Shadow IT
Security
Unmanaged or unauthorized systems/services used outside official governance and controls.
Definition
Shadow IT includes unsanctioned SaaS apps, personal cloud storage, and unofficial devices. It creates blind spots in security, compliance, and retention and can lead to uncontrolled data sharing.
Why this matters
Why it matters: Organizations cannot protect what they cannot see; users can accidentally expose sensitive data.
Example
Example: Provide approved alternatives and implement discovery and access controls to reduce unsanctioned use.