Shadow IT: The Sword of Damocles Hanging over Companies

Talkspirit
2021-12-07
4
min.

Temps de lecture: 4 minutes

The term “Shadow IT” (also known as “rogue IT” in North America or simply “phantom computing” in France) has been popularized over the last decade to refer to all information and communication systems implemented within a company without the approval of the IT department.

According to the U.S. based Gartner, which regularly explores this topic, it refers to “software, services or computing devices which are not owned or controlled by an organization’s IT department”. 

Being “out of control,” Shadow IT creates significant risks for companies. Using key figures (from recent third-party studies) and targeted findings, let’s focus on how this phenomenon threatens our livelihood and the integrity of our data. 

shadow-IT

 DOWNLOAD THE INFOGRAPHICS

It all starts with the employees

According to a study by the consulting firm Frost & Sullivan, “more than 80% of employees admit to using IT solutions without the formal approval of their CIO.”

Shadow IT is therefore a massive phenomenon, and the company must learn to defend itself. It’s estimated that out of about 20 SaaS applications used within a company, seven haven’t yet received approval from their IT department—more than a third!

Without bad intention and quite the contrary (because the motive is very often to improve their productivity), the employees themselves are the ones who invite a Trojan horse into their company… because they’re completely unaware of the risks.

Here are four situations in which Shadow IT inevitably develops: 

  • Employees consider that the tools their IT Department offers them do not meet their business needs.
  • The CIO is not responsive enough or doesn’t understand the business needs and constraints.
  • Employees feel they have no other means of obtaining the data they need for their missions.
  • Tools are so simple, fluid and almost instantaneous (Google Docs, Slack or Dropbox…) ”These apps can be downloaded in one click, so any need to notify the IT department may seem superfluous.” (Openip)

Thinking they can solve problems and save time, they create multiple risks for themselves, their coworkers and the entire company.

Multiple uses that are as many threats

According to the 2017 Shadow IT Report by CESIN, CIOs estimate their company uses an average of 30-40 cloud applications and services. In reality this figure is largely underestimated: we’re talking about 250 to 5,950 cloud apps per company, with an average closer to 1,700 apps (2017 Shadow IT Report). That’s a huge, disturbing perception gap of the need for Shadow IT control and prevention.

The cloud storage revolution has enabled businesses and individuals alike to take advantage of the cloud, or rather “clouds”. In its latest report ,Symantec counted more than 22,000 cloud applications with a business aspect and enabling information sharing! So many temptations for employees to import their favorite software into their company.

So, what are all these applications, cloud services and equipment that IT departments haven’t approved, and which vary greatly from one company to another?

  • social networks: Twitter, Facebook, Whatsapp 
  • storage and file sharing: Google Drive, Dropbox, Wetransfer
  • personal messaging: Outlook, Gmail, Yahoo
  • video sites: Youtube, Dailymotion 
  • personal devices: computer, tablet, telephone 
  • search engines: Google, Ecosia, Yahoo, Qwant

Another Trojan horse: the BYOD (“bring your own device”), which the CNIL defines as the use of personal computer equipment (tablet, telephone, personal computer) in a professional context. Abolishing the seal between professional and personal lives, between professional and personal software and between professional and personal data, the provision by the employee of his or her own equipment is also a major danger for companies.

Also read: Navigating Urbanization and Governance Within the Enterprise Social Network (ESN): Benchmarks 

Security flaws and risks of cyber-attacks

Shadow IT’s biggest threat? Cybercrime. According to the Gartner study, “by 2020, one third of all computer attacks will target Shadow IT.”

But a host of dangers await the company as it allows Shadow IT to progress within it, ranging from leakage of strategic data to the risk of virus infection and password theft.”

Here are some of the various risks and threats that Shadow IT represents for the company:

  • security: data breach or theft
  • cost: generally higher than solutions approved by the CIO
  • compliance: inconsistent application of processes throughout the entire company
  • dispersion of data and therefore loss of information
  • lack of technical integration of the tools between them and therefore poor circulation of information
  • durability: low durability (as an obsolete tool is immediately or at the same time replaced by another one)
  • noncompliance with the GDPR (General Data Protection Regulation)
  • reputation: risk to the company’s image in the event of a problem

A growing awareness nonetheless

According to a study published by Entrust Datacard, 77% of CIOs agree that by 2025, parallel computing will become a bigger problem in their organizations if they do nothing about it.

According to the results of the latest survey conducted by cybersecurity specialist Check Point and Dimensional Research, 95% of companies reported facing additional challenges with the implementation of large-scale remote access for employees and the use of unsanctioned IT tools (meaning Shadow IT).

The CIO is holding all the cards

To stop Shadow IT within the company and regain control over the tools/hardware/software employees use, CIOs can play several hands:

  • develop a network of correspondents within each business line to enable reporting on IT needs (and shortcomings)
  • provide more frequent assistance to business teams in the achievement of their projects
  • offer to provide reactive and efficient help on IT integration problems between business tools
  • … and raise employee awareness of risky behaviors

Indeed, of these, 42% say a clearer policy outlining how employees can request technology would help employees access new tools in a more IT-compliant manner. (source: Entrust Datacard, 2019)

Concerning the collaborative tools segment (which represents the bulk of Shadow IT), another approach is increasingly being taken by CIOs. To remedy Shadow IT, they’re choosing to adopt a collaborative platform that allows them to centralize, modernize and secure exchanges. A broad functional spectrum, natively integrated, which meets the essential business needs and thus avoids the employee needs for additional tools. 

