Table of contents
Generate summary with AI

Many IT teams find out about the spread of shadow IT the same way. A renewal charge turns up on a corporate card for a tool nobody in IT has heard of. Or an employee leaves, and it turns out their client files live in a personal Dropbox. Each case looks small on its own, but taken together, they make up a second IT environment running alongside the one you manage, with its own spend, its own data, and its own risk, and none of it is on your books.
That second environment gets expensive when something goes wrong. IBM’s 2025 Cost of a Data Breach Report found that one in five organizations had experienced a breach linked to a shadow-AI security incident, with an average breach cost of $4.74 million. But breach exposure is only one line item. Duplicate subscriptions, forgotten licenses, and the hours your team spends untangling tools it never approved all add up long before an incident does. Controlling that cost starts with knowing what it actually is.
Why shadow IT has become too big to ignore
Shadow IT used to mean a rogue install on a workstation that the next audit would catch. That version still exists, but it’s now the smallest part of the problem. The actual problem is that most tools can be adopted in minutes with a work email address and a company card, and many buying decisions have moved out of IT altogether.
In practical terms, shadow IT is any device, application, or service used for work without IT’s knowledge or approval. What has changed is how much that definition now covers. Alongside unauthorized installs, it includes:
- Shadow SaaS: Project and collaboration tools like Trello, Notion, or Asana that a team sets up without IT review, or a free Calendly or Canva account tied to a work address.
- Personal cloud storage and messaging: Work files saved to a personal Dropbox, Google Drive, or OneDrive account, and client conversations running through WhatsApp or Telegram.
- Connected apps and automations: Browser extensions and integration tools like Zapier that are granted access to company email, calendars, or files through OAuth.
- Shadow AI: ChatGPT, Gemini, and AI meeting note-takers used with company data before anyone has checked how the provider stores or reuses it.
“The common thread isn’t whether the tool is useful or malicious; it’s that IT hasn’t assessed, secured, licensed, or added it to the company’s inventory.”
Eugene Keyser, Senior IT Support Engineer
The scale reflects where buying decisions now sit. Capgemini Research Institute’s 2025 survey of 1,000 executives at organizations with at least $1 billion in revenue found that business units (not IT) initiate 48% of SaaS spending and 59% of generative AI spending.
Those are companies with formal procurement processes. In a smaller business with lighter controls, a company card and a work email address are often all it takes.
Why it keeps spreading
Shadow IT grows fastest in departments that need specialized tools and can buy them directly. Marketing adds campaign and design platforms, sales picks up prospecting and scheduling tools, and developers test cloud services and open-source packages outside formal review.
In most cases, the employee isn’t trying to get around security. They’re trying to finish a task, and the approved tool is too slow, too hard to use, or missing a feature they need. That makes shadow IT a useful signal as well as a risk. Every unapproved tool points to a gap in what IT provides or in how quickly IT responds to requests.
What it puts at risk
Shadow IT doesn’t cause a breach or compliance violation on its own. What it does is remove the visibility IT needs to prevent one, which makes incidents more likely, harder to investigate, and harder to explain to an auditor. The risks show up in a few consistent places:
- Unknown data exposure: Nobody can say what company data sits in an unapproved tool, who can access it, or whether MFA, encryption, and updates are in place.
- Leaky accounts and integrations: Personal accounts and loosely reviewed integrations can expose customer records.
- Orphaned access: Access often outlives the employee who set it up, surviving role changes and departures.
- Compliance gaps: If regulated data sits in an untracked tool, the business may be unable to show where it’s stored, how long it’s kept, who viewed it, or whether it was properly deleted.
- Data leaking into AI tools: Employees paste confidential text, source code, or customer details into AI tools whose data handling nobody has reviewed.
- Unreliable AI output: AI outputs can contain convincing errors or unsafe code that gets treated as reliable.
- Overprivileged AI agents: Connected AI agents can read company data or act inside company systems with whatever access they were granted.
What the hidden Shadow IT costs are and how to calculate them
Most businesses never put a figure on shadow IT because the costs never arrive on one invoice. Some are cash going out the door, some are technician hours that never get logged against a tool, and some are risk that stays invisible until an incident puts a number on it.
Pricing it properly means separating those layers, then working out which tools carry the most weight.
The direct costs are the ones that show up in spending records, if anyone thinks to look. They include:
- Duplicate and overlapping subscriptions: A team buys a tool that does the same job as one the company already licenses, such as a paid file-sharing plan on top of Microsoft 365 or Google Workspace storage.
- Unused licenses and silent renewals: Seats keep renewing after employees stop using a tool, change roles, or leave, because nobody in IT knows the subscription exists.
The indirect costs are harder to see but often larger. They include:
- Breach exposure: An unapproved tool can process company data without MFA, logging, or access reviews, and if it contributes to a breach, the business pays for investigation, recovery, and downtime.
- Compliance and governance gaps: When regulated data sits in a system IT can’t monitor, proving where it’s stored, who accessed it, and whether it was deleted becomes expensive or impossible during an audit.
- Technician time: Access requests, sharing problems, offboarding, and eventual cleanup all land on IT, usually without being recorded against the tool that caused them.
» Here’s our guide to preparing for a software license audit
Which tools cost the most
A tool’s price is a poor guide to its cost. A free app with access to customer data can do far more damage than an expensive one that stands alone. The categories that tend to carry the most hidden cost are:
- Storage, file sharing, and messaging: Personal Dropbox, Google Drive, or WeTransfer accounts and WhatsApp groups put company records outside normal access and deletion controls. Something could go wrong on the scale of regulatory failures and penalties from data breaches and you’d never know it was happening until it was too late.
