Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Shadow IT in SaaS and AI tools: what security teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19696
Topic starter  

TL;DR: Shadow IT now spans unsanctioned SaaS apps, unmanaged devices, shared files, and browser-based AI tools, with BetterCloud reporting an average of 106 SaaS applications per organisation and 59% of IT teams still concerned about unsanctioned services, according to Safetica and cited research. The governance lesson is straightforward: discovery, data classification, and exposure-based control matter more than blanket bans when users adopt tools faster than approved processes can absorb them.

NHIMG editorial — based on content published by Safetica: Shadow IT: The 3 Places It Hides in Your Company

By the numbers:

  • The average organisation is actually running 106 SaaS applications, which widens the gap between approved inventory and real usage.
  • 59% of IT teams remain somewhat or very concerned about unsanctioned tools, showing the issue is already a mainstream operational problem.
  • 39.2% of respondents named detection of unauthorized applications and unsanctioned cloud services among their top hybrid and multicloud security challenges.

Questions worth separating out

Q: What breaks when shadow IT sits outside identity governance controls?

A: Access reviews, offboarding, and privileged approval workflows lose reliability when shadow IT is outside the system of record.

Q: Why do SaaS app integrations create extra risk for IAM teams?

A: SaaS integrations create extra risk because they extend trust beyond the original user session through tokens, API keys, and delegated permissions.

Q: What do security teams get wrong about Shadow AI?

A: They often treat Shadow AI as an approval problem for software, when it is usually also an identity problem.

Practitioner guidance

  • Implement continuous discovery across SaaS, devices, and browser activity Use automated discovery to surface web apps, installed software, unmanaged devices, and file-sharing paths, then reconcile them against approved inventories and owners.
  • Classify data before you classify the tool Map which files, transcripts, and source code move through each unsanctioned service, then assign risk based on regulated or business-critical data exposure.
  • Treat Shadow AI as a separate control domain Create a specific review path for generative AI tools that considers prompt retention, training reuse, and who is allowed to paste confidential content.

What's in the full article

Safetica's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step discovery workflow for identifying unsanctioned SaaS apps, devices, and shared files across a lean environment
  • Practical guidance on separating personal activity from business exposure while preserving privacy controls
  • Details on how the platform scores tools by the classified data they touch and narrows enforcement to the riskiest services
  • Examples of how Shadow AI fits into the same governance model as SaaS sprawl and file-sharing drift

👉 Read Safetica's analysis of Shadow IT and Shadow AI exposure patterns →

Shadow IT in SaaS and AI tools: what security teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19287
 

Shadow IT is fundamentally an identity and data governance failure, not a software-compliance issue. The article correctly shows that the risk begins when approved identity pathways are used to reach unapproved services or personal accounts. In practice, that means the control gap sits between access ownership, data classification, and offboarding. Teams should treat unaudited tool adoption as a governance event, not a simple policy violation.

A question worth separating out:

Q: Who is accountable when access to regulated data is mishandled?

A: Accountability usually sits with the covered entity or service provider that owns the data environment, but business associates can also carry direct obligations under HIPAA. In practice, the IAM team, compliance function, and system owner must share responsibility for proving that access was authorized, reviewed, and revoked. The framework, contract, and technical record all have to agree.

👉 Read our full editorial: Shadow IT is a visibility problem before it is a policy problem



   
ReplyQuote
Share: