Thirty years of enterprise IT, distilled into something you can use on Monday morning.
Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet.
No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on.
New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.
Hey, everybody, and welcome back to the Operational ITAM podcast.
I'm Bill Van Nort, and I hope you brought the flashlight I told you to bring,
because today we're going hunting in the dark. Shadow IT.
The tools your business bought without telling you. The servers nobody owns.
The subscriptions hiding in expense reports.
The episode I warned you way back in episode one might make your security team sweat.
If you're new to the show, welcome. Glad to have you. This one stands alone
just fine, but it connects to everything.
The gates from episode two, the ledger from episode three, and the audit findings
we spent two episodes fighting.
Because here's the through line. An
awful lot of what goes wrong in asset management was born in the shadows.
Today we find out where the shadows come from. And I'll warn you now,
the answer is going to be uncomfortable. Because some of it comes from us.
Good morning, good afternoon, or good evening, wherever you happen to be listening from.
This is the Operational ITAM Podcast, the show where we take the unglamorous
machinery of enterprise technology and make it make sense.
I'm your host, Bill, and today's episode requires a little humility, mine included.
Welcome in, grab your coffee, grab your headphones, and let's get into it.
First, the definition, because I promised you I'd always define my terms.
Shadow IT is any technology—hardware, software, cloud service,
and lately, artificial intelligence—acquired and used inside your organization
without the knowledge, approval, or management of your IT function.
The marketing team's design subscription on a corporate card,
the developer's personal cloud account running a workload that quietly became production,
the department that bought its own laptops because yours took too long,
And the newest resident of the shadows, the AI chatbot half your workforce is
using and most of them aren't mentioning.
We'll get to that one after the break, and it deserves its own segment, believe me.
Now before we talk about scale, I want to do something a little unusual for
this show. I want to defend the people in the shadows.
Because the standard industry framing, shadow IT as villainy,
employees as rule breakers, IT as the wronged party, is not just self-serving,
it's analytically wrong.
And if you start from the wrong diagnosis, you'll prescribe the wrong cure.
Here's the honest truth from somebody who has sat in the CIO chair.
Shadow IT is a demand signal.
Every unsanctioned tool is a business need that showed up at your front door,
found it locked, and went around back.
One industry survey found that only about 1 in 8 IT departments can actually
keep pace with the demand for new technology requests. 1 in 8.
Which means, for the overwhelming majority of organizations,
the official answer to, I need a tool to do my job, is, functionally, wait.
And people whose bonuses, deadlines, and careers are on the line do not wait. They swipe the card.
Would you wait? Be honest. I've been the guy whose process was being routed
around, and when I finally stopped being offended long enough to ask why, the answer stung.
Because my process was slower than their problem.
Write that down, because it's the thesis of this whole episode.
People don't route around IT because they're villains. They route around IT
because the sanctioned path is slower than their problem.
That's the empathy. Now here's the accounting, because sympathy for the cause
does not erase the cost. Scale first.
Gartner has estimated that 30-40% of IT spending in large organizations happens
as shadow IT, outside IT's visibility and control.
Sit with that. If your official technology budget is $50 million,
there may be another $15 or $20 million in technology spend scattered across
expense reports, departmental budgets, and purchase cards that your ledger has never heard of.
And the visibility gap is worse than the spend gap. Research has repeatedly
found organizations formally tracking on the order of 100 cloud services while
actually using close to 10 times that number.
10 times. Your ledger from episode 3?
If you haven't hunted the shadows, the right hand column, the deployment side,
isn't just incomplete. It's a rounding error of the truth.
Now, the risks, and there are three, in escalatory order.
Risk 1. Waste. Shadow purchases mean duplicate tools.
Three departments buying three different project management platforms,
none at volume pricing, all renewing automatically, none appearing at any renewal negotiation.
Remember the SaaS numbers from episode 3? Roughly half of purchased licenses going unused?
Shadow spend is where that problem goes to hide, because nobody can right-size
a subscription nobody knows exists.
Risk 2. Audit exposure. Think back to the two-parter.
Where do you suppose those findings come from? They come from right here.
