
The term Shadow IT refers to IT devices, software and services outside the ownership or control of IT organizations. And, although the terminology makes it sound kind of shadowy or illicit in nature, Shadow IT has grown out of necessity. With the advent of Software-as-a-Service (SaaS) applications and the increasing acceptance of Bring Your Own Device (BYOD) to the office, employees are looking to get their work done in ways that seem easiest and most effective to them.
Yet, there are real risks involved. At times, certain protections and safeguards will be forfeited with Shadow IT, even though the users themselves don't realize it. Much of today's advice to IT departments for handling Shadow IT is to learn how to deal with it and coexist, rather than trying to shut it down, as outlined in this article Shadow IT: 8 Ways to Cope in InformationWeek. Clearly, a strategy that lets employees be effective, but also affords the necessary protections is needed.
This post will discuss the immense scope of the Shadow IT issue, the risks inherent with unauthorized software, and the instances where it is essential to enforce IT policies in order to enable protection strategies.
How widespread is Shadow IT?
Armed only with a credit card and a browser, anyone can purchase low-cost subscription licenses and have a new application up and running in no time at all, explains the article Managing Shadow IT in ComputerWeekly.com. Even importing corporate data and integrating with other enterprise applications can be achieved, without IT having any involvement or even awareness of new systems.
As of August 2015, in a study of large enterprise customers, Cisco determined IT departments estimate their companies are using an average of 51 cloud services, when the reality is that 730 cloud services are being used. And this challenge is only going to grow. They expect that this 15x multiplier will continue to grow as well. Cisco points out the hidden costs of Shadow IT - including greater business risk - are 4 to 8 times higher than the costs from the cloud provider.
Another study titled The Hidden Truth behind Shadow IT, conducted by Frost & Sullivan and sponsored by McAfee, found that more than 80 percent of the 600 respondents used non-approved SaaS applications in their jobs - and IT employees were the worst offenders. By their figures, the average company utilizes around 20 SaaS applications; and of these, more than seven are non-approved. With over 80 percent of employees admitting to using non-approved SaaS in their jobs, businesses clearly need to protect themselves while still enabling access to applications that help employees be more productive, said Pat Calhoun, general manager of network security at McAfee.
Where are Employees turning to Shadow IT the Most?
The Frost & Sullivan survey says non-approved SaaS encompasses every category. Business productivity (e.g., word processing, spreadsheets) is the top category, with 15% of all employees admitting to utilizing applications such as Microsoft Office 365 and Google Apps. Social media applications, led by LinkedIn and Facebook, are used by 12% of respondents, without official approval; and File Sharing, Storage, and Backup applications (including Dropbox and Apple iCloud) follow at 11%.
So What's the Risk?
Employees who deploy SaaS applications can put their organization at serious security risk of data loss, breaches, or attacks. Interestingly, approximately 40% of both IT and line-of-business respondents realize that sensitive corporate and personal data could be accessed or stolen by malicious actors or exposed to unauthorized users. About 15% of participants have either experienced or perceived a security incident-malware infection, data loss, unauthorized or blocked access-associated with using a particular SaaS application, as shown in this figure from the Frost & Sullivan survey:
From a broad perspective, the ComputerWeekly.com article outlines the four key risk of Shadow IT as:
Software Asset Management (SAM) Compliance
Governance and Standards
Lack of testing and change control
Configuration Management
Elastica, a Blue Coat Company, has published a report on Shadow Data which they define as all potentially risky data exposures lurking in cloud apps, due to lack of knowledge of the type of data being uploaded and how it is being shared. They report that of all the documents the average user stored in the cloud, 25% were broadly shared and of those, and 12.5% contained compliance-related data and source code.
Are your Mission-Critical Applications Protected?
Of course, this leads us to think about how the widespread use Shadow IT means that traditional forms of software protection, such as technology escrow, will often be bypassed when IT and procurement departments are not involved in SaaS subscriptions, and they are handled directly by employees.
Without the oversight of IT, certain protections aren't put into place, and this is particularly important for the mission-critical applications that have a significant impact on your business.
What would happen if the SaaS provider went out of business, was acquired, or failed to support your SaaS application? When an application was subscribed to by an employee acting on their own, you're out of luck. You face loss of productivity due to application downtime, loss of revenue, data loss, and potential brand damage.
On the other hand, when a mission-critical SaaS application is acquired through the IT department, a protection strategy such as SaaSProtect from Iron Mountain - a special form of technology escrow protection for SaaS applications and data - is often put into place. SaaSProtect ensures you will have access to your data and the application itself even if something were to happen to the software or the company hosting it. It gives you a
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
06/09/2026
June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
20/06/2026
New add-on creates doubles & vocal stacks
IK Multimedia's latest ReSing add-on kits the innovative software out with the ability to automatically genera...
20/06/2026
What exactly is Apogee Control V3?
Control V3 is a new mixer application that controls Apogee interfaces. The new hit feature is that V3 finally allows for...
19/06/2026
Split compound eases operational challenges at Shinnecock Hills Golf Club...
19/06/2026
North Carolina, Oklahoma meet in the best-of-three Finals as ESPN leans into spe...
19/06/2026
Company launch comprehensive mix-comparison tool
The Him DSP are a plug-in company founded by The Him, an EDM DJ and producer who has amassed over half a bi...
19/06/2026
Major Sampler upgrades introduced
The latest version of Bitwig's DAW software has just entered public beta testing, and is available now for all users w...
