Shadow IT
Tools and services employees use without IT approval. Every invisible account is risk that nobody is watching.
Full definition
Shadow IT is the set of applications, services and devices employees use for work without the approval or knowledge of the technology team: the personal storage account for sharing heavy files, the free tool that solved a team's problem, the SaaS bought with a department card.
It is almost always born in good faith, people trying to work better, but it creates invisible risk: accounts without multi-factor authentication, corporate data in services without contracts, credentials nobody revokes when the employee leaves, and access no security tool is monitoring.
The mature response is not just prohibition, because prohibition pushes usage further into the shadows. What works better is discovering what is used, offering approved alternatives that solve the same need, and educating on the real risk of each shortcut.
Related terms
Shadow AI
Use of AI tools without company approval: sensitive data pasted into chatbots and decisions based on outputs nobody validates.
Data leak
Exposure of sensitive information with no attack involved: a misconfigured database, an overshared file, an email to the wrong recipient.
Attack surface
The set of points where an attacker can try to get in: exposed systems, accounts, vendors and, above all, people.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.