Shadow It Explained: Risks & Opportunities

Cloud computing has made it easier for IT users to bypass IT procurement protocols in order to access the solutions they need to fulfil their job requirements. From a user perspective, IT oversight and stringent governance policies are often designed to protect the organization—not necessarily to address the challenges of IT users at the workplace.

The result is shadow IT: the practice of bypassing these limitations and accessing the required IT solutions without knowledge of the appropriate IT department.

This article introduces shadow IT and how it affects IT management and procurement. We will look at:

What is shadow IT?

Shadow IT is the use and management of any IT technologies, solutions, services, projects, and infrastructure without formal approval and support of internal IT departments.

Users might adopt shadow IT technologies that do not align with your organizational requirements and policies pertaining to:

As such, users of shadow IT bypass the approval and provisioning process and utilize the unauthorized technology without knowledge of their IT department.

Shadow IT systems can include:

  • SaaS, PaaS, IaaS, and other cloud services
  • Prepackaged off-the-shelf software
  • Hardware such as computers, smartphones, tablets and other devices

The most prevalent form of shadow IT systems are SaaS offerings, since these include unique products and solutions to address specific requirements of IT users that may not be identified, considered, or addressed by the vast array of common IT solutions already supported by the organization. The convenient purchase process allows IT users to subscribe, use, and decommission the shadow IT SaaS solution before the organization identifies the purchase or detects anomalous network activity.

The second most common source of shadow IT products is commercial desktop products, along with phone and tablet apps. Remote PCs and laptops are frequently configured as desktop administrators or they may be using their own devices not controlled by IT. Cellphones and tablets are usually locked down for email, but they are frequently left open for app installation. It is common to find unauthorized free and commercial products loaded on user devices. Many prohibited and dangerous apps sneak on to user devices this way.

Why do users turn to shadow IT?

Shadow IT is inevitable. IT users adopts shadow IT practices only to fulfill their job requirements in ways that make their life easier. Gartner research finds that an average of 30-40% of the purchases in the enterprise involve shadow IT spending. A research study by Everest Group found puts these figures closer to 50%.

Part of the problem lies with the organizations:

  • Not offering adequate support for technologies that IT users require.
  • Making the governance, approval, and provisioning process too slow and ineffective.

Especially for Agile or DevOps-driven organizations focused on continuous innovation and rapid software development and release cycles, the need for new tooling can arise with little warning for IT departments to identify, vet, and approve the products at the Agile/DevOps pace.

Inadequate communication and collaboration between developers and IT teams further bottleneck the speed and flexibility of IT support required to approve the necessary technologies. At the same time, inadequate security capabilities tend to prevent organizations from approving new technologies even when they want to support devs with the latest and greatest solutions available in the industry.

Robert Thorne

Robert Thorne

Automotive & Future Transportation Editor

Robert Thorne covers electric vehicle innovations, autonomous driving systems, global mobility trends, and automotive engineering developments.

Share this article