Also read: Seven Unbeatable Arguments to Convince Your General Management to Deploy an Enterprise Social Network 

*
*     *

Are you seeking to drastically reduce the risk of Shadow IT practices in your company? The Talkspirit team is at your disposal to show you solutions and advise and support you in your project. Contact us or schedule a demo (free consultation, without obligation).

Contact us

Schedule a demo

Authors: Benoît Renoul, Hugo Bessaguet


[Based on analysis of third-party studies, this article and its related infographics illustrate the causes and challenges of Shadow IT for French SMEs & middle-market companies, putting them into perspective with the aim of raising awareness among IT managers.]

Inscrivez-vous à notre newsletter
En vous inscrivant vous acceptez notre politique de confidentialité et consentez à recevoir des nouvelles de notre entreprise.
Envoyer
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
ALLER PLUS LOIN

Vous avez les ressources pour passer à l’action

2025-01-24
7
min.

Top 10 Technology Trends in 2025, According to Gartner

2025-01-02
7
min.

Top HR Trends in 2025, According to Gartner

2024-12-26
6
min.

5 Strategies That Can Help Improve Employee Autonomy at Work

2024-12-19
6
min.

HR: Watch Out for These Employee Burnout Signs

2024-12-12
min.

[Expert Opinion] Elmy’s Journey to Becoming a Mission-Driven Company

2024-12-09
5
min.

Regenerative Business: the Trend Taking Companies by Storm

2024-12-05
6
min.

How can companies combine digital sobriety with well-being at work?

2024-11-29
7
min.

Agile Methodology: What Are the Pros and Cons for Businesses?

2024-11-19
8
min.

Creating OKRs Aligned with Your ESG Goals: a Step-by-Step Guide

2024-11-13
8
min.

Implementing Accessibility in the Workplace: Key Strategies and Best Practices

2024-11-13
6
min.

8 Steps to Create a Collective Intelligence Framework that Speeds Up Decision-making

2024-11-12
7
min.

Comment mesurer l’impact social et environnemental d’une entreprise ?

2024-11-07
7
min.

Management agile : 7 clés pour embarquer vos équipes

2024-11-07
5
min.

Meta Meltdown: What Can We Learn from the Workplace Closure?

2024-11-06
8
min.

How Can You Promote Sustainable AI in the Workplace?

2024-11-04
5
min.

Collaborative Platform: Definition and Challenges

2024-11-03
5
min.

20 collaborative tools to improve employee productivity

2024-10-29
8
min.

Parole d’expert : Comment améliorer l’équité, la diversité et l’inclusion en entreprise ?

2024-10-28
6
min.

7 Best Practices for Leveraging Emotional Intelligence as a Leadership Tool

2024-10-23
7
min.

RH : Les symptômes de burnout auxquels il faut être attentif

2024-10-17
7
min.

Améliorer l’autonomie au travail, c’est possible avec ces 5 leviers

2024-10-10
5
min.

Do Purpose-Driven Companies Outperform Traditional Ones?

2024-10-09
10
min.

Best Leadership Practices for Boosting Employee Engagement

2024-10-08
7
min.

[Parole d’expert] Comment devenir une entreprise à mission ?

2024-10-08
6
min.

Turn your employees into ambassadors for your enterprise social network!

2024-10-01
8
min.

How Does AI Impact Employees Within an Organization?

2024-10-01
6
min.

How can AI shape the future of self-management: insights from the academic literature

2024-10-01
7
min.

10 exemples d’utilisation du biomimétisme en entreprise

Article
2024-10-01
6
min.

Gartner’s 10 technology trends for 2024

2024-09-30
9
min.

What Participative Decision-Making Can Bring to Your Organization

2024-09-30
8
min.

How the Next Generation Company Is Redefining the Future of Work

2024-09-30
6
min.

How Do You Tactfully Handle a Micromanaging Boss ?

2024-09-30
8
min.

How Do You Give Constructive Feedback to Your Peers in a Self-Managing Organization?

2024-09-30
8
min.

How Consent-Based Decision-Making Works

2024-09-30
8
min.

From Corporate Hierarchy to Agility: How to Create Engaged and High-Performing Teams?

2024-09-30
7
min.

Driving Culture Change with Holaspirit: Insights from Welser Profile

2024-09-26
6
min.

5 Interesting Ways AI Can Transform Knowledge Management Processes

2024-09-17
7
min.

Critères ESG : pourquoi et comment les intégrer dans votre stratégie RSE ?

2024-09-10
10
min.

How Can You Improve Organizational Agility in the Workplace?

2024-09-10
5
min.

L’entreprise à impact : LA réponse aux défis du développement durable

2024-09-09
9
min.

How to Improve Cross-functional Team Collaboration

2024-09-05
6
min.

