Skip to content

Shadow IT and Unmanaged Assets

The systems nobody told you about, why they appear, and how to find them without becoming the enemy.

Editorial team 2 min read

Every organisation has systems outside its own inventory: a marketing microsite, a data science VM, a SaaS trial that became load-bearing, a demo environment with production data.

Why it happens

Rarely malice. Usually the official route was slow, so somebody used a corporate card and solved their problem. Treat that as a signal about your own processes, because a programme that punishes shadow IT simply makes it better hidden.

How to find it

  • Expenditure. Card statements and invoices find SaaS faster than any scanner.
  • Identity. Sign-in logs for the identity provider show which applications people actually use; OAuth grants reveal what has been given access to corporate data.
  • DNS and egress. Outbound requests to cloud consoles and API endpoints.
  • Certificates and passive DNS, for anything published under your domains.
  • Cloud billing, which knows about accounts that no inventory does.

What to do with it

Decide per asset: adopt (bring it under management), migrate (move the function into a supported platform) or remove. Adoption needs to be genuinely easy or the cycle repeats.

The durable fix is a paved path: a quick, documented way to get a project, a domain, a cloud account or a tool with sensible defaults already applied. Shadow IT is a routing problem, and routing problems are solved by better roads rather than more signs.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025