Your marketing coordinator signed up for a free design tool last month. Your accountant started using a browser-based spreadsheet app because it synced better with their home computer. Someone in sales downloaded an AI writing assistant to help with cold emails. None of these people asked permission, and none of these tools went through any security review.
This is shadow IT, and most small businesses have far more of it than they realize. Organizations often have many unauthorized applications running alongside their official software. For a small business, this can result in several unknown tools per person, each one a potential doorway for data theft or phishing attacks. Identifying these hidden apps is the first step toward securing your data, helping you determine which ones matter and clean up the risk safely.
You cannot fix problems you cannot see. The discovery phase requires some detective work, but the methods are straightforward enough for anyone to follow.
Start with credit card and bank statements from the past year. Look for recurring charges you don’t recognize, especially small monthly amounts. Software subscriptions often fly under the radar because they seem insignificant individually. Make a list of every charge that could be a software subscription, then cross-reference against your approved applications.
Ask department heads to review their team’s expense reports for software purchases. Employees often expense tools they found useful without realizing the security implications.
Browser extensions are shadow IT that most people forget about entirely. These small add-ons often have broad permissions to read data on every website an employee visits. Walk through company computers and document every extension installed in Chrome, Firefox, Edge, or Safari. Extensions that sync bookmarks, manage passwords, outside your official password manager, or enhance productivity often transmit data to third-party servers.
When employees click “Sign in with Google” or “Connect to Microsoft 365,” they grant third-party applications access to company data. These connections persist even if the employee stops using the app. Check your Google Workspace admin panel or Microsoft 365 admin center for a list of third-party apps with access to your company accounts. You will likely find tools you have never heard of with permissions to read emails, access files, or view calendar data.
The simplest discovery method is asking. Send a brief, non-judgmental survey asking employees to list every work-related tool they use that the company did not provide. Frame this as a security audit, not a witch hunt. Employees who fear punishment will hide the information you need most. Consider offering amnesty for honest disclosure during this initial survey period.
Not every unauthorized application poses the same threat. A browser extension that changes your cursor color is different from a cloud storage service holding customer contracts. Your remediation efforts should target the highest-risk applications first.
Create a simple scoring system for each discovered app:
Sort your discovered applications into three categories:
Block immediately: Apps with poor security reputations, excessive permissions, or access to sensitive data. These applications require immediate shutdown.
Evaluate for approval: Apps that serve legitimate business purposes and come from reputable vendors. These might become officially sanctioned tools after proper review.
Monitor and phase out: Low-risk apps that do not justify the effort of immediate removal but should not continue indefinitely. Set a deadline for transition.
Create a spreadsheet tracking each application with columns for: app name, vendor, number of users, data types accessed, risk score, and action decision. This document becomes your roadmap for the remediation phase and your proof of due diligence if questions arise later.
With your risk assessment complete, you can begin the actual cleanup. This phase requires both technical actions and communication with your team. Understanding how to implement automated phishing training alongside shadow IT remediation creates a stronger security foundation.
Start with the applications that have access to your core business systems. In Google Workspace, go to Admin Console, then Security, then API Controls. You will find a list of third-party apps with access to your organization’s data. Remove access for any application not on your approved list. Microsoft 365 has similar controls under Microsoft Entra ID, Enterprise Applications.
Revoking OAuth permissions does not delete data already collected by these applications. It only stops future access. Keep this limitation in mind as you proceed.
For company-owned devices, you can push browser policies that block unapproved extensions. Google Workspace and Microsoft 365 both allow administrators to create extension allowlists and blocklists. For devices you cannot directly control, provide clear instructions for employees to remove specific extensions themselves.
Contact vendors directly to cancel subscriptions and request account deletion. Many software vendors are subject to privacy regulations that require them to delete user data upon request. Send these requests in writing and keep copies. For applications where employees used personal accounts with company data, you will need their cooperation to complete the cancellation process.
Before removing access to any tool, talk to the people using it. Explain why the application poses risks and, where possible, suggest approved alternatives. Employees adopted these tools because they solved real problems. If you remove shadow IT without addressing the underlying need, employees will simply find new unauthorized solutions. According to CISA guidance, employee education about security risks helps reduce both phishing susceptibility and unauthorized software adoption.
Removing access to shadow applications is only half the battle. Company data sitting in abandoned accounts remains vulnerable. This phase focuses on getting that data deleted or recovered.
For each high-risk application on your list, determine what company data it might contain. Cloud storage apps might hold documents, spreadsheets, or presentations. Communication tools might contain customer conversations. AI tools might have processed confidential documents. Project management apps might contain client information, deadlines, and internal discussions.
Some shadow applications might contain data you actually need. Before requesting deletion, export any business-relevant information to your official systems. Most applications provide data export features, though you may need to contact support for complete exports. Transfer this data to approved storage, then proceed with deletion requests.
Contact each vendor with a formal data deletion request. Reference applicable privacy regulations (GDPR, CCPA, or others relevant to your location and industry). Request written confirmation when deletion is complete. Vendors typically have about a month to respond to these requests, though many act faster.
For applications where employees used personal accounts, you will need their cooperation. Provide step-by-step instructions for deleting company data from their personal accounts, and verify completion.
Trust but verify. After receiving deletion confirmations, attempt to access the accounts again. Some vendors claim deletion but retain data in backup systems or archives. If you can still access data after a deletion request, escalate with the vendor’s privacy or legal team.
Shadow IT remediation is not a one-time project. New unauthorized applications will appear unless you build systems to prevent them. Research from academic studies on security training shows that ongoing education significantly reduces risky employee behavior.
Publish a list of approved applications for common business needs. Include tools for file storage, project management, communication, design, and other categories where shadow IT commonly appears. Make this list easy to find and keep it updated. When employees know approved alternatives exist, they are less likely to search for their own solutions.
Give employees a simple way to request new software. A complicated approval process encourages people to skip it. A quick form that gets reviewed in a timely manner encourages compliance. When you approve requests, add the new tool to your approved list. When you deny requests, explain why and suggest alternatives.
Schedule quarterly reviews of OAuth connections, browser extensions, and expense reports. Shadow IT grows slowly, and regular audits catch problems before they become serious. Consider automated security tools that can detect new unauthorized applications as they appear.
Employees need to understand why shadow IT matters. Include shadow IT risks in your security awareness training alongside phishing prevention. The UK’s National Cyber Security Centre recommends combining technical controls with employee education for the strongest protection. Help employees recognize that unauthorized apps can serve as entry points for phishing attacks and data breaches, connecting these risks to real consequences for the business.
Shadow IT exists because official tools fail to meet employee needs. If your team keeps adopting unauthorized project management software, your approved project management tool probably has problems. Survey employees about gaps in your official software stack and address legitimate complaints. The goal is making approved tools the easiest option, not just the required one.
Learning from real breach incidents can help your team understand why these precautions matter. When employees see the actual consequences of security failures, they become more willing participants in prevention efforts.
Follow this checklist to manage your shadow IT remediation:
Shadow IT remediation takes time, but the process is straightforward. Work through each phase systematically, prioritize by risk, and build prevention into your regular operations. The goal is not perfection but progress. Each unauthorized application you identify and address reduces your exposure to data breaches, phishing attacks, and compliance problems.
Launch a realistic phishing simulation in minutes and get the tools you need to build a cyber-aware team.
This blog offers general information about phishing and cybersecurity for small and medium-sized organisations. It is not legal, financial, or technical advice. Speak to a qualified professional before acting on any guidance you read here.