MiBOT SupportMiBOT Support
8 min read

Shadow IT: The Hidden Risk in Your SA Business

By Herman du PlessisTechnically reviewed by Herman du Plessis

Shadow IT is any app, device or cloud account your staff use for work without IT's knowledge or approval — think personal Dropbox, WhatsApp for client files, or a free Trello board tracking sensitive matters. It's not malicious; it's usually people trying to get work done. But it creates real security gaps, POPIA exposure and data you can't recover when someone resigns.

Most SA business owners only find out shadow IT exists after something goes wrong: a client file leaks, a bookkeeper leaves and takes the WhatsApp group with her, or an auditor asks where sensitive data actually lives and nobody can answer.

This guide walks you through what shadow IT looks like in a South African context, why it's spreading, and the practical steps to bring it back into the light — without turning into the IT police.

What exactly is shadow IT?

Shadow IT is any technology used for work that hasn't been vetted, approved or managed by whoever runs your IT. In a 15-person law firm or accounting practice, that usually means:

  • Staff using personal Gmail to send documents home so they can work over the weekend
  • A partner storing client files in a personal Dropbox because "it's easier"
  • Teams using WhatsApp Web on office machines to share client info
  • A junior signing up for a free Canva, Trello, ChatGPT or Notion account with their work email
  • Someone plugging a personal USB drive into a work laptop to move files
  • A department buying a SaaS subscription on a personal credit card and expensing it

None of this feels dangerous in the moment. That's exactly the problem.

Why is shadow IT such a big deal for SA businesses?

The risks are practical, not theoretical.

You lose control of client data. When a paralegal stores matters in her personal OneDrive, that data sits outside your backup, outside your access controls, and outside your ability to prove — to a client or a regulator — where it is and who has seen it.

POPIA exposure grows quietly. The Information Regulator expects you to know where personal information is processed and stored. If your staff are using tools you don't know about, you cannot honestly complete a data inventory or respond to a data subject request. If a compromise happens on one of those platforms, you still have to notify "as soon as reasonably possible" — you don't get to plead ignorance.

Offboarding becomes a nightmare. When someone resigns, you can revoke their Microsoft 365 access in minutes. You cannot revoke the personal Gmail account they used to email themselves three years of client correspondence.

Due diligence questionnaires get awkward. Clients and tender processes increasingly ask which systems process their data. "We don't fully know" is not an acceptable answer.

Costs pile up invisibly. Departments buy overlapping tools. Nobody notices the R400/month subscriptions still billing eighteen months after the person left.

Why does shadow IT keep spreading?

Because your staff aren't trying to break rules — they're trying to do their jobs. Shadow IT usually grows for four reasons:

  1. The approved tool is clunky or missing. If sharing a large file through your official system takes eight clicks, WeTransfer wins.
  2. IT feels slow or unreachable. If requesting a new tool means waiting a week for a reply, people go around the process.
  3. Free tiers are everywhere. Every SaaS product offers a free plan. Signing up takes ninety seconds.
  4. Remote and hybrid work. Staff working from home reach for whatever's on their personal laptop.

Fix those underlying causes and shadow IT shrinks naturally. Punish people for using it and they just get better at hiding it.

How do you find the shadow IT already in your business?

You can't manage what you can't see. Start here:

Run a browser and app audit. Your Microsoft 365 management console shows which third-party apps staff have connected to their work accounts. You'll be surprised. Review the list quarterly and revoke anything unapproved.

Check your firewall or DNS logs. These show which cloud services traffic is actually going to. If half your staff are visiting dropbox.com daily and you don't officially use Dropbox, you've found shadow IT.

Review credit card and expense claims. Search the last twelve months of expenses for keywords like "subscription", "monthly", "software", "SaaS", or specific vendors. Look for recurring small amounts.

Just ask. A short, blame-free survey — "tell us every tool you use to get your job done, we won't be cross" — usually surfaces more than any technical scan. People will tell you if they know they won't be punished.

Look at what leavers had installed. When someone resigns, audit their machine before you wipe it. It's a snapshot of the tools your team actually reaches for.

What do you do once you've found it?

Don't just ban everything. That drives it underground.

Sort what you find into three buckets:

  • Sanction it — the tool is genuinely useful, so bring it into the fold. Buy proper business licences, add it to your access controls, include it in offboarding.
  • Replace it — you already have an approved tool that does the job. Migrate people over and explain why.
  • Retire it — the tool duplicates something else or creates unacceptable risk. Set a deadline, help people move, then block it.

Publish a short, readable acceptable-use policy. Two pages, plain English, no legal jargon. Cover: which categories of tools are approved, how to request a new one, and what's off-limits (personal cloud storage for client data, personal email for work files).

Make the approved path easier than the shortcut. If requesting a new tool takes ten minutes and gets a same-day answer, people will use the process. If it takes three weeks, they won't.

Train the whole team once a year. Not a two-hour lecture — a 20-minute session showing real examples of how shadow IT bites SA businesses. Pair it with your phishing training.

Build shadow-IT checks into onboarding and offboarding. New staff get a list of approved tools on day one. Leavers get a proper checklist that includes revoking third-party app connections.

Key facts

  • Shadow IT is any technology used for work without IT's knowledge or approval.
  • Under POPIA, the responsible party must notify the Information Regulator and affected data subjects "as soon as reasonably possible" after reasonable grounds to believe a compromise occurred — see inforegulator.org.za. The investigation does not need to be complete first.
  • MiBOT Support is ISO/IEC 27001:2022 certified — the same standard we help clients demonstrate to their own auditors and tender panels.

Frequently asked questions

Is shadow IT always bad? No. Some of the best tools in your business probably started as shadow IT — someone found something that worked and quietly used it. The problem isn't the initiative; it's the lack of visibility. Sanction the good stuff, retire the risky stuff.

How is shadow IT different from BYOD? Bring-your-own-device is about hardware — staff using personal laptops or phones for work. Shadow IT is about software and services. A staff member can use a company laptop and still create shadow IT by signing up for unapproved cloud tools. The two often overlap.

We're a small firm — do we really need a policy? Yes, but keep it proportionate. A two-page acceptable-use document, an approved-tools list, and a clear "how to request something new" process is enough for most 10-80 person firms. It's mostly about making expectations visible.

Can our IT provider help find shadow IT? Yes. A good managed provider will audit your Microsoft 365 tenant, review network traffic patterns, and help you build a sensible approved-tools list — as part of ongoing proactive monitoring rather than a once-off project. That's the difference between break-fix vs managed IT.

Getting shadow IT under control without the drama

Shadow IT isn't a staff problem — it's usually a signal that your approved tools or processes need work. Fix the friction, make the safe path the easy path, and most of it disappears.

If you're staring at a growing pile of unknown apps and personal accounts across your business and you're not sure where to start, that's exactly the kind of thing a proper managed IT support partner sorts out with you — quietly, without turning it into a witch-hunt.

At MiBOT Support, we help SA professional-services firms map what's actually running in their environment, tidy it up, and put the guardrails in place so it doesn't sprawl again. If you'd like a conversation about your setup, book a free consultation and we'll take it from there.

Last reviewed: September 2026

Ready to Experience IT That Actually Works?

Let us take care of your technology so you can focus on growing your business.

  • 25+ years supporting SA businesses
  • Under 1-hour response
  • ISO/IEC 27001:2022 certified
Book a callCall