// Episode 006

Shadow IT: Reading the Demand Signal

31 July 2026 · 15 min listen · 2,459 words

Unsanctioned software isn't a discipline problem. It's your users telling you what IT failed to deliver.

// Listen
Shadow IT SaaS Shadow AI
In This Episode

What You'll Take Away

Key Terms

Defined Plainly

Shadow IT
Technology acquired and used without IT knowledge or approval — most commonly SaaS bought on a departmental card or expensed by an individual.
Shadow AI
The AI-tool subset of shadow IT. Growing faster than general shadow IT because the tools are cheap, individually purchased, and often fed sensitive data by default.
SaaS discovery
The process of identifying unsanctioned subscriptions by cross-referencing expense data, single sign-on logs, network telemetry, and OAuth grants against the approved catalogue.
Orphaned admin account
An administrative account on a SaaS tool belonging to someone who has left the organization. Frequently the last remaining access path to data nobody knows exists.
Full Transcript

Read the Episode

The complete transcript — 2,459 words. Search it, quote it, or send the relevant section to a colleague who needs to see it.

Show / hide transcript

Hunting Shadow IT

Hey, everybody, and welcome back to the Operational ITAM podcast. I'm Bill Van Nort, and I hope you brought the flashlight I told you to bring, because today we're going hunting in the dark. Shadow IT. The tools your business bought without telling you. The servers nobody owns. The subscriptions hiding in expense reports. The episode I warned you way back in episode one might make your security team sweat.

If you're new to the show, welcome. Glad to have you. This one stands alone just fine, but it connects to everything. The gates from episode two, the ledger from episode three, and the audit findings we spent two episodes fighting. Because here's the through line. An awful lot of what goes wrong in asset management was born in the shadows.

Today we find out where the shadows come from. And I'll warn you now, the answer is going to be uncomfortable. Because some of it comes from us. Good morning, good afternoon, or good evening, wherever you happen to be listening from. This is the Operational ITAM Podcast, the show where we take the unglamorous machinery of enterprise technology and make it make sense.

I'm your host, Bill, and today's episode requires a little humility, mine included. Welcome in, grab your coffee, grab your headphones, and let's get into it. First, the definition, because I promised you I'd always define my terms. Shadow IT is any technology—hardware, software, cloud service, and lately, artificial intelligence—acquired and used inside your organization without the knowledge, approval, or management of your IT function.

The marketing team's design subscription on a corporate card, the developer's personal cloud account running a workload that quietly became production, the department that bought its own laptops because yours took too long, And the newest resident of the shadows, the AI chatbot half your workforce is using and most of them aren't mentioning.

We'll get to that one after the break, and it deserves its own segment, believe me. Now before we talk about scale, I want to do something a little unusual for this show. I want to defend the people in the shadows. Because the standard industry framing, shadow IT as villainy, employees as rule breakers, IT as the wronged party, is not just self-serving, it's analytically wrong.

And if you start from the wrong diagnosis, you'll prescribe the wrong cure. Here's the honest truth from somebody who has sat in the CIO chair. Shadow IT is a demand signal. Every unsanctioned tool is a business need that showed up at your front door, found it locked, and went around back. One industry survey found that only about 1 in 8 IT departments can actually keep pace with the demand for new technology requests.

1 in 8. Which means, for the overwhelming majority of organizations, the official answer to, I need a tool to do my job, is, functionally, wait. And people whose bonuses, deadlines, and careers are on the line do not wait. They swipe the card. Would you wait? Be honest. I've been the guy whose process was being routed around, and when I finally stopped being offended long enough to ask why, the answer stung.

Because my process was slower than their problem. Write that down, because it's the thesis of this whole episode. People don't route around IT because they're villains. They route around IT because the sanctioned path is slower than their problem.

Shadow IT Costs

That's the empathy. Now here's the accounting, because sympathy for the cause does not erase the cost. Scale first. Gartner has estimated that 30-40% of IT spending in large organizations happens as shadow IT, outside IT's visibility and control. Sit with that. If your official technology budget is $50 million, there may be another $15 or $20 million in technology spend scattered across expense reports, departmental budgets, and purchase cards that your ledger has never heard of.

And the visibility gap is worse than the spend gap. Research has repeatedly found organizations formally tracking on the order of 100 cloud services while actually using close to 10 times that number. 10 times. Your ledger from episode 3? If you haven't hunted the shadows, the right hand column, the deployment side, isn't just incomplete.

