Skip to content
Atlas
GET IN TOUCH

B://ASSESS22Shadow IT

Find the software
nobody told you about.

Shadow IT is any software, service, or device your staff have adopted without going through IT: the file sharing account someone set up to get a large file to a client, the project tool one team pays for on a personal card, the automation somebody built that the business now quietly depends on. This work finds it, assesses the risk, and decides what to adopt, replace, or shut down. It is for organisations that suspect, correctly, that their real application list is considerably longer than their official one.

Shadow IT is not a discipline problem. It is a signal that the sanctioned tools were not good enough, and it almost always holds company data.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
  • 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
  • 03Only handled when it breaksAttention arrives after the disruption rather than before it.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Discovery

    What is actually in use, found through expenditure, network traffic, and sign-in data rather than by asking people to declare it.

  • 02

    Risk assessment

    What data each tool holds, which country it lives in, who is paying for it, and what happens to the data when that person leaves.

  • 03

    Rationalisation

    Adopt, replace, or retire, decided on merit. Sometimes the unofficial tool is genuinely better than the sanctioned one, and the right outcome is to adopt it properly.

  • 04

    Ongoing visibility

    Detection that keeps running, because this recurs the moment a sanctioned tool frustrates somebody with a deadline.

Scope, assess, report, support

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Week 1

    Scope

    We agree what is being examined and what a useful answer looks like, so the work is not open-ended.

  2. 02Weeks 2 – 3

    Assess

    Evidence gathered from your systems and your people, because the documented process and the real one rarely match.

  3. 03Week 4

    Report

    Findings written for a decision maker: what is true, what it means, and what we would do about it, ranked.

  4. 04As needed

    Support

    We can hand the report over and step back, or stay and deliver the remediation. Both are normal.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is shadow IT?

Shadow IT is any software, service, or device your staff have adopted without going through IT: the file sharing account someone set up to get a large file to a client, the project tool one team pays for on a personal card, the automation somebody built that the business now quietly depends on. This work finds it, assesses the risk, and decides what to adopt, replace, or shut down. It is for organisations that suspect, correctly, that their real application list is considerably longer than their official one.

02What counts as shadow IT in a normal business?

Any technology being used for work that the business did not approve and does not manage. In practice it is rarely dramatic: a free file transfer service, a survey tool, a note-taking app, a spreadsheet that has quietly become a system, or an AI assistant. Each one seems small. Collectively they hold a surprising amount of your company’s information in places you cannot see, cannot back up, and cannot recover.

03Why does shadow IT happen if we have approved tools?

Because someone had a job to do and the approved tool made it harder. That is almost always the whole explanation. People are not trying to create risk, they are trying to send a file, book a meeting, or track a project. Treating it as a discipline problem produces a policy nobody follows. Treating it as feedback on the sanctioned tools produces a fix that holds.

04What is the actual risk of an employee using a free tool for work?

Four things, in rough order of how often they bite. Data sits somewhere you cannot recover it from. The account is tied to one person, so their departure takes it with them. There is no visibility of who else it has been shared with. And you may have an obligation, under the Privacy Act or a customer contract, that the tool quietly breaches. The free survey tool holding customer responses is a real example we have found more than once.

05How do you find shadow IT without surveilling staff?

Mostly through data you already hold and have every right to look at. Expense claims and card statements show what is being paid for. Sign-in logs show which third-party applications have been granted access to your Microsoft 365 or Google accounts. Network and DNS data shows what is being reached. None of that requires reading anyone’s messages, and we would advise against approaches that do.

06Should we block everything we find?

No. Blocking without replacing simply moves the activity to personal devices, where you have no visibility at all. The sequence that works is: find it, understand why it was adopted, provide something at least as good, then close the old path. Blocking first is the version that fails, usually quietly.

07How much does shadow IT cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

08How long does it take to get started with shadow IT?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

09Can you deliver shadow IT alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

10Do we have to use Atlas for the work the report recommends?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

11Do you work with organisations outside Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

12Who does the assessment, and who presents the findings?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

13What do we actually receive at the end?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services