Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What happens when organisations allow remote workers to…
Cyber Security

What happens when organisations allow remote workers to use unapproved software and services?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Cyber Security

When unapproved software is tolerated, the organisation inherits third-party risk it may not understand or monitor. Each extra tool can introduce weak authentication, insecure storage, exposed integrations, or data sharing outside approved controls. The result is a broader attack surface, more paths for compromise, and a harder job for incident responders trying to trace where sensitive information has gone.

What changes when remote workers bypass approved software and services?

Allowing remote staff to adopt their own tools changes the control model from centrally governed access to an expanding set of third-party relationships. The immediate issue is not convenience, it is that the organisation no longer knows which services hold corporate data, which ones enforce strong authentication, or which ones create hidden integrations that survive long after the original business need has passed.

That shift makes shadow IT a visibility problem and a trust problem at the same time. If the company cannot inventory the service, it cannot confidently assess whether it stores files securely, logs access properly, or applies the same retention and deletion rules as approved platforms.

It also weakens the practical boundary between corporate and personal work. A remote worker may move information between approved and unapproved tools to get the job done faster, but that convenience can erase the assumptions behind data classification, monitoring, and incident response.

Why unapproved tools expand exposure and complicate control

Each unsanctioned application can introduce a different authentication model, permission set, storage location, and support relationship. That fragmentation matters because security teams end up defending a larger attack surface while also losing standardisation around logging, conditional access, patching, and offboarding.

Unapproved services often create the exact failure modes that approved controls are meant to limit: weak account recovery, unmanaged API keys, exposed sharing links, and data copied into systems with unclear jurisdiction or retention. When those tools are later linked to sanctioned systems, the integration itself becomes part of the risk.

Governance also degrades. Approval processes usually exist to answer basic questions about ownership, data handling, and vendor accountability. When staff self-select tools, those questions remain unanswered until a problem appears, which means the organisation discovers the exposure late and has fewer options for containment.

What incident response teams lose when they cannot see the tool chain

During an incident, responders need to know where the data went, which accounts touched it, and what external services may have cached or synchronised it. Unapproved software makes that reconstruction slower because logs are fragmented, ownership is unclear, and the organisation may not have contractual access to the records it needs.

That uncertainty can prolong containment. If the same document was copied into multiple consumer services, local sync folders, or browser-based collaboration tools, responders may have to treat each one as a potential source of exposure rather than a single controlled platform.

For that reason, NIST AI Risk Management Framework is not the direct answer here, but the same governance logic applies: organisations need an inventory of the systems that can materially affect data handling, trust, and accountability before they can manage risk well.

Risk and Threat Considerations

Unapproved software creates a classic shadow IT exposure: the business accepts data-sharing paths that were never reviewed for authentication strength, storage security, or monitoring quality. That increases the chance of account compromise, data leakage, and unnoticed third-party access, especially where remote workers connect personal convenience tools to corporate work.

Failure mechanism: The organisation loses control over the approved boundary, so sensitive data is duplicated into services with unknown logging, unclear retention, or weak access controls. Adversaries can exploit the extra surface through stolen credentials, insecure integrations, or exposed sharing settings.

Impact: A compromise or misuse in one unsanctioned service can spill into multiple systems, slow containment, and leave incident responders unable to prove exactly where the data resides or who can still reach it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.SC-01 — Cybersecurity Supply Chain Risk ManagementUnapproved services create third-party exposure and trust dependencies.
ID.AM-01 — Inventory of AssetsShadow IT is partly an asset visibility problem across remote work tools.
PR.AA-05 — Identity Management, Authentication and Access ControlRemote workers and their tools rely on authentication and access boundaries.
Recommendation — Inventory and govern third-party services that can receive or store company data. Maintain a current inventory of sanctioned tools and data-touching services. Enforce approved authentication and access policies for all remote work services.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeUnapproved services often expand access beyond what is needed.
CM-8 — System Component InventoryHidden tools and integrations undermine control over the environment.
Recommendation — Limit permissions and sharing paths to the minimum required for each service. Track all software and services that can process or store organisational data.

Practitioner Guidance

What to prioritise: Start with the tools that can store, sync, or forward sensitive data outside approved platforms, then map who can access them and whether business data is already flowing through them.

What to verify: Confirm that every remotely used service has an owner, a business purpose, and a documented decision on authentication, data retention, and offboarding. If any of those are missing, treat the service as unmanaged rather than merely inconvenient.

Common mistake: Teams often focus on blocking obvious consumer apps while ignoring browser extensions, file transfer tools, and collaboration add-ons that create the same exposure in a less visible form.

Practitioner takeaway: The control objective is not to eliminate every nonstandard tool, but to ensure that any tool handling company data is visible, governable, and removable without breaking incident response or data accountability.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org