[Expert Opinion] Amicio’s Best Practices for Agile and Effective collaboration

2024-09-03
6
min.

Les entreprises à mission sont-elles plus performantes que les entreprises traditionnelles ?

2024-08-29
7
min.

Raison d’être, vision, mission : de quoi parle-t-on ?

2024-08-29
7
min.

Performance Management: 4 Keys to Building Effective Teams

2024-08-22
6
min.

Managers: 8 Hacks for Improving Teamwork Efficiency

2024-08-20
6
min.

Entreprise régénérative : de quoi parle-t-on ?

2024-08-13
6
min.

7 techniques éprouvées pour responsabiliser ses collaborateurs

2024-08-12
6
min.

Sustainable performance: the art of combining productivity and social responsibility

2024-08-09
6
min.

How Do I Set Up My Internal Communication on Corporate Social Responsibility (CSR)?

2024-08-08
6
min.

5 Examples That Show How Different Organizations Can Leverage the Same Collaborative Platform

2024-08-06
6
min.

[Webinaire] Opportunités et risques de l’IA : ce que les entreprises nouvelle génération doivent absolument savoir !

2024-08-04
5
min.

How to implement an enterprise social network in your company

2024-08-02
7
min.

How will artificial intelligence transform the way we work?

2024-07-30
7
min.

Nos 15 podcasts de management préférés

2024-07-25
8
min.

Key Employee Engagement Data from Gallup's 2024 Study

2024-07-25
10
min.

13 Icebreaker Ideas for More Dynamic Team Meetings

2024-07-23
7
min.

6 bonnes pratiques pour améliorer la cohésion d’équipe

2024-07-22
5
min.

Why Scale Ups Opt for a Self-Management Tool?

2024-07-22
5
min.

Why Is Accountability Important in the Workplace?

2024-07-22
8
min.

The Pros & Cons of Going Teal

2024-07-22
3
min.

The Power of Spotify Squads

2024-07-22
8
min.

Setting Roles Into Your Organization

2024-07-22
6
min.

How to Implement Effective Self-Management in the Workplace

2024-07-22
7
min.

Empowering the right people in the right roles

2024-07-22
7
min.

Our Step-by-Step Guide to Effective Governance Meetings

2024-07-22
5
min.

How to Measure the Success of Holacracy in Your Organization

2024-07-22
5
min.

Integrative Decision-Making VS Consensus

2024-07-22
9
min.

How the Liberated Company Unleashes Your Employees’ Potential

2024-07-22
8
min.

How To Instil Self-Advocacy in Employees and Build Stronger Teams in the Process

2024-07-22
10
min.

💥 How can Scaleups Grow Faster and Successfully by Integrating Strategy into their Organization Structure?💥

2024-07-22
10
min.

Everything you Need to Know About Organizational Health

2024-07-22
4
min.

Finding Your Organization’s Purpose

2024-07-22
15
min.

50 Effective Employee Engagement Strategies

2024-07-22
9
min.

Effective Team Meeting: Strategies, Agendas, and Checklist Included

2024-07-19
8
min.

Why Should you Consider Implementing a Shared Leadership Model?

2024-07-19
10
min.

What is Shared Governance?

2024-07-19
7
min.

5 Tactics to Adapt Your Business to a VUCA World

2024-07-19
5
min.

How Does Employee Engagement Affect Business Results

2024-07-19
6
min.

Agile Trends 2024: What is the Next Wave of Agile Transformation?

2024-07-18
6
min.

What Makes Self-Managed Teams Unique?

2024-07-18
5
min.

The Influence of Company Culture On Employee Engagement

2024-07-18
7
min.

How Does a Flat Organization Actually Work?

2024-07-18
5
min.

Essential Meeting Room Equipment for Modernizing Your Workspace

2024-07-16
9
min.

What Does a Transparent Company Actually Look Like?

2024-07-16
13
min.

What Is Self-Management?

2024-07-16
17
min.

The Best Self-Management Tools for Your Organization

2024-07-16
7
min.

What is Sociocracy? Introducing a Toolkit for Agile Organizations

2024-07-16
8
min.

Teal Organization: Everything You Need to Know

2024-07-16
6
min.

A Guide to Tactical Meetings (Agenda Template Included)

2024-07-16
4
min.

Org Chart Templates and Visual Organization Representation

2024-07-16
7
min.

How to Clearly Define Roles and Responsibilities Within Your Team?

2024-07-16
9
min.

How QoQa Managed to Successfully Implement Holacracy Using Holaspirit

2024-07-16
8
min.

How Great Place To Work Implemented Self-Management Using Holaspirit

2024-07-16
26
min.

Holacracy: Core Concepts, Benefits and Limitations

2024-07-16
8
min.

Example of Company OKRs, How Did They Do It?

2024-07-16
8
min.

8 Best Kept Secrets of High-Performing Agile Teams

2024-07-16
12
min.

5 organizational governance models to make your teams more agile

2024-07-16
6
min.

Les meilleurs outils SaaS pour votre entreprise

2024-07-09
6
min.

Gérer la communication interne d’une association avec Talkspirit : le défi de l’ARSL!