A department stands up software on a server nobody told licensing about.
A team downloads a free tool, and we learned in Episode 3 exactly what free can turn into.
One licensing change, and that friendly little runtime is billing you per employee.
When the audit letter lands, the shadows get counted. At list price.
Whether you knew about them or not.
Ignorance is not a defense recognized in any license agreement I have ever read.
And I have read more of them than any human should.
Risk three, and it's the big one, security. Unsanctioned tools mean unmanaged tools.
No patching, no multi-factor enforcement, no offboarding when the employee leaves,
corporate data sitting in personal accounts.
The breach research year after year links a meaningful share of security incidents
to unmanaged, unsanctioned technology, and breach costs run to the millions.
Every zombie asset, remember the zombies? A device on your network your record's never heard of?
Every shadow app is the software version of a zombie, drawing data,
drawing risk, invisible to every control you have.
Your security team can't protect what your asset program can't see.
That sentence, by the way, is how you get your security team to fund your asset
program. You're welcome.
If you're enjoying the show, do me a favor, like and subscribe,
post your comments, and share this episode with a department head who's quietly
built their own technology stack.
And when you send it, tell them it's not an ambush. This one's on their side.
All right, and now the segment I promised. Let's talk about the newest,
fastest growing shadow in the building, shadow AI.
Everything we just said about shadow IT applies, but compressed and amplified.
Employees adopted generative AI tools faster than any technology in my 30 years,
faster than any governance process on earth could keep up with.
And surveys suggest a majority of the people using AI at work are doing it quietly.
One widely cited finding put the share of workers hiding their chatbot use from
their employer at around 70%.
Now here's why this shadow is darker than the old ones. When somebody used an
unsanctioned file sharing app in 2015, the data sat somewhere it shouldn't. Bad.
But when somebody pastes your source code, your customer list,
or your draft contract into an unmanaged AI tool, that data doesn't just sit.
It leaves. Into a third-party system entirely outside your control.
The payload changed, and the breach data has caught up.
IBM's most recent cost of a data breach research found roughly one in five breached
organizations was compromised through Shadow AI, and those incidents ran hundreds
of thousands of dollars more expensive than the average breach.
This is not a future problem. This is a current line item.
But, and here is where 30 years of pattern recognition earns its keep, we have seen this movie.
Shadow AI in 2026 is Shadow Cloud in 2012 wearing a smarter costume.
And we know how that movie ends, because the industry already ran the experiment.
Bans alone failed. Blocking the popular tool just pushed usage to personal devices
and lesser-known tools that were harder to see and worse on security.
What worked was visibility plus a sanctioned alternative. Give people an approved
tool that's actually good, make it easier to use than the shadow version,
and watch the shadows thin out on their own.
Keep that in your pocket. It's about to become the whole strategy.
Which brings us to a listener question right on cue. Dave from Milwaukee writes,
Bill, my CISO wants to block every unsanctioned app at the firewall and be done with it.
Gut feeling says that's wrong, but I can't articulate why.
Dave, your gut is smarter than the firewall. And here's the articulation.
Blocking treats the symptom and feeds the disease. The need that drove someone
to that tool doesn't vanish when the tool gets blocked.
It goes to their phone, their home network, their personal account,
where you have zero visibility instead of partial visibility.
You haven't eliminated the shadow, you've made it darker.
Block the genuinely dangerous stuff, absolutely, but pair every block with a
sanctioned path, or you're just running an expensive program to make your blind spots blinder.
So how do you actually find the shadows?
You promised your flashlight. Here it is. Five beams.
None of them require new budget, and every one of them uses data you already
have, which by now you know is my favorite kind of project.
Beam 1. Follow the money.
Pull your purchase card and expense report data and filter for software and
subscription merchants.
Then pull your accounts payable vendor master and look for technology vendors
that procurement never onboarded.
The shadows are self-documenting. People expense them.
It is the single richest shadow IT data source in your company,
and it's sitting in finance, one polite email away.
Beam 2. Follow the identity. Your single sign-on and identity platform logs
show what applications people authenticate to, including the ones that were
never formally sanctioned.
