Shadow IT: the security risk hiding in plain sight at UK small businesses
Shadow IT — tools and services used by staff without IT approval — is one of the most common sources of unexpected attack surface exposure at UK small businesses.
Here's a scenario that plays out often enough to be a pattern, not a one-off: a member of staff signs up for a project management tool using their work email address. They connect it to the company's Google Workspace to pull in calendar data. They invite three colleagues. Six months later, that person leaves, nobody thinks to decommission the account, and the tool retains an active OAuth connection to the company's Google Workspace under credentials that no longer belong to an employee. Nobody in the business knows the connection exists.
Shadow IT is any technology used by staff in the course of their work that hasn't been approved, provisioned, or monitored by whoever is responsible for the company's IT. It's one of the most common sources of unexpected attack surface exposure at small businesses, and it's almost entirely invisible until something goes wrong.
Why shadow IT is everywhere in small businesses
Shadow IT exists because the friction between "I need this tool to do my job" and "I have formal approval to use this tool" is often too high, particularly in small businesses where there's no dedicated IT function to go through. Staff solve immediate problems with whatever's available — a free SaaS tool, a personal cloud storage account, a browser extension that makes something easier — without anyone making a deliberate security decision about whether that's appropriate.
This isn't recklessness. It's a rational response to the gap between what people need to do their jobs and the tooling their organisation has formally provisioned. The problem is the security implications that accumulate invisibly.
How shadow IT creates attack surface exposure
Shadow IT creates attack surface risk in several specific ways.
Unauthorised OAuth connections — when a tool connects to a core system like Google Workspace or Microsoft 365 via OAuth, it gains access to data within those systems. If the tool is breached, that access becomes an attacker's access. If the staff member who connected it leaves, the connection often persists.
Data in unmanaged tools — customer data, client information, or sensitive documents uploaded to an unauthorised file sharing service or collaboration tool sits outside any data governance or security policy the business has in place. If that service is breached, the business's data is in the breach.
Credentials reused across personal and business contexts — staff using personal email addresses to sign up for work tools, or reusing passwords across personal and business accounts, creates credential exposure that extends beyond what the business can monitor or control.
Subdomains and services created without central oversight — a developer spinning up a subdomain for a side project using company infrastructure, or connecting a new service to the company domain without telling anyone, adds to the external attack surface without anyone performing a security assessment.
How to find shadow IT you don't know about
The honest answer is that you can't audit shadow IT entirely through technical means — some of it exists purely in staff behaviour. But you can find the technical traces it leaves.
An external attack surface scan surfaces subdomains, connected services, and DNS records that weren't in any official inventory. OAuth audit logs in Google Workspace and Microsoft 365 show which third-party applications have been granted access and under which accounts. A review of credit card statements often surfaces SaaS subscriptions nobody formally approved.
Olimpio's tech exposure feature maps the technology stack visible on your domain and associated assets, surfacing third-party connections and services that are part of your external footprint whether or not they were formally provisioned.
What to do about it
Eliminate shadow IT that creates genuine risk — OAuth connections to tools that are no longer in use, data in unauthorised locations, services with access to company systems that weren't formally evaluated.
For shadow IT that's meeting a genuine business need, the answer is formalisation — bringing it into the official provisioned environment, applying the same access controls and offboarding processes as any other tool.
And prevent new shadow IT from accumulating by making the path to approved tools low-friction enough that staff don't feel the need to go around it. The goal isn't to stop people using useful tools; it's to ensure there's a record of what's connected and a process for managing it properly when things change.
Frequently asked questions
How common is shadow IT in small businesses? Extremely common. Most small businesses without a dedicated IT function have staff using tools that were never formally evaluated or approved. The question is usually not whether shadow IT exists but how much and what risk it carries.
Is using a personal tool for work purposes a GDPR problem? Potentially yes, if personal data is processed through a tool that isn't covered by your data processing agreements and privacy policy. This is one of the more practical GDPR risks for small businesses.
Can we realistically stop staff from using shadow IT? Not entirely, but the goal isn't zero shadow IT — it's visibility and management. Knowing what's connected, having a process for evaluating tools before connecting them to core systems, and auditing regularly is more achievable and more effective than trying to prevent it entirely.
What's the highest-risk form of shadow IT for a small business? OAuth connections to core systems like email and cloud storage, because they create direct access to data and persist beyond the staff member who created them. These are worth auditing immediately.
Where should we start if we suspect we have significant shadow IT exposure? Start with OAuth audit logs in your core platforms to see what third-party applications have access. Then run an external scan to see what's visible on your attack surface that wasn't in any official inventory.
Run a free scan to see what's visible on your external attack surface including technology and services you may not know are there: olimpio.io/free-scan