Generate summary with AI

Many IT teams find out about the spread of shadow IT the same way. A renewal charge turns up on a corporate card for a tool nobody in IT has heard of. Or an employee leaves, and it turns out their client files live in a personal Dropbox. Each case looks small on its own, but taken together, they make up a second IT environment running alongside the one you manage, with its own spend, its own data, and its own risk, and none of it is on your books.

That second environment gets expensive when something goes wrong. IBM’s 2025 Cost of a Data Breach Report found that one in five organizations had experienced a breach linked to a shadow-AI security incident, with an average breach cost of $4.74 million. But breach exposure is only one line item. Duplicate subscriptions, forgotten licenses, and the hours your team spends untangling tools it never approved all add up long before an incident does. Controlling that cost starts with knowing what it actually is.

Why shadow IT has become too big to ignore

Shadow IT used to mean a rogue install on a workstation that the next audit would catch. That version still exists, but it’s now the smallest part of the problem. The actual problem is that most tools can be adopted in minutes with a work email address and a company card, and many buying decisions have moved out of IT altogether.

In practical terms, shadow IT is any device, application, or service used for work without IT’s knowledge or approval. What has changed is how much that definition now covers. Alongside unauthorized installs, it includes:

  • Shadow SaaS: Project and collaboration tools like Trello, Notion, or Asana that a team sets up without IT review, or a free Calendly or Canva account tied to a work address.
  • Personal cloud storage and messaging: Work files saved to a personal Dropbox, Google Drive, or OneDrive account, and client conversations running through WhatsApp or Telegram.
  • Connected apps and automations: Browser extensions and integration tools like Zapier that are granted access to company email, calendars, or files through OAuth.
  • Shadow AI: ChatGPT, Gemini, and AI meeting note-takers used with company data before anyone has checked how the provider stores or reuses it.

“The common thread isn’t whether the tool is useful or malicious; it’s that IT hasn’t assessed, secured, licensed, or added it to the company’s inventory.”

Eugene Keyser, Senior IT Support Engineer

The scale reflects where buying decisions now sit. Capgemini Research Institute’s 2025 survey of 1,000 executives at organizations with at least $1 billion in revenue found that business units (not IT) initiate 48% of SaaS spending and 59% of generative AI spending.

Those are companies with formal procurement processes. In a smaller business with lighter controls, a company card and a work email address are often all it takes.

Why it keeps spreading

Shadow IT grows fastest in departments that need specialized tools and can buy them directly. Marketing adds campaign and design platforms, sales picks up prospecting and scheduling tools, and developers test cloud services and open-source packages outside formal review.

In most cases, the employee isn’t trying to get around security. They’re trying to finish a task, and the approved tool is too slow, too hard to use, or missing a feature they need. That makes shadow IT a useful signal as well as a risk. Every unapproved tool points to a gap in what IT provides or in how quickly IT responds to requests.

What it puts at risk

Shadow IT doesn’t cause a breach or compliance violation on its own. What it does is remove the visibility IT needs to prevent one, which makes incidents more likely, harder to investigate, and harder to explain to an auditor. The risks show up in a few consistent places:

  • Unknown data exposure: Nobody can say what company data sits in an unapproved tool, who can access it, or whether MFA, encryption, and updates are in place.
  • Leaky accounts and integrations: Personal accounts and loosely reviewed integrations can expose customer records.
  • Orphaned access: Access often outlives the employee who set it up, surviving role changes and departures.
  • Compliance gaps: If regulated data sits in an untracked tool, the business may be unable to show where it’s stored, how long it’s kept, who viewed it, or whether it was properly deleted.
  • Data leaking into AI tools: Employees paste confidential text, source code, or customer details into AI tools whose data handling nobody has reviewed.
  • Unreliable AI output: AI outputs can contain convincing errors or unsafe code that gets treated as reliable.
  • Overprivileged AI agents: Connected AI agents can read company data or act inside company systems with whatever access they were granted.

What the hidden Shadow IT costs are and how to calculate them

Most businesses never put a figure on shadow IT because the costs never arrive on one invoice. Some are cash going out the door, some are technician hours that never get logged against a tool, and some are risk that stays invisible until an incident puts a number on it.

Pricing it properly means separating those layers, then working out which tools carry the most weight.

The direct costs are the ones that show up in spending records, if anyone thinks to look. They include:

  • Duplicate and overlapping subscriptions: A team buys a tool that does the same job as one the company already licenses, such as a paid file-sharing plan on top of Microsoft 365 or Google Workspace storage.
  • Unused licenses and silent renewals: Seats keep renewing after employees stop using a tool, change roles, or leave, because nobody in IT knows the subscription exists.

The indirect costs are harder to see but often larger. They include:

  • Breach exposure: An unapproved tool can process company data without MFA, logging, or access reviews, and if it contributes to a breach, the business pays for investigation, recovery, and downtime.
  • Compliance and governance gaps: When regulated data sits in a system IT can’t monitor, proving where it’s stored, who accessed it, and whether it was deleted becomes expensive or impossible during an audit.
  • Technician time: Access requests, sharing problems, offboarding, and eventual cleanup all land on IT, usually without being recorded against the tool that caused them.

