# Shadow IT in the mid-market: find unknown tools, assess them and bring them into order

> Why departments buy their own tools, which risks arise, and how to make shadow IT visible, assess it and move it onto an orderly path without punishing the departments.

URL: https://techport.ai/en/it-beratung/entwickeln-und-beschaffen/schatten-it

---

1.  [IT Consulting](/en/it-beratung)/
2.  [Build and Buy](/en/it-beratung/entwickeln-und-beschaffen)/
3.  Bringing shadow IT into order

[Build and Buy](/en/it-beratung/entwickeln-und-beschaffen)

# Bringing shadow IT into order

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

Shadow IT is not misconduct by employees but feedback. It emerges when a need arrives faster than a solution, and it grows when the official route takes too long. A marketing team books a campaign tool, sales uses a service for quotations, production keeps lists in a cloud storage nobody approved.

The problem is not whether those tools are good or bad. The problem is that company data sits in systems nobody has reviewed, for which there is no contract, and which can disappear when the responsible person leaves.

## How you notice it

*   The credit card statement shows monthly amounts for services nobody in IT knows.
*   A customer asks which systems are in use and the list is incomplete.
*   Staff report incidents in applications IT has never heard of.
*   After someone leaves it is unclear who has access to an important account.

## Why this happens

Departments buy tools because they have a problem and because it is technically possible today: a service is booked in ten minutes and needs no installation. The official route by contrast takes weeks, sometimes ends in a refusal without an alternative, and therefore feels like a brake. As long as IT answers requests with delay or with no, shadow IT is the rational response. It does not disappear through stricter rules but through a faster route.

## How we go about it

1.  **Make it visible without blame.** We find existing services through several routes: invoices and credit card statements, network data, sign-ins with company accounts and open conversations in the areas. What matters is the message that this is about order and not about consequences.
2.  **Assess by risk.** We assess per service which data is processed, who has access, whether a contract and a processing agreement exist, where the data sits and how business critical the usage is. That produces three groups: adopt, replace, stop immediately.
3.  **Adopt rather than ban.** What makes business sense becomes official: with a contract, accounts at company level rather than personal ones, managed permissions, backup and a named owner. The department keeps its tool, the company gains control.
4.  **Offer a fast route.** We set up a simple procedure by which new tools are assessed and approved within days, with clear criteria and a standard check. A procedure that is faster than the workaround ends the problem for good.

## What you gain

*   A complete picture of where company data actually sits.
*   Contracts and access rights that survive a change of personnel.
*   Departments that use the official route because it is the faster one.

## From our projects

The most effective measure is not the search but the message that usage can be disclosed without consequences. In projects that begin with an amnesty, more services come to light within a few days than through any technical survey. The second recurring finding concerns accounts: very often business critical services run through the personal account of one individual, sometimes through their private email address. That is usually the most urgent point, because independently of data protection it ties access to company data to a single person.

## Good to know

Where personal data is processed in a self-booked service, the obligations of the GDPR apply whether or not IT knows about it. The controller is the company, not the department. In practice that means a data processing agreement under Article 28, an entry in the record of processing activities under Article 30, a review of the technical and organisational measures under Article 32 and, for providers outside the EU, a valid basis for the transfer. Tools with AI features additionally need classification under the AI Act.

## Häufige Fragen

Should we block unknown services technically?

Blocking helps with clearly impermissible services and with known risks. As a basic strategy it does not work, because it drives usage onto private devices where you cannot see it at all. More effective is the combination of a few clear prohibitions, a fast approval route and a good standard offering for the most common needs.

How do we handle a service that has become indispensable?

Adopt and secure it rather than switch it off. In practice that means moving the contract to the company, migrating access to company accounts, sorting out permissions, checking backup and export, and naming an owner. Only then can you assess calmly whether it is the right tool in the long run.

## Let us talk about Bringing shadow IT into order

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our software](/en/loesungen)

## Further reading

[Build and BuyAutomating processes with low-codeWhere automation pays off, how to use low-code sensibly, which rules stop it becoming the next unmaintainable landscape, and how to measure the benefit.](/en/it-beratung/entwickeln-und-beschaffen/low-code-und-automatisierung)[Architecture and ApplicationsCleaning up the application landscapeWhich systems carry which process, where data originates, what is duplicated and what is being phased out. An overview that speeds up decisions instead of filling folders.](/en/it-beratung/architektur-und-anwendungen/anwendungslandschaft)[IT Governance and ComplianceImplementing data protection technicallyGDPR put into practice: technical and organisational measures, processor agreements, records, deletion concept, log data, third country transfers and handling data breaches.](/en/it-beratung/it-governance-und-recht/datenschutz-in-der-it)[KnowledgeIT maturity checkKnow where your IT stands in ten minutes.](/en/it-beratung/reifegrad-check)[KnowledgeIT glossaryTerms from IT, software and security, briefly explained.](/en/it-beratung/glossar)

Back to the field [Build and Buy](/en/it-beratung/entwickeln-und-beschaffen)

## Sources

*   [Article 30 GDPR, records of processing activities](https://gdpr-info.eu/art-30-gdpr/)
*   [Article 32 GDPR, security of processing](https://gdpr-info.eu/art-32-gdpr/)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