It's a rounding error of the truth. Now, the risks, and there are three, in escalatory order. Risk 1. Waste. Shadow purchases mean duplicate tools. Three departments buying three different project management platforms, none at volume pricing, all renewing automatically, none appearing at any renewal negotiation. Remember the SaaS numbers from episode 3?

Roughly half of purchased licenses going unused? Shadow spend is where that problem goes to hide, because nobody can right-size a subscription nobody knows exists. Risk 2. Audit exposure. Think back to the two-parter. Where do you suppose those findings come from? They come from right here. A department stands up software on a server nobody told licensing about.

A team downloads a free tool, and we learned in Episode 3 exactly what free can turn into. One licensing change, and that friendly little runtime is billing you per employee. When the audit letter lands, the shadows get counted. At list price. Whether you knew about them or not. Ignorance is not a defense recognized in any license agreement I have ever read.

And I have read more of them than any human should. Risk three, and it's the big one, security. Unsanctioned tools mean unmanaged tools. No patching, no multi-factor enforcement, no offboarding when the employee leaves, corporate data sitting in personal accounts. The breach research year after year links a meaningful share of security incidents to unmanaged, unsanctioned technology, and breach costs run to the millions.

Every zombie asset, remember the zombies? A device on your network your record's never heard of? Every shadow app is the software version of a zombie, drawing data, drawing risk, invisible to every control you have. Your security team can't protect what your asset program can't see. That sentence, by the way, is how you get your security team to fund your asset program.

You're welcome. If you're enjoying the show, do me a favor, like and subscribe, post your comments, and share this episode with a department head who's quietly built their own technology stack. And when you send it, tell them it's not an ambush. This one's on their side.

Shadow AI Rises

All right, and now the segment I promised. Let's talk about the newest, fastest growing shadow in the building, shadow AI. Everything we just said about shadow IT applies, but compressed and amplified. Employees adopted generative AI tools faster than any technology in my 30 years, faster than any governance process on earth could keep up with.

And surveys suggest a majority of the people using AI at work are doing it quietly. One widely cited finding put the share of workers hiding their chatbot use from their employer at around 70%. Now here's why this shadow is darker than the old ones. When somebody used an unsanctioned file sharing app in 2015, the data sat somewhere it shouldn't.

Bad. But when somebody pastes your source code, your customer list, or your draft contract into an unmanaged AI tool, that data doesn't just sit. It leaves. Into a third-party system entirely outside your control. The payload changed, and the breach data has caught up. IBM's most recent cost of a data breach research found roughly one in five breached organizations was compromised through Shadow AI, and those incidents ran hundreds of thousands of dollars more expensive than the average breach.

This is not a future problem. This is a current line item. But, and here is where 30 years of pattern recognition earns its keep, we have seen this movie. Shadow AI in 2026 is Shadow Cloud in 2012 wearing a smarter costume. And we know how that movie ends, because the industry already ran the experiment. Bans alone failed. Blocking the popular tool just pushed usage to personal devices and lesser-known tools that were harder to see and worse on security.

What worked was visibility plus a sanctioned alternative. Give people an approved tool that's actually good, make it easier to use than the shadow version, and watch the shadows thin out on their own. Keep that in your pocket. It's about to become the whole strategy. Which brings us to a listener question right on cue. Dave from Milwaukee writes, Bill, my CISO wants to block every unsanctioned app at the firewall and be done with it.

Gut feeling says that's wrong, but I can't articulate why. Dave, your gut is smarter than the firewall. And here's the articulation. Blocking treats the symptom and feeds the disease. The need that drove someone to that tool doesn't vanish when the tool gets blocked. It goes to their phone, their home network, their personal account, where you have zero visibility instead of partial visibility.

You haven't eliminated the shadow, you've made it darker. Block the genuinely dangerous stuff, absolutely, but pair every block with a sanctioned path, or you're just running an expensive program to make your blind spots blinder.

Finding Hidden Tools

So how do you actually find the shadows? You promised your flashlight. Here it is. Five beams. None of them require new budget, and every one of them uses data you already have, which by now you know is my favorite kind of project. Beam 1. Follow the money. Pull your purchase card and expense report data and filter for software and subscription merchants.

Then pull your accounts payable vendor master and look for technology vendors that procurement never onboarded. The shadows are self-documenting. People expense them. It is the single richest shadow IT data source in your company, and it's sitting in finance, one polite email away. Beam 2. Follow the identity. Your single sign-on and identity platform logs show what applications people authenticate to, including the ones that were never formally sanctioned.