- Business tools holding sensitive data: A sales team’s own CRM or a department’s Airtable base full of customer or employee records often duplicates software the company already pays for, while holding data IT can’t protect.
- Automation and developer tools: Zapier or Make workflows connected to company accounts, personal GitHub repositories, and pay-as-you-go cloud accounts on a personal card can expose credentials and run up charges quietly.
This isn’t a fringe problem. In the Cloud Security Alliance’s 2025 State of SaaS Security survey of 420 IT and security professionals, 56% said employees upload sensitive data to unauthorized SaaS apps.
When ranking what to deal with first, weigh each tool by the data it holds, the access it has, its cost, how many people use it, and how much daily work depends on it. The worst combinations come first.
How to calculate the cost of a shadow tool
Once a tool has been discovered, the calculation is straightforward if direct spending, staff time, and risk stay in separate columns. Follow these steps:
- Pull 12 months of invoices, corporate-card charges, expense claims, and contracts for the tool
- Compare the seats being paid for against the seats actually in use. Unused seats are part of the subscription cost, not an extra cost on top of it
- Check whether an approved tool already covers the same function. If it does, mark the subscription spend as avoidable
- Estimate the hours IT spends supporting, securing, offboarding, and eventually removing the tool
- Multiply those hours by your internal hourly cost for technician time
- Add any one-off cash costs (such as cancellation fees, migration work, or legal review) to direct spending
- Have finance verify the figures, counting any subscription shared between departments only once
- Report direct spending and staff time as separate totals, and keep potential breach or compliance losses apart as an estimated risk rather than adding them to the bill
Here’s an example of how that might work. A 12-person marketing team at a company already on Microsoft 365 signs up for Dropbox Standard at $15 per user per month, billed annually. Four of those seats belong to people who have since left or moved teams. IT spends about two hours a month on access and sharing issues, plus eight hours migrating files to OneDrive and closing the account once the tool is found. For technician time, the example uses the US Bureau of Labor Statistics median wage for computer support specialists at $30.24 an hour.
Cost line | Calculation | Annual cost |
|---|---|---|
Subscription spend | 12 seats × $15 × 12 months | $2,160 |
Of which unused seats | 4 seats × $15 × 12 months | $720 (already included above) |
Avoidable spend | OneDrive already covers the need | $2,160 |
Technician time | 32 hours × $30.24 | $968 |
Total annual cost | Direct spend + technician time | $3,128 |
At the business level, that adds up quickly. A business running eight unmanaged tools with a similar profile would be spending about $17,280 a year on subscriptions it doesn’t need, plus roughly $7,741 in technician time, for a total of about $25,000.
Note: This calculation excludes benefits and overhead, so the real cost would be even higher.
The scary part is that this example just covers the costs you can see for a relatively cheap subscription. If it’s something like an Ahrefs enterprise subscription bought on an SEO manager’s card, you’re looking at thousands of dollars for a single tool. At a yearly subscription discovered halfway through, you’re still liable for the rest of the year. Any breach or compliance exposure these tools create sits on top of it, and a single incident can outweigh years of subscription waste.
That means a midsize company with poor governance that has a bad shadow IT problem could potentially waste over $100,000 in a year.
» Trying to cut costs? Don’t miss our guide to building an IT cost optimization framework
Visibility comes before cost control
Shadow IT stops being a hidden cost once you can name each tool, price it, and give it an owner. The subscription waste is real, but the larger exposure sits in the tools nobody knows about. Every unmanaged device or account is somewhere company data can live without IT’s controls. Closing that gap starts with the network, because you can’t manage what you haven’t found.
Atera’s Network Discovery runs scheduled scans on a daily, weekly, or monthly basis to identify devices on your network, from workstations and servers to printers and SNMP-enabled equipment. It flags unauthorized devices, checks discovered devices for known CVE vulnerabilities, integrates with Active Directory, and uses built-in alerts to notify your team when something unexpected appears.
Once a device checks out, bringing it into Atera’s RMM platform lets you use asset and inventory scanning to show you what’s installed so the device gets the same monitoring and patching as the rest of the fleet. Pair that with identity, web, and expense reviews for shadow SaaS and AI, and your team stops finding shadow IT by accident and starts managing it on its own schedule.
» Interested? Try Atera for free
Frequently Asked Questions
Related Articles
How organizations should approach IT cost management
IT budgets are growing, but so is the pressure on every dollar inside them. The real risk isn't just overspending, but spending decided by default with renewals that roll over unchecked, purchases nobody owns, and cuts that quietly turn into technical debt.
Read nowHow device performance monitoring improves digital employee experience
Your fleet can be fully patched and green on every dashboard while employees lose minutes to slow logons, frozen apps, and throttled laptops. Without device performance monitoring, that friction reaches IT one ticket at a time. With it, degradation shows up as data first, so IT can fix it across the fleet before anyone has to ask.
Read nowHow to build an IT governance framework that actually works
IT governance frameworks exist everywhere, but they don't often get followed. When approvals drag, scope creeps into routine work, and checkpoints live outside the tools teams use every day, people find the shortcut. Governance that holds keeps oversight on real risk, gives every decision an owner and a threshold, and enforces itself inside the workflows where the work already happens.
Read nowIs IT vendor consolidation really worth it?
Every added tool promised to make things easier, and now IT teams are drowning in licenses, integrations, and vendors nobody remembers signing up for. Cutting the number down feels like relief, but a smaller stack that still can't do the job is just a different kind of expensive. What actually disappears matters more than how many logos leave the list.
Read nowEndless IT possibilities
Boost your productivity with Atera’s intuitive, centralized all-in-one platform