And look hard at OAuth grants.
Every time an employee clicks Sign In With Your Work Account on some third-party
app, they've connected that app to your environment.
That consent log is a shadow inventory writing itself in real time.
Beam 3. Follow the network.
DNS queries, web gateway logs, egress traffic.
Your network team already sees every cloud service your organization talks to.
They've just never had a reason to hand asset management the list. Give them the reason.
Beam 4. Follow the endpoint. Your endpoint management platform,
the one I've been telling you to lean on since episode 1, knows every installed
application, including the ones that never pass through a gate.
That's the same normalization work from episode 3, pointed at a darker corner.
And lastly, beam 5, the one everyone forgets. Just ask.
Run an amnesty survey. Tell people, in plain language, no punishment, no gotcha.
Tell us what you're using and why, and we'll try to make the good stuff official.
You will be astonished what people volunteer when the question isn't an accusation.
And the why answers? That's free consulting on exactly where your service catalog is failing.
Which brings us to the response. You've found the shadows. Now what?
Three buckets. And notice there's no bucket labeled punish.
Bucket 1. Adopt. A lot of shadow tools are genuinely good. That's why people chose them.
Sanction them. Negotiate real terms. Bring them into the ledger and let the team keep their tool.
You just converted an adversary into an ally.
Bucket 2. Migrate. Where 5 shadow tools do one job, consolidate to one sanctioned
choice, with a transition period and actual help, not a memo.
Bucket 3. Retire. The genuinely dangerous ones, the data leaking,
the unlicensed, the abandoned, get shut down, with an explanation of why.
Because when IT says because I said so, that is how the shadows formed in the first place.
And then the permanent fix, and you knew this was coming. Gate 1,
Episode 2, the request gate.
A fast, clear, well-stocked service catalog is the single best shadow IT prevention
technology ever invented, because the shadows are exactly the shape of whatever
your catalog can't deliver quickly.
Speed up the front door, and the back door traffic drops on its own.
Let's take it to the library one more time. The head librarian is doing her
rounds one evening, and behind the boiler room she finds.
A second library. Shelves the patrons built themselves.
Books nobody cataloged. Some wonderful. Some borrowed from lenders with,
let's say, alarming terms and conditions.
Her first instinct is fury. But then she reads the note tacked to the doorframe.
Acquisitions take six weeks. We needed the books now.
And a wise librarian, the kind who keeps her job, doesn't burn down the reading room.
She catalogs the good books, replaces the dangerous ones, thanks the patrons
for showing her exactly which collections the library was failing to stock,
and then she fixes the acquisitions desk.
Because the secret library was never a rebellion, it was a suggestion box she'd been ignoring.
One closing principle, and the arc continues. Hardware is a custody discipline.
Software is an evidence discipline.
Audit defense is a process discipline. Settlement, a commercial discipline.
Shadow IT? Shadow IT is a service discipline.
The shadows are not a security problem you punish or a compliance problem you
audit. They are a service problem you out-compete.
Make the sanction path faster than the shadow path and the shadows shrink.
Let the sanction path stay slow and no policy on earth will save you.
You don't fight shadows with rules. You fight shadows with light.
And with a front door that opens faster than the back door.
Class dismissed. Homework. And this one might be the most eye opening yet.
Get 90 days of purchase card and expense data from finance. Software and subscription merchants only.
Count the distinct products. Then count how many appear in your asset records.
That gap, that exact number, is your shadow. Measured, dated,
and ready for the one page brief you learned to write last episode.
Fair warning from someone who has run this exact exercise more than once,
the number will be bigger than you think.
It always is. Every single time.
Next episode, we take on a fight I promised in the very first show,
the Great Refresh debate.
Three years? Four? Five or more?
The vendors have brochures, the CFO has opinions, and I have actual failure rate data.
And one of those three is going to win. We'll find out which.
That's today's episode. The flashlight is yours now. Go point it somewhere uncomfortable.
I'm Bill Van Nort. This is the Operational ITAM Podcast. Like the shadows,
speed the front door, and I'll see you next week. Take care.