19/06/2026
Four times the power of their predecessors
Akai Pro have just introduced upgraded versions of two of their popular standalone MPC systems, kitting them out ...
19/06/2026
Data from May shows seasonal outdoor trends triggers lower viewing
Warsaw, Pola...
19/06/2026
Buttons is best control system in the rAVe Best of Infocomm Awards 2026...
19/06/2026
Mavis Studio Makes iPad Production More Powerful
Brie Clayton June 19, 2026
0 Comments
InfoComm update brings new NDI Preview, PTZ control, USB audio ...
19/06/2026
Immersive Studio Metaverse Stage Tackles Post with Blackmagic Design
Brie Clayton June 19, 2026
0 Comments
New narrative projects rely on DaVinci Reso...
19/06/2026
How to Run the Original 1993 After Effects
Graham Quince June 19, 2026
0 Comments
How to the original After Effects v1 in an emulator, and you don'...
19/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
19/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
19/06/2026
SMPTE , the home of media professionals, technologists and engineers, has announced that its entire Standards catalog is now freely available to the global medi...
19/06/2026
nsign, the digital signage SaaS platform built around its core principle of Simplify Complexity, has announced a partnership with BrightSign , expanding the dep...
19/06/2026
Visual Productions announces the availability of its new RdmRelay2 at InfoComm 2026 (ACT Entertainment, Booth N6813). A networked, four-channel DMX relay, it is...
19/06/2026
Adobe Unveils Major Expansion of Creative Agent Across Firefly and Creative Clou...
19/06/2026
Immersive Studio Metaverse Stage Innovates Storytelling with URSA Cine Immersive
Brie Clayton June 18, 2026
0 Comments
Two new narrative short films c...
19/06/2026
Friday 19 June 2026
How to watch the 2026/27 Premier League season on Sky Sports
Which matches are Sky Sports showing on the 2026/27 Premier League opening we...
19/06/2026
Catch up on the latest developments across Baselight and Daylight v7, Nara and FilmLight API Wednesday 8 July, 5pm onwards
Firehouse: DCTV, 87 Lafayette St, Ne...
19/06/2026
Lab studies explain how new cancer drug works as it enters patient testing Immunologists at Scripps Research show how a new, experimental drug revives immune ce...
18/06/2026
Ratings Roundup is a rundown of recent rating news and is derived from press rel...
18/06/2026
PTZOptics has unveiled new Visual Reasoning demonstrations at InfoComm 2026 (Boo...
18/06/2026
IBC2026 will take place at the RAI Amsterdam from September 11-14, bringing toge...
18/06/2026
InfoComm 2026 held its first-ever Media Day on June 17, providing journalists an...
18/06/2026
FOR-A America has announced a Trade Agreements Act (TAA)-compliant LED display solution combining Alfalite's Litepix LED displays and Brompton Technology...
18/06/2026
In-venue and creative video staffers at the professional and collegiate level have one major thing in common: the intensity and attention to detail ramps up dur...
18/06/2026
The International Federation of American Football (IFAF) and TMRW Sports have an...
18/06/2026
AJA Video Systems has unveiled Io Xpand, a Thunderbolt 5-enabled PCIe expansion ...
18/06/2026
ESPN has announced its coverage plans for the 30th anniversary of the WNBA's...
18/06/2026
FOX Sports' Big Noon Kickoff will broadcast live from Wembley Stadium in Lon...
18/06/2026
InfoComm 2026 opened on Wednesday at the Las Vegas Convention Center, bringing t...
18/06/2026
As media companies look to deliver more live, VOD, and snackable sports content ...
18/06/2026
Top L-R: Take Me Home, The Lake
Bottom L-R: TheyDream, Union County
Free Summer Screening Series Announced
Screenings for the Local Utah Community at...
18/06/2026
Improvements & new IR content
iamReverb Audio have just launched a free update that kits their convolution reverb plug-in out with some new features and int...
18/06/2026
Modelling suite gains improved captures, iOS support & more
Two notes Audio Engineering have just announced the launch of Genome 2.0, a significant update t...
18/06/2026
New AI assistance feature, video overhaul & more
VSL have just announced the launch of Vienna Ensemble Pro 8.1 and 8.1V, a pair of major updates to their ev...
18/06/2026
The average daily TV screen time in May was 3 hours and 36 minutes, marking a clear decrease of 15 minutes compared to April. This trend proved to be much stron...
18/06/2026
Integration embeds Gracenote content intelligence, including contextual segments...
18/06/2026
AJA Video Systems unveiled Io Xpand, a high-performance Thunderbolt 5-enabled PCIe expansion chassis for AJA KONA and Corvid video and audio I/O cards. As dema...
18/06/2026
New NVRT-driven workflow enables on-demand traffic mirroring and guided troubleshooting for AV teams, integrators, and support organizations ahead of InfoComm 2...
18/06/2026
At InfoComm 2026, Mavis announced a major update to Mavis Studio, its live production app for the iPad, with new features designed to make professional AV produ...
18/06/2026
Transaction Positions Harmonic as a Pure-Play Broadband Company
Harmonic Inc. (NASDAQ: HLIT), the worldwide leader in virtualized broadband solutions, today a...
18/06/2026
ACT Entertainment and NETGEAR have announced a strategic partnership that establishes verified interoperability between NETGEAR Switches and key technologies fr...
18/06/2026
IBC2026 is set to bring the global media, entertainment and technology community together at the RAI Amsterdam from 11 14 September, enabling industry players f...