Shadow IT
Shadow IT refers to software, cloud services, and devices that employees use without the IT department's approval.
Shadow IT describes applications, devices, and cloud services used without the IT department's knowledge or approval. It often arises because employees want to work more quickly or conveniently.
How it works
A team might sign up for an online project management tool and upload customer data. A department may use private cloud storage to share large files. Employees could use AI chatbots for texts containing confidential information. The IT department is unaware and cannot protect access or data. When an employee leaves the company, these accounts often remain active.
An example from practice: A marketing team used an external survey tool for two years. They shared a single account with the password stored in a group chat. Following a data breach at the provider, the contact details of 5,000 customers became public. The IT department only learned of this after being contacted by a journalist.
What to look out for
- Make shadow IT visible through proxy logs, DNS, and cloud sign-ins.
- Offer good, approved alternatives, as prohibitions alone lead to workarounds.
- Introduce a simple process for approving new tools and services.
- Connect applications to SSO where possible for centralised account management.
- Establish and communicate clear rules for the use of AI tools.
Switzerland and regulation
If personal data is stored in unvetted services, a data processing agreement is often missing. This is problematic under the revFADP (revised Federal Act on Data Protection). The issue is worse if data is stored abroad. For financial institutions, shadow IT can also violate FINMA's outsourcing requirements.
Shadow AI
An emerging form of shadow IT is the uncontrolled use of AI services. Employees copy contracts, source code, or customer data into public AI chatbots. This data may be stored by the service provider. Depending on the terms, it could also be used for other purposes.
Typical mistakes
A common mistake is for IT to react with blanket prohibitions. This often pushes usage onto private devices, where it becomes completely invisible. Another error is failing to communicate why certain services are not permitted.
How we implement it
We identify the use of unknown cloud and AI services through proxy, DNS, and identity logs. We then report any unusual data flows to you with our analysis.