Month: September 2026

What is Shadow IT, and what does it mean for cyber security within UK SMEs?

We all know that the threats to our businesses through cyber-attacks and scams changes and expands almost daily, and it is really difficult to stay abreast of when there is so much else going on in our businesses that needs our attention.  One of the fastest-growing cyber risks for SMEs is what has become known as Shadow IT, because it introduces technology that the business doesn’t know about, can’t monitor, and can’t secure.  It is more of a risk for SMEs than it is for corporates, who generally have strong policies to protect themselves, and are prepared to spend money on resources to enforce those policies.  Luxury that SMEs can’t afford.  Shadow IT can be particularly dangerous because employees often adopt apps and AI tools to work faster, without involving IT or their MSP.  It’s not that they are deliberately introducing problems into the environment but often they see the use of tools that they have been using for a long time privately, as increasing their efficiency and making their jobs easier.

What is Shadow IT?

Shadow IT is any software, cloud service, device, or AI tool used for work without the approval or oversight of the business or its IT provider.  Examples include:

  • Employees storing company files in personal Google Drive or Dropbox accounts.
  • Using ChatGPT or other AI tools with confidential customer information.
  • Free file-sharing services such as WeTransfer.
  • Personal laptops, tablets, or phones accessing company email.
  • Unsanctioned project management tools like Trello, Notion, or Monday.com.

This list is far from exhaustive.

Why SMEs are especially vulnerable

Unlike large enterprises, SMEs often have:

  • Limited IT staff.
  • Smaller security budgets.
  • Employees wearing multiple hats and choosing their own tools.
  • Less visibility into what applications is being used.

All of which makes Shadow IT easy to introduce and difficult to detect.  The biggest risks:

  1. Data leakage caused potentially by employees uploading:
  • Client financial information.
  • Legal documents.
  • HR records.
  • Intellectual property.

…into services that the company does not control.

For regulated sectors like legal and financial services, this can create significant issues.

2. Increased phishing and ransomware exposure via free and consumer apps which:

  • Don’t enforce MFA.
  • Have weak passwords.
  • Lack business-grade monitoring.

If compromised, attackers gain another doorway into cloud or company systems.  It’s also worth noting that it introduces Cyber Essentials failure points.

3. AI creates “Shadow AI” and is becoming one of its newest forms. Some examples are:

  • Staff pasting customer contracts into AI chatbots.
  • Uploading spreadsheets containing personal data.
  • Using AI browser extensions that access company emails.

Sensitive information can leave the organisation without anyone realising.

4. Compliance failures such as Cyber Essentials which requires organisations to control software, accounts, devices, and access.  Shadow IT can mean:

  • Unpatched software.
  • Unknown devices.
  • Unmanaged cloud accounts.
  • Data stored outside approved locations.

The above can jeopardise Cyber Essentials and other certifications and cyber insurance conditions.  Let’s look at a simple attack scenario:

  • Step 1 – Employee uses a personal Dropbox account to share files with a customer.
  • Step 2 – The Dropbox password is reused from another breached website.
  • Step 3 – Attackers access the Dropbox account and discover invoices, contracts, and email addresses.
  • Step 4 – They use this information to launch convincing phishing emails against customers and finance staff.

The result of this is invoice fraud or ransomware infection.  This type of attack is increasingly common because attackers exploit unmanaged services rather than well protected corporate systems.

Warning signs that Shadow IT exists

  • Employees using WhatsApp or other messaging apps for customer conversations.
  • Personal email accounts used for work documents.
  • Unknown browser extensions installed.
  • Multiple file-sharing platforms in use.
  • AI tools appearing in browser history or network logs.
  • Staff connecting personal USB devices or laptops.

How can SMEs reduce the risk and protect themselves.

ControlBenefit
Application DiscoveryIdentify every cloud app employees use
Approved software policyProvide sanctioned alternatives so staff don’t seek their own tools
Multi-factor authenticationProtect business accounts even if passwords are stolen
Protective monitoring/Managed Detection and ResponseDetect unusual logins, new applications and risky behaviour
AI usage policyDefine what information can and cannot be entered into AI tools
Employee awareness trainingExplain why convenience care create business risk

Why this matters for Cyber Essentials

Shadow IT maps directly to several Cyber Essentials control themes:

  • Asset management: You must know what software and services are in use.
  • Access control: Only authorised users should access company resources.
  • Secure configuration: Unapproved apps may not meet security standards.
  • Protective monitoring: Continuous visibility helps identify Shadow IT before it becomes a breach.

Shadow IT isn’t just employees installing software, it’s invisible cyber risk. Every unapproved app, AI tool, or cloud service creates a potential doorway into your business. If you can’t see it, you can’t secure it.  This is a particularly strong message for a UK SME audience because it ties directly into Cyber Essentials, GDPR, and the need for continuous cyber risk monitoring.

I hope this has been useful information but it’s just the tip of the iceberg.  If you want to know more then please use the contact information below, or DM me on my LinkedIn account.

Scroll to top