Shadow IT Became Mainstream IT — Now What?
We did not lose control of the estate in the crisis; we discovered how little of it we had truly held all along.
Executive Summary
Under the pressure of sending entire workforces home in a matter of days, the careful boundary between what corporate IT provided and what employees improvised for themselves quietly collapsed. Teams reached for whatever kept the work moving — a file-sharing account opened on a personal card, a messaging tool a colleague already knew, a spreadsheet doing the job of a system that would have taken eighteen months to procure. For a decade we called this shadow IT and spent real energy trying to eliminate it. Through the past year we stopped fighting it, because there was no alternative, and in the process we learned something uncomfortable: a great deal of it worked.
This essay reflects on what that discovery means now the emergency has receded but the tools have not. The central claim is straightforward. Shadow IT did not vanish once it proved useful; it was absorbed into the mainstream without ever being acknowledged as such. The organisations now behaving as though normal service has resumed are carrying a specific, compounding liability — not the old nuisance of a few rogue applications, but a whole operating layer that runs the business and sits outside the controls, the architecture, and the institutional memory of the people accountable for it.
The uncomfortable truth of the past year is not that shadow IT crept back in. It is that we promoted it, and then declined to give it a job title.
The Year We Stopped Saying No
For most of the last decade, the relationship between central IT and the rest of the organisation was governed by a single reflex: the answer to an unapproved tool was no. The reasoning was sound. Unmanaged applications leak data, duplicate spend, evade security review, and multiply the surface an attacker can reach. A well-run function knew where its data lived and which systems touched it, and shadow IT was the standing threat to that knowledge. We built discovery tooling to find it and policy to forbid it, and we told ourselves the war was slowly being won.
Then, over a fortnight, the premise dissolved. When an entire workforce leaves the building at once, the function that has spent years perfecting the word no discovers it can no longer afford to say it. A team that cannot collaborate on a document is a team that cannot work at all, and no procurement cycle moves at the speed of a national lockdown. So the improvisation began, and — this is the part we rarely state plainly — central IT largely let it. Not by decision, but by absence. The controls did not fail so much as step aside, because enforcing them would have meant halting the organisation at the precise moment it most needed to keep moving.
What followed was not chaos. That is what makes it interesting. The pattern I have observed across sectors is that the improvised estate settled quickly into something functional. People are resourceful under constraint, and the tools they chose were, on the whole, the tools that already worked well enough for millions of others. The file-sharing platform did share files. The lightweight project board did track the work. The business ran — in many cases it ran faster, freed from the friction of a procurement process designed for a slower world. And so a question that would have been unthinkable eighteen months earlier began to form at the edge of every senior conversation: if the workarounds are working, what exactly were the controls protecting us from?
Why the Workarounds Held
It is tempting to read the survival of shadow IT as a story about clever employees outwitting slow institutions. That flatters everyone and explains nothing. The improvised estate held because several structural forces were pushing in the same direction, and understanding them is the difference between managing what we now have and simply hoping it behaves.
- The tools had already crossed a quality threshold. The consumer and small-business software of the past few years is genuinely capable. An employee reaching for an unsanctioned tool in a crisis was not reaching for something shoddy; they were reaching for something that had been refined by enormous markets and often exceeded the internal alternative on usability.
- The cost of adoption had fallen to near zero. A credit card and an email address now stand up a capability that once required a project. When the barrier to acquiring software is lower than the barrier to raising a ticket, the ticket loses.
- The crisis inverted the burden of proof. In normal times, a new tool must justify itself against a default of no. During the past year, the default flipped: the burden fell on anyone who wanted to stop a working arrangement, and few were willing to carry it while the organisation was fighting to stay upright.
- The people closest to the work were also closest to the decision. Distributed teams made local choices at speed, and those choices aggregated into an estate that no central body ever designed or approved but which, in sum, does the organisation’s work.
None of these forces has reversed. The tools are still good, still cheap, and still chosen by the people who use them. What has changed is only that the emergency justification has expired. The estate remains; the story we told ourselves to permit it does not. That gap — between a permanent reality and a temporary rationale — is where the risk now lives.
The Governance We Quietly Suspended
Every organisation I have observed made the same implicit trade during the crisis, and almost none has revisited it deliberately. To keep working, we suspended the governance that would have slowed us down: the architecture review that asks how a new system fits the estate, the data assessment that asks what information it will hold and where, the security review that asks who can reach it and how we would know if someone did. These were not abolished. They were bypassed, once, as an exception — and the exception has quietly become the standing arrangement.
The danger is not that governance was suspended in an emergency; that was the right call, and a function that had refused would have failed the organisation. The danger is that suspension has no natural end. A control that is switched off under pressure does not switch itself back on when the pressure lifts. Someone has to decide to restore it, and restoration is unglamorous, contested work that competes for attention against a hundred more visible priorities. So the default outcome — the one that happens if no one intervenes — is that the emergency posture simply persists, decays into habit, and is eventually mistaken for the normal state of affairs.
“A control switched off in a crisis does not switch itself back on when the crisis ends. Someone has to choose to restore it, and no one is measured on having done so.”