And look hard at OAuth grants. Every time an employee clicks Sign In With Your Work Account on some third-party app, they've connected that app to your environment. That consent log is a shadow inventory writing itself in real time. Beam 3. Follow the network. DNS queries, web gateway logs, egress traffic. Your network team already sees every cloud service your organization talks to.

They've just never had a reason to hand asset management the list. Give them the reason. Beam 4. Follow the endpoint. Your endpoint management platform, the one I've been telling you to lean on since episode 1, knows every installed application, including the ones that never pass through a gate. That's the same normalization work from episode 3, pointed at a darker corner.

And lastly, beam 5, the one everyone forgets. Just ask. Run an amnesty survey. Tell people, in plain language, no punishment, no gotcha. Tell us what you're using and why, and we'll try to make the good stuff official. You will be astonished what people volunteer when the question isn't an accusation. And the why answers? That's free consulting on exactly where your service catalog is failing.

What To Do Next

Which brings us to the response. You've found the shadows. Now what? Three buckets. And notice there's no bucket labeled punish. Bucket 1. Adopt. A lot of shadow tools are genuinely good. That's why people chose them. Sanction them. Negotiate real terms. Bring them into the ledger and let the team keep their tool. You just converted an adversary into an ally.

Bucket 2. Migrate. Where 5 shadow tools do one job, consolidate to one sanctioned choice, with a transition period and actual help, not a memo. Bucket 3. Retire. The genuinely dangerous ones, the data leaking, the unlicensed, the abandoned, get shut down, with an explanation of why. Because when IT says because I said so, that is how the shadows formed in the first place.

And then the permanent fix, and you knew this was coming. Gate 1, Episode 2, the request gate. A fast, clear, well-stocked service catalog is the single best shadow IT prevention technology ever invented, because the shadows are exactly the shape of whatever your catalog can't deliver quickly. Speed up the front door, and the back door traffic drops on its own.

Let's take it to the library one more time. The head librarian is doing her rounds one evening, and behind the boiler room she finds. A second library. Shelves the patrons built themselves. Books nobody cataloged. Some wonderful. Some borrowed from lenders with, let's say, alarming terms and conditions. Her first instinct is fury. But then she reads the note tacked to the doorframe.

Acquisitions take six weeks. We needed the books now. And a wise librarian, the kind who keeps her job, doesn't burn down the reading room. She catalogs the good books, replaces the dangerous ones, thanks the patrons for showing her exactly which collections the library was failing to stock, and then she fixes the acquisitions desk. Because the secret library was never a rebellion, it was a suggestion box she'd been ignoring.

One closing principle, and the arc continues. Hardware is a custody discipline. Software is an evidence discipline. Audit defense is a process discipline. Settlement, a commercial discipline. Shadow IT? Shadow IT is a service discipline. The shadows are not a security problem you punish or a compliance problem you audit. They are a service problem you out-compete.

Make the sanction path faster than the shadow path and the shadows shrink. Let the sanction path stay slow and no policy on earth will save you. You don't fight shadows with rules. You fight shadows with light. And with a front door that opens faster than the back door.

Refresh Debate Next

Class dismissed. Homework. And this one might be the most eye opening yet. Get 90 days of purchase card and expense data from finance. Software and subscription merchants only. Count the distinct products. Then count how many appear in your asset records. That gap, that exact number, is your shadow. Measured, dated, and ready for the one page brief you learned to write last episode.

Fair warning from someone who has run this exact exercise more than once, the number will be bigger than you think. It always is. Every single time. Next episode, we take on a fight I promised in the very first show, the Great Refresh debate. Three years? Four? Five or more? The vendors have brochures, the CFO has opinions, and I have actual failure rate data.

And one of those three is going to win. We'll find out which. That's today's episode. The flashlight is yours now. Go point it somewhere uncomfortable. I'm Bill Van Nort. This is the Operational ITAM Podcast. Like the shadows, speed the front door, and I'll see you next week. Take care.

Sources & Further Reading

Everything Referenced

Listener Case Files

Got a Situation Like This?

Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. Situations get worked on air.

Submit a Case File
From Listening to Doing

Apply This to Your Own Environment

The podcast covers the principles. An Executive Briefing applies them to your renewal calendar, your portfolio, and your actual numbers. 45–60 minutes, no charge.