» Here’s our guide to preparing for a software license audit

Which tools cost the most

A tool’s price is a poor guide to its cost. A free app with access to customer data can do far more damage than an expensive one that stands alone. The categories that tend to carry the most hidden cost are:

  • Storage, file sharing, and messaging: Personal Dropbox, Google Drive, or WeTransfer accounts and WhatsApp groups put company records outside normal access and deletion controls. Something could go wrong on the scale of regulatory failures and penalties from data breaches and you’d never know it was happening until it was too late.
  • Business tools holding sensitive data: A sales team’s own CRM or a department’s Airtable base full of customer or employee records often duplicates software the company already pays for, while holding data IT can’t protect.
  • Automation and developer tools: Zapier or Make workflows connected to company accounts, personal GitHub repositories, and pay-as-you-go cloud accounts on a personal card can expose credentials and run up charges quietly.

This isn’t a fringe problem. In the Cloud Security Alliance’s 2025 State of SaaS Security survey of 420 IT and security professionals, 56% said employees upload sensitive data to unauthorized SaaS apps.

When ranking what to deal with first, weigh each tool by the data it holds, the access it has, its cost, how many people use it, and how much daily work depends on it. The worst combinations come first.

How to calculate the cost of a shadow tool

Once a tool has been discovered, the calculation is straightforward if direct spending, staff time, and risk stay in separate columns. Follow these steps:

  1. Pull 12 months of invoices, corporate-card charges, expense claims, and contracts for the tool
  2. Compare the seats being paid for against the seats actually in use. Unused seats are part of the subscription cost, not an extra cost on top of it
  3. Check whether an approved tool already covers the same function. If it does, mark the subscription spend as avoidable
  4. Estimate the hours IT spends supporting, securing, offboarding, and eventually removing the tool
  5. Multiply those hours by your internal hourly cost for technician time
  6. Add any one-off cash costs (such as cancellation fees, migration work, or legal review) to direct spending
  7. Have finance verify the figures, counting any subscription shared between departments only once
  8. Report direct spending and staff time as separate totals, and keep potential breach or compliance losses apart as an estimated risk rather than adding them to the bill

Here’s an example of how that might work. A 12-person marketing team at a company already on Microsoft 365 signs up for Dropbox Standard at $15 per user per month, billed annually. Four of those seats belong to people who have since left or moved teams. IT spends about two hours a month on access and sharing issues, plus eight hours migrating files to OneDrive and closing the account once the tool is found. For technician time, the example uses the US Bureau of Labor Statistics median wage for computer support specialists at $30.24 an hour.

Cost line

Calculation

Annual cost

Subscription spend

12 seats × $15 × 12 months

$2,160

Of which unused seats

4 seats × $15 × 12 months

$720 (already included above)

Avoidable spend

OneDrive already covers the need

$2,160

Technician time

32 hours × $30.24

$968

Total annual cost

Direct spend + technician time

$3,128

At the business level, that adds up quickly. A business running eight unmanaged tools with a similar profile would be spending about $17,280 a year on subscriptions it doesn’t need, plus roughly $7,741 in technician time, for a total of about $25,000.

Note: This calculation excludes benefits and overhead, so the real cost would be even higher.

The scary part is that this example just covers the costs you can see for a relatively cheap subscription. If it’s something like an Ahrefs enterprise subscription bought on an SEO manager’s card, you’re looking at thousands of dollars for a single tool. At a yearly subscription discovered halfway through, you’re still liable for the rest of the year. Any breach or compliance exposure these tools create sits on top of it, and a single incident can outweigh years of subscription waste.

That means a midsize company with poor governance that has a bad shadow IT problem could potentially waste over $100,000 in a year.

» Trying to cut costs? Don’t miss our guide to building an IT cost optimization framework

Visibility comes before cost control

Shadow IT stops being a hidden cost once you can name each tool, price it, and give it an owner. The subscription waste is real, but the larger exposure sits in the tools nobody knows about. Every unmanaged device or account is somewhere company data can live without IT’s controls. Closing that gap starts with the network, because you can’t manage what you haven’t found.

Atera’s Network Discovery runs scheduled scans on a daily, weekly, or monthly basis to identify devices on your network, from workstations and servers to printers and SNMP-enabled equipment. It flags unauthorized devices, checks discovered devices for known CVE vulnerabilities, integrates with Active Directory, and uses built-in alerts to notify your team when something unexpected appears.

Once a device checks out, bringing it into Atera’s RMM platform lets you use asset and inventory scanning to show you what’s installed so the device gets the same monitoring and patching as the rest of the fleet. Pair that with identity, web, and expense reviews for shadow SaaS and AI, and your team stops finding shadow IT by accident and starts managing it on its own schedule.

» Interested? Try Atera for free

Frequently Asked Questions

Was this helpful?

Related Articles

How organizations should approach IT cost management

Read now

How device performance monitoring improves digital employee experience

Read now

How to build an IT governance framework that actually works

Read now

Is IT vendor consolidation really worth it?

Read now

Endless IT possibilities

Boost your productivity with Atera’s intuitive, centralized all-in-one platform