Shadow IT is not an act of rebellion — it is what happens when the approved tool is slower than the free one. A staff member who cannot get the file to a client by Friday will find a way that works, and nobody notices until the client list is sitting in a free account nobody controls. This guide gives Australian managers a four-step approach that ends the tug of war between the policy document and the way work actually gets done.
Key takeaways
- Banning tools outright pushes usage underground; a sanctioned path is the control that works.
- Find what staff actually use before writing rules — the answer is always a longer list than expected.
- Classify apps by the data they hold, not by how official they look.
- Publish a 48-hour review promise so staff have a reason to ask instead of a reason to hide.
- Fold the review cycle into your wider security awareness training so new tools surface before they become permanent.
Who this is for
This is for owners and office managers at Australian organisations between roughly 5 and 200 staff, and for MSPs advising them. You have no dedicated IT department, or a small one that is busy, and you suspect that more tools are in use than appear on any software invoice.
Why this matters
Unsanctioned tools carry the company's data on someone else's terms: no admin control, no offboarding path, no breach notification obligation to you, and often a free tier whose terms of service permit exactly the data handling your privacy policy forbids. The Australian Signals Directorate's guidance on securing email and accounts starts from a simple premise — you cannot protect accounts you do not know exist. That applies to software the same way it applies to logins.
The legal side is not hypothetical either. Under the Privacy Act, a business holding personal information is accountable for how third-party services handle it, and the OAIC's notifiable data breach scheme does not care whether the leak came from your approved CRM or a staff member's free note-taking app.
Step 1: Find out what is actually in use
Do not open with an amnesty announcement — start by counting.
- Pull the apps list from your email platform and identity provider: OAuth grants and connected apps tell you which services staff have already authenticated with company accounts.
- Ask each team lead one question: what tools did your team sign up for themselves?
- Check browser extension policies and expense claims — subscriptions paid on a personal card are the classic invisible line item.
Most teams find between 20 and 60 tools when the approved list holds about a dozen. That number is normal, not a scandal.
Step 2: Classify by data exposure
Sort what you found into three buckets:
- Holds customer or personal data. CRMs, HR systems, invoicing, anything with names and payment details. These need proper vetting: who owns the account, where the data lives, what happens when the staff member leaves.
- Holds internal work product. Project trackers, shared docs, design tools. Lower stakes, but still need an owner and an offboarding path.
- Personal convenience only. Note apps, to-do lists with nothing company-specific in them. Leave these alone.
The classification, not the tool's brand, decides how much scrutiny each one gets.
Step 3: Sanction, replace or sunset — never just ban
- Sanction the tools that work and pass vetting. Add them to the approved list with a named owner. This is the step that fixes shadow IT: staff adopt the official path when the official path is genuinely faster.
- Replace the tools that carry real data but fail vetting, with a migration plan and a deadline. Move the data, close the accounts, confirm the closure.
- Sunset quietly for low-risk duplicates — pick the winner per job, tell the team once, and stop paying for the rest at renewal.
A blanket ban on everything not on the list fails in practice: it teaches staff that asking first gets them a no and a slower week, so next time they do not ask.
Step 4: Make asking faster than hiding
The whole programme rests on one transaction: a staff member wants a tool, they ask, and they get an answer quickly.
- Publish a simple route — a form, an email alias or a standing agenda item — and commit to a 48-hour decision.
- Say yes often enough to be credible. A review process that approves nothing is a process staff route around.
- When the answer is no, give the reason and the alternative. "No, but the sanctioned tool does that with this template" keeps the relationship intact.
Step 5: Keep it alive
Re-run the discovery pass every six months and after every restructure or major hiring wave — new teams generate new tools. Tie the review into your existing training rhythm: a five-minute segment on "who owns which tool" during quarterly security awareness training refreshes the approved list in people's heads without another memo.
Track three numbers: the count of unsanctioned tools holding company data, the median time from request to decision, and the number of tools without a named owner. When the first falls and the second stays under 48 hours, the programme is working.
What to avoid
- The network-blocking arms race. Firewalls miss browser-based tools, and every block drives the next workaround deeper underground.
- Naming and shaming. The point of discovery is a complete picture; the fastest way to lose that picture is to punish the first honest answer.
- Vetting only new tools. The riskiest ones are usually the oldest free accounts nobody has touched since 2024.
- Writing a policy nobody read. A one-page approved-tools list with owners beats a ten-page acceptable-use policy every time.
FAQ
What is shadow IT? Software, cloud services and devices staff use for work without IT or management approval — from free file-sharing accounts to unvetted AI chat tools handling client documents.
Is shadow IT actually a security risk for small businesses? Yes. Unsanctioned tools hold company data outside your control, with no admin oversight, no offboarding process and no breach-notification path to you.
How do we find shadow IT without spying on staff? Use admin-side sources: OAuth grants in your identity provider, connected apps in Microsoft 365 or Google Workspace, expense claims and a direct question to team leads. No screen surveillance required.
Should we ban AI chatbots at work? Banning them outright usually fails. Sanction one approved tool, publish what must never be pasted into any chatbot — client data, financials, personal information — and train on the boundary. Cyber Aware's AI chatbot guidance pairs well with this approach.
How long does a shadow IT clean-up take? About four weeks for a 50-person team: one to discover, one to classify, one to migrate the high-risk tools, one to publish the approved list and reporting route.
What if a staff member refuses to give up a tool? Find out what job it does. If the sanctioned alternative cannot do that job, the fault sits with the alternative, not the staff member — fix the tool list before enforcing it.
Do we need a formal policy document? A one-page approved-tools list with named owners and a 48-hour review promise does more than a long policy nobody reads. Keep the formal policy as the backing document for auditors and insurers.
One last thing
The fastest shadow IT diagnostic costs nothing: search your staff's expense claims for software subscriptions paid on personal cards in the last six months. Every hit is a tool with real usage and no official ownership — and a conversation waiting to happen.