Join our Newsletter — 33% off our NHI Course

What should organisations do when shadow IT is already widespread across departments?

When shadow IT is widespread, organisations should establish a governance framework that defines approved software, procurement rules, usage expectations, and decommissioning steps. They should pair that policy with continuous discovery, employee education, and centralised SaaS management so shadow usage can be reduced without blocking legitimate productivity needs.

What governance needs to cover once shadow IT is already embedded

When shadow it is already widespread, the goal is not a blanket ban. The practical response is to make “approved, reviewed, and supportable” the default path, while giving teams a fast way to request exceptions. That means defining what can be bought, who can approve it, how data may be stored, and how apps are retired when they are no longer needed.

Organisations usually fail when governance is written as a policy statement but not translated into procurement rules, onboarding criteria, and exit steps. The governance model needs clear ownership for business units, security, IT, procurement, and legal so that decisions are consistent even when departments adopt tools independently.

A useful way to think about this is that shadow IT becomes a portfolio problem, not just a compliance problem. Each application has an owner, a data classification, an access model, a contract status, and a retirement path. Without those basics, the organisation cannot tell which tools are acceptable risk and which ones create immediate exposure.

How to reduce shadow usage without slowing productive teams

The most effective programmes pair control with convenience. If approved tools are harder to obtain than unsanctioned ones, users will route around the process again. So the organisation should publish a small, usable catalogue of approved services, simplify intake for new requests, and remove friction from legitimate buying and onboarding.

Continuous discovery is the other half of the answer. Organisations need an always-on view of SaaS usage, unsanctioned data flows, and duplicate applications so they can distinguish harmless local productivity tools from services that handle sensitive data or create unmanaged access paths. Discovery should feed review, not just reporting.

Employee education matters when it is practical and specific. People need to know which types of tools are allowed, what data cannot be uploaded, when a departmental workaround becomes a governance issue, and how to escalate a tool request instead of buying first and asking later. Training works best when it reflects the actual purchasing and usage patterns seen in the business.

What “centralised SaaS management” should actually do

Centralised SaaS management should give the organisation a control point for inventory, approvals, renewals, access review, and decommissioning. It should also show which services are redundant, which ones have no clear owner, and which subscriptions should be consolidated into an approved platform.

The value is not just financial. A central view makes it easier to enforce retention, revoke stale access, and verify that business-critical tools still have support, logging, and recovery arrangements. It also reduces the chance that a departed team member leaves behind an orphaned subscription or an unmanaged integration that still has access to corporate data.

In practice, this works best when SaaS management is tied to procurement, directory services, and security review rather than treated as a separate inventory exercise. The more the organisation can connect purchase, identity, and usage data, the faster it can decide whether a tool should be approved, constrained, or removed.

Risk and Threat Considerations

Shadow IT creates unmanaged exposure because the organisation loses visibility into what data is being stored, who can access it, and whether the service meets basic security expectations. The main risk is not only the tool itself, but the accumulation of unsanctioned exceptions that weaken governance, complicate incident response, and increase the chance of data leakage or account compromise.

Failure mechanism: Departments adopt tools outside approved channels, then connect them to company data, shared credentials, or informal admin access. That breaks inventory, ownership, and review processes, which makes it harder to spot excessive access, insecure configurations, or stale subscriptions before they become incidents.

Impact: Sensitive data can spread across services with inconsistent security controls, recovery becomes slower, and the organisation may be unable to prove who approved access or where data resides. Over time, shadow IT can also create duplicate spending and fragmented operational accountability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-1 — Inventory and Control of Enterprise Assets Shadow IT requires a current inventory of software and services.
CIS-6 — Access Control Management Unapproved tools often create unmanaged access paths and stale accounts.
Recommendation — Maintain an authoritative software and service inventory with ownership and approval status. Restrict and review access to SaaS tools through centralized control.
ISO/IEC 27001:2022 A.5.9 — Inventory of information and other associated assets Widespread shadow IT needs asset visibility to govern approved services.
A.5.23 — Information security for use of cloud services Shadow IT commonly involves unsanctioned cloud services and SaaS use.
Recommendation — Keep an inventory of sanctioned applications, owners, and data dependencies. Set approval and security requirements for cloud services before adoption.
NIST CSF 2.0 GV.PO-01 — Policy The question is about defining approved software, procurement rules, and usage expectations.
ID.AM-01 — Physical devices and systems inventoried Discovery and inventory are central to managing widespread shadow IT.
PR.PS-01 — Configuration management Approved SaaS management depends on controlled configuration and standardisation.
Recommendation — Establish policy that defines approved software, procurement, and decommissioning rules. Continuously discover and inventory the software and services in use. Standardize approved SaaS configurations and review changes through control.

Practitioner Guidance

What to prioritise: Start with the highest-risk services first, especially those handling regulated, customer, or operationally critical data. A low-risk productivity app is not the same as a collaboration tool connected to finance, HR, or production workflows.

What to verify: Before trusting any “approved” status, confirm that the tool has an owner, a renewal date, a data classification, an offboarding path, and a clear access model. If any of those are missing, the app is already partially unmanaged.

What good looks like: Teams can still move quickly, but new software passes through a visible intake path, existing software is discoverable, and every material service has a retirement plan. The objective is controlled adoption, not perfect centralisation.

Practitioner takeaway: The most effective shadow IT response is to reduce the incentive to bypass governance while increasing the organisation’s ability to see, approve, and retire what departments already use.