Back to glossary

Shadow IT

2 min read

In security operations, shadow IT is the set of systems and services the business uses without the knowledge of security or IT: unmanaged and unmonitored. It is not usually rebellion. It is a team that needed something on Tuesday and found a way to have it working by Wednesday.

July 24, 2026
Compartir:

How it works

Three routes account for most of it. Someone signs up to a cloud service with a corporate email address and a card. Someone creates infrastructure in a cloud account that was opened for a project and never brought under central billing. Someone connects a third-party application to the corporate identity provider through an authorisation consent screen, which grants it access to mail or files without touching any server at all.

The last route is the one people underestimate: it needs no infrastructure, leaves no host to scan, and produces a live integration holding tokens against corporate data. Discovering it means reading grants in the identity platform, not scanning networks.

What goes wrong

Unmanaged systems miss everything the managed estate gets: patching, logging, backup, monitoring, offboarding. When the employee who created the service leaves, the account remains with a personal recovery address, which is a durable route back into corporate data long after their badge stopped working.

On external tests it is the standard source of our first foothold, because assets nobody owns are assets nobody patches, and they carry the corporate brand and often a real subdomain, which is where subdomain takeover starts. The 2026 version of the problem is shadow AI, where company data is processed by services procurement never saw, which adds a data protection question to the security one, since the record of what was sent to whom does not exist.

The response that fails is a prohibition. Every estate we test that banned unsanctioned services still has them, and now they are hidden more carefully. What reduces it is making the sanctioned path faster than the unsanctioned one, plus discovery that runs continuously.

Where this shows up in an audit

Discovery is part of every external engagement, it is reconciled against whatever asset inventory exists, and the first deliverable is the list of assets the client did not recognise, which is consistently the part that changes behaviour in the debrief. We attribute each one with evidence, since an inventory a client disputes is an inventory they ignore. Third-party application grants in the identity platform are reviewed alongside, because they are the exposure with no host to find. This is part of how we find the assets nobody told you about.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.