This is why I distrust the language of return that has crept into so many transformation conversations this year. There is no returning to a governance model that was designed for an estate that no longer exists. The systems of record have multiplied. The data has scattered. The map that the architecture function once maintained describes a territory that has moved. To govern what we now have, we must first admit that we are not going back to what we had.
The Bill Nobody Has Costed
The specific liabilities of a mainstreamed shadow estate are not exotic. They are the same risks we always understood, now operating at a scale and depth we never sanctioned. Two deserve particular attention because they compound silently.
The first is data. When business-critical information settles into tools the organisation does not administer, several things become true at once that were not true before. The organisation may not know precisely what data those tools hold. It may not control who can access them or reliably revoke that access when someone leaves. It may be unable to answer a regulator’s or a customer’s question about where personal data resides, because the honest answer is that no single person knows. And it cannot protect what it cannot see — a backup regime, a retention policy, and a breach-detection capability all assume you know which systems to point them at.
The second is continuity. An estate assembled by individual choice is an estate held together by individual knowledge. The account is in someone’s name. The configuration lives in someone’s head. The integration that quietly moves data between two improvised tools was built by a person who may not be here next year. Resilience that depends on specific people remembering specific things is not resilience; it is luck with good manners.
The table below contrasts the logic under which these tools were adopted with the logic the organisation actually needs now that they are load-bearing. The gap between the two columns is the work.
| Dimension | Emergency logic (how we adopted) | Steady-state logic (what we now need) |
|---|---|---|
| Speed | Adopt in hours, justify never | Decide deliberately, review periodically |
| Ownership | Whoever set it up | A named accountable owner |
| Data | Wherever it landed | Known location, classified, governed |
| Access | Whoever had the link | Provisioned and revocable |
| Continuity | Someone remembers | Documented and transferable |
| Exit | Unthinkable | A known, tested path |
None of this argues for tearing the estate down. Much of it earns its place. The argument is that load-bearing infrastructure must be treated as load-bearing, and a great deal of ours is currently held to the standard of a temporary convenience.
From Tolerating to Absorbing
The instinct of a controls-minded function, confronted with an estate it never approved, is to reassert the old regime: discover everything, forbid what fails review, and force the survivors back through the front door of procurement. I think this instinct is wrong, and not only because it would fail. It misreads what the past year proved. The improvised estate was not a failure of discipline to be corrected; it was a signal about where the organisation’s real needs and the official provision had diverged. The task is not to punish the divergence but to close it.
What that requires, in my experience, is a shift from tolerating shadow IT to absorbing it — bringing it inside the boundary of things the organisation knows about and stands behind, without pretending it arrived through the front door. The moves are unglamorous and sequential.
- See it honestly. Rebuild the map. Find what is actually running the business, not what the policy says should be. This is discovery aimed at understanding, not at prosecution — and people will only tell you the truth if they are confident the answer is not punishment.
- Triage by consequence, not by origin. Sort the estate by what depends on it and what it would cost if it failed or leaked, rather than by whether it was ever approved. A sanctioned system holding nothing important matters less than an improvised one holding everything.
- Give every load-bearing tool an owner. The single most valuable act is to attach a name to each system that matters — someone accountable for its data, its access, and its continuity. Most of the risk in a shadow estate is not technical; it is that no one is responsible.
- Bring the survivors up to standard, or replace them deliberately. Some tools should be formally adopted and governed. Some should be consolidated. A few should be retired in favour of a better fit. The point is that each outcome is now a decision, taken in daylight, rather than an accident nobody owns.
- Fix the reason it happened. If it is faster to buy a tool on a personal card than to get one through the proper channel, the proper channel is the problem. An organisation that does not make the sanctioned path the easy path has simply scheduled its next shadow estate.
The fifth move is the one most often skipped and the one that matters most. Shadow IT is not a moral failing of employees; it is a market signal about the friction of official provision. Absorb this estate without addressing the friction that created it, and the exercise buys a year at most before the pattern repeats under the next pressure.
What This Reveals About Transformation
There is a larger lesson here, and it is not really about tools. For years, transformation programmes have promised to modernise how organisations work, and for years they have moved at the stately pace of governance, procurement, and architectural caution. Then a crisis achieved more operating-model change in a fortnight than most of those programmes managed in a decade — remote work, cloud adoption, the collapse of the old software procurement model — and it did so precisely by ignoring the machinery that transformation programmes rely on.
That should unsettle us more than it has. It suggests that the gap between transformation intent and transformation reality is not mainly a gap of ambition or investment. It is a gap of friction. The improvised estate is what an organisation’s genuine needs look like when they route around the official channels — and the fact that they routed around so successfully is an indictment of how heavy those channels had become. The organisations that learn the right lesson from the past year will not be the ones that rebuild the old walls fastest. They will be the ones that ask why their own people found it easier to go around the front door than through it, and that treat the answer as a design brief rather than a disciplinary matter.
We did not lose control of the estate in the crisis; we discovered how little of it we had truly held all along. What we do with that discovery — whether we absorb what we have learned or paper over it and wait for the next emergency to teach it again — is the transformation question that actually matters now.