they fear they (or other members of staff) will be reprimanded. In other words, a poor security culture means you’re much less likely to detect shadow IT.
Help with addressing specific user needs
The NCSC has produced a range of guidance that can help organisations address common technology challenges in a safe and secure manner. By providing these services, you may prevent your staff adopting shadow IT to fulfil their genuine user needs:
- guidance on choosing an enterprise instant messaging solution
- guidance on choosing a video conferencing service that meets your business needs
- guidance on how to deploy and use a cloud service securely
- guidance on how to make sure your organisation is prepared for an increase in homeworking
- guidance on understanding the security of your organisation's AI systems
Technical mitigations
There are a range of technologies and commercial solutions that can help organisations manage the risk of shadow IT on the enterprise network. This includes X.509 certification, network scanners, cloud access security brokers (CASBs), secure access secured edge (SASE), and unified endpoint management (UEM).
One of the few effective controls to prevent employees from connecting unsanctioned devices is strong network access controls.
The most effective controls use cryptographic certificates issued to devices to decide whether to allow them onto networks. For ethernet this is typically using 802.1x protocol, and WPA2/3 enterprise for wireless networks.
An X.509 certificate is a digital certificate that uses the widely accepted international X.509 public key infrastructure (PKI) standard to verify that a public key belongs to the user, computer or service identity contained within the certificate. This will help you protect against new devices connecting to the network that haven’t been previously authorised. For more information, please refer to the NCSC’s Provisioning and securing security certificates guidance.
However, organisations must consider that there can be challenges with certificate-based network access controls:
- provisioning devices can be time consuming, particularly when first rolling out 802.1x
- not all devices can support 802.1x or WPA2/3 Enterprise, notably older devices or some printers, leading to some ports needing to have 802.1x disabled (and employees might plug in a router or other device into these ports)
- smaller organisations not using more enterprise-grade switches might not have support in the network fabric to support authentication by 802.1
- 802.1x has some flaws where you can connect an unauthorised device by using a network hub to impersonate a device after it has authenticated (this should be considered as malicious activity however as it is intentionally bypassing a control)
Despite these issues, 802.1x and WPA2/3 Enterprise can be effective controls to make it harder to connect unauthorised devices, particularly in sensitive networks or sensitive regions of networks. Port control-based on network adapter MAC address can offer a lightweight approach to access control, although this makes it much easier for someone to evade when connecting a device.
When access controls are paired asset management (see below), this can help you understand what shadow devices you have. It’s important to keep this up to date, so you can prepare for all eventualities.
Having up-to-date and relevant information on the expected assets in an organisation is important in being able to identify shadow IT. In very small organisations (around 20 people or less), this could be as simple as a manually-maintained spreadsheet. For larger organisations, more advanced tooling will be required. Ideally, asset management systems will include key information including physical details of the device, location details, software version details, ownership, and connectivity information (such as hostname, IP address, network adapter MAC addresses, etc).
The larger an organisation, the more automated the process of populating and updating the asset management register needs to be to ensure it’s accurate. For more information refer to the NCSC asset management guidance.
There are numerous tools that allow you to scan an internal network to identify devices on it, such as using a dedicated device to perform scanning, or an agent installed on devices. However, organisations should be aware that there are risks of giving a network scanner credentials and the ability to scan all network ranges, making the scanner itself a valuable target for attackers. The generated lists of devices can be compared to lists of known assets, or used to monitor for assets that have appeared (particularly if the scanner is able to identify information such as hostname). External scanners can be useful in to identify which of your devices can be detected externally by an adversary, and hence potentially be used to access your network.
Cloud Access Security Brokers (CASB) aim to identify the use of cloud services by users, typically by monitoring traffic on the network. Different CASB’s can work in different ways, although a common pattern is to proxy all connections by users on the network to a central cloud-based service. This can provide visibility and potentially control over the services that users interact with. This can help to identify use of unapproved cloud services, although without breaking/intercepting encrypted connections will not be able to identify unapproved use of approved cloud services (i.e. personal accounts) or provide visibility into what users are doing in approved services.
CASBs are often included as part of a Secure Access Service Edge (SASE) solution, which can provide additional visibility and control over traffic on the network.
Unified Endpoint Management (UEM) tools seek to monitor, manage and secure your organisations end point devices from a single dashboard. If deployed well, then any device connecting to the network that isn’t owned by the organisation should be identified as shadow IT, at which point you then either remove it, enroll it, or adopt it. However note that in large organisations, onboarding many different classes of device can be highly resource intensive.


