As remote and hybrid work continues, more employees are turning to personal apps, workarounds and unofficial tools to get things done. It’s convenient, but risky.
According to cybersecurity firm Rootshell Security, this rise in so-called Shadow IT is exposing organisations to threats they can’t even see coming.
Whether it’s file-sharing apps on a personal laptop or unsecured task tools, Shadow IT covers anything being used for work that hasn’t been approved or protected by IT.
“It’s almost always not bad intent, it’s just people doing whatever helps them work faster,” says Shaun Peapell, VP of Global Threat Services at Rootshell. “But once it’s outside the IT team’s view, it’s outside your defences.”
Static Security Models No Longer Cut It
The bigger issue? Most businesses still rely on annual audits or one-off tests to understand their exposure. But Shadow IT doesn’t appear on a schedule.
“A lot of organisations still think they’re in control – because they ran a test six months ago,” says Shaun Peapell. “But the tools teams are using now? They’re not on that test. They weren’t even on the radar.”
Rootshell’s analysts have seen a steady rise in:
-
Staff using consumer tools to handle sensitive business data
-
Personal devices are being used with zero protection in place
-
IT teams are completely unaware of what platforms are actually in use
And because traditional tests don’t account for these behaviours, the risks stay hidden until something breaks.
What Needs to Change
Rootshell Security is calling for businesses to stop relying on outdated models of security and start looking at their threat exposure in real time.
“You can’t defend what you don’t know about,” Shaun Peapell adds. “And you won’t find Shadow IT in a PDF that gets updated once a year.”
Instead of treating cybersecurity like a tick-box exercise, organisations need to:
-
Adopt a Continuous Testing Approach. Cybersecurity is not a one-time event but an ongoing process.
-
Embrace a Holistic Approach: Security isn’t just about technology but also processes and people.
-
Prioritise Threat Intelligence: Cyber threats are dynamic, and organisations need to respond with agility.
-
Leverage Compliance as a Foundation, Not a Ceiling: While compliance is essential, it should serve as the baseline, not the end goal.
“Cyber threats don’t wait for Q4,” says Shaun Peapell. “The companies that stay ahead are the ones that stop treating security like admin and start treating it like the live, moving target it is.”
To learn more visit: https://www.rootshellsecurity.net


Be First to Comment