# Shadow IT

**What is shadow IT?**

Shadow IT means the programs, devices and services used in a business without the IT function knowing about them. It rarely arises from bad intent. It arises because someone wants to get their work done.

Typical examples are a private cloud storage account for a large file, a translation service in the browser into which contract text is pasted, a private mobile phone carrying company email, or a tool a department bought for itself.

The problem is not the software itself. The problem is that nobody knows about it. It is not updated, it appears in no backup, it is not revoked when an employee leaves, and in the event of a data breach nobody knows which data is affected at all.

Bans help little, because the need remains. Ask openly instead what people actually work with, and provide a vetted route for the most common cases. An up to date record of the services in use is the basis for that.

## Related terms
- [IT asset inventory](https://vetosec.at/en/it-security/it-inventar/)
- [Attack surface](https://vetosec.at/en/it-security/angriffsflaeche/)
- [Cloud security](https://vetosec.at/en/it-security/cloud-sicherheit/)
- [Data breach](https://vetosec.at/en/it-security/datenleck/)

## Source
https://vetosec.at/en/it-security/schatten-it/ (vetosec, grundlagen)
