Build and Buy

    Bringing shadow IT into order

    By Redaktion techport.ai, IT-Beratung · Last updated on

    Shadow IT is not misconduct by employees but feedback. It emerges when a need arrives faster than a solution, and it grows when the official route takes too long. A marketing team books a campaign tool, sales uses a service for quotations, production keeps lists in a cloud storage nobody approved.

    The problem is not whether those tools are good or bad. The problem is that company data sits in systems nobody has reviewed, for which there is no contract, and which can disappear when the responsible person leaves.

    How you notice it

    • The credit card statement shows monthly amounts for services nobody in IT knows.
    • A customer asks which systems are in use and the list is incomplete.
    • Staff report incidents in applications IT has never heard of.
    • After someone leaves it is unclear who has access to an important account.

    Why this happens

    Departments buy tools because they have a problem and because it is technically possible today: a service is booked in ten minutes and needs no installation. The official route by contrast takes weeks, sometimes ends in a refusal without an alternative, and therefore feels like a brake. As long as IT answers requests with delay or with no, shadow IT is the rational response. It does not disappear through stricter rules but through a faster route.

    How we go about it

    1. Make it visible without blame. We find existing services through several routes: invoices and credit card statements, network data, sign-ins with company accounts and open conversations in the areas. What matters is the message that this is about order and not about consequences.
    2. Assess by risk. We assess per service which data is processed, who has access, whether a contract and a processing agreement exist, where the data sits and how business critical the usage is. That produces three groups: adopt, replace, stop immediately.
    3. Adopt rather than ban. What makes business sense becomes official: with a contract, accounts at company level rather than personal ones, managed permissions, backup and a named owner. The department keeps its tool, the company gains control.
    4. Offer a fast route. We set up a simple procedure by which new tools are assessed and approved within days, with clear criteria and a standard check. A procedure that is faster than the workaround ends the problem for good.

    What you gain

    • A complete picture of where company data actually sits.
    • Contracts and access rights that survive a change of personnel.
    • Departments that use the official route because it is the faster one.

    From our projects

    The most effective measure is not the search but the message that usage can be disclosed without consequences. In projects that begin with an amnesty, more services come to light within a few days than through any technical survey. The second recurring finding concerns accounts: very often business critical services run through the personal account of one individual, sometimes through their private email address. That is usually the most urgent point, because independently of data protection it ties access to company data to a single person.

    Good to know

    Where personal data is processed in a self-booked service, the obligations of the GDPR apply whether or not IT knows about it. The controller is the company, not the department. In practice that means a data processing agreement under Article 28, an entry in the record of processing activities under Article 30, a review of the technical and organisational measures under Article 32 and, for providers outside the EU, a valid basis for the transfer. Tools with AI features additionally need classification under the AI Act.

    Häufige Fragen

    Should we block unknown services technically?

    Blocking helps with clearly impermissible services and with known risks. As a basic strategy it does not work, because it drives usage onto private devices where you cannot see it at all. More effective is the combination of a few clear prohibitions, a fast approval route and a good standard offering for the most common needs.

    How do we handle a service that has become indispensable?

    Adopt and secure it rather than switch it off. In practice that means moving the contract to the company, migrating access to company accounts, sorting out permissions, checking backup and export, and naming an owner. Only then can you assess calmly whether it is the right tool in the long run.

    Let us talk about Bringing shadow IT into order

    In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

    Further reading

    Back to the field Build and Buy

    Sources