Shadow IT

The Hidden Risks of Unmanaged Devices and Shadow IT

You can’t protect what you don’t know exists.

It’s a sentence that underlines one of the biggest security risks facing small businesses: shadow IT. That’s when technology is used within your business without the knowledge or oversight of your IT team.

Laptops, computers, mobile devices, printers, copiers, network devices, software, and even AI can become entry points for attackers or lead to security breaches. And keeping on top of it can be a challenge for any business.

That’s where expert help comes in.

In this post, we’re breaking down some of the most common examples of shadow IT and how an MSP can help strengthen small business

cybersecurity.

Let’s dive in.

Your Attack Surface and Shadow IT

Imagine a house. There are many different ways you could technically get inside: the front door, back door, garage, windows, bulkhead, etc., which is why you secure these entryways with locks, alarms, and other security measures.

This is basically your attack surface: every potential entry point an attacker can use to get inside your business.

But what if someone installed a back door without ever telling you? One, hidden in a corner, without a lock or any other security system.

That’s how shadow IT works.

For example: an employee could connect a personal laptop to the company network, or use their personal phone to access company data. But shadow IT can also include software, such as undocumented applications, cloud services, and, more recently, AI tools.

While not inherently dangerous, this lack of visibility makes things much harder for your IT team to enforce security, apply updates, monitor activity, and fix things when something goes wrong.

And that’s when unmanaged devices become a serious problem.

Laptops and Computers

Not everyone relies on their work device for their day-to-day tasks. Some employees prefer their own personal devices, either for familiarity or because they perform better than standard work systems.

This personal use is known as Bring Your Own Device (BYOD). And while BYOD policies provide employees with greater flexibility, they can lead to potential issues without proper safeguards. That’s because personal systems can lack the security and management features that a company-owned device has, like endpoint protection or remote management.

That means every personal device can create a potential security gap for your IT environment.

For example: Your accountant is working remotely on their personal PC, which missed an important security update. A few days later, the computer is hit with a malware infection. Because the device lacks proper management software, your IT team isn’t able to detect the infection before the device connects to your network and spreads the malware.

Mobile Devices

87% of companies expect their employees to use their personal device for work-related tasks, like email or answering calls. But a personal phone can be just as risky as a personal laptop, making it difficult for security teams to track and manage how employees handle work data on their personal phones.

Then there’s the simple fact that an employee can outright lose their phone. If that phone has been accessing business data like emails, cloud apps, or messaging platforms, then you suddenly have a device containing access to company information outside of your direct control, and your IT team won’t be able to revoke access or remotely wipe the device.

Printers and Copiers

You’d be forgiven for discounting your printer as a serious security concern.

But modern printers connect directly to your business network and store documents, credentials, and more. That means if you’ve printed critical information, like tax documents or customer information, and a bad actor gains access to your unsecured printer, they gain an entry point into your network while also exposing that sensitive information.

Network Devices

Then there are the devices that make up your actual network: routers, switches, Wi-Fi access points, and IoT devices.
Many small businesses may purchase a router or a wi-fi access point, connect it to their greater network, and move on with their day. In fact, according to cybersecurity research from IBM X-Force, 86% of router users never change their default factory admin passwords.
This is a major issue because bad actors know how to crack default passwords, and a device that’s a critical part of your network is a tempting entry point for criminals.

Undocumented Software

Shadow IT doesn’t just mean physical items either. Undocumented applications and cloud services can create just as many security gaps as an undocumented laptop or mobile device.

Imagine someone downloads an app without telling IT. Because IT doesn’t know about it, the app isn’t included in the security review. That app later experiences a data leak, and suddenly your employee’s account gets compromised. But because your security team isn’t aware of the issue, they’re not able to stop it.

Suddenly, a bad actor has made it onto your network, and there’s a good chance your security team isn’t going to have any idea why.

Shadow AI

We’d be remiss if we didn’t touch on undocumented AI use – shadow AI.

Similar to shadow IT, shadow AI can lead to security gaps because users may not be aware of the risk when it comes to entering work information into public tools.

Certain AI tools like ChatGPT, Claude, and Gemini process information outside of your company’s network. Depending on the service, account type, and configuration, information entered into an AI tool may be stored according to the provider’s policies.

Companies without clear guardrails for AI use can end up with employees sharing sensitive work information without realizing they’re potentially moving that data outside of your company’s control.

How an MSP Brings Visibility to Security Blind Spots

Managing shadow IT is not easy.

You need to enforce proper security hygiene, constantly monitor your network for unknown connections, and secure the devices you do know about.

It’s a full-time job, and something better left to experts like a managed service provider (MSP).

That’s because an MSP is built for this kind of thing: managing and securing your technology.

Here’s how:

They Find What’s on Your Network

An MSP can more easily identify devices and systems connected to your network. That means no guesswork or worrying about rogue connections. And once you know what’s connected, they can start addressing the devices that either shouldn’t be there or need to be secured.

They Manage Your Devices

Once identified, your MSP can start to implement proper management procedures.

That can include

  • Endpoint management for individual computers and other endpoints.
  • Patch management to automate critical security updates.
  • Mobile device management for any personal phones or tablets.
  • Antivirus and endpoint protection to keep documented devices secure.
  • Security enforcement like multi-factor authentication, encryption, and zero trust principles.

They Help You Create BYOD and AI Policies

There’s always the chance someone plugs in their phone or computer for a “Few minutes” or just outright forgets to tell IT. That’s why you need clear policies surrounding shadow IT, BYOD, AI use, and software in general.

An MSP can help create a BYOD policy that outlines:

  • What devices are approved for work use.
  • What kind of work can be performed on personal devices.
  • How employees should notify IT about devices being used for work.
  • What types of information can be stored and accessed on those devices.

This same process can be extended to AI use. For example:

  • What AI tools are approved for work use.
  • What kind of information employees are allowed to enter into AI.
  • Who is allowed to use AI in the first place.

With a clear policy, your employees will have a much better understanding of what is and isn’t allowed at work regarding their devices and software.

Constant Monitoring

Employees come and go, new devices are purchased, and new apps are installed. Things are always changing, and your attack surface changes with them.

A good MSP will provide ongoing monitoring and management so shadow IT is caught before it becomes a problem and security gaps are promptly closed.

Shine a Light on Your Blind Spots with The 20 MSP

There’s a good chance something’s connected to your network that you don’t know about. It could be a laptop, a phone, an app, or something else. Right now, that connection could be completely harmless. But until you get eyes on what you can’t see, you’ll never know for sure.

And that’s where we come in.

At The 20 MSP, we’ve been managing the unmanaged for decades. From our remote monitoring and management software to our 24/7 support desk, we help our clients secure the technology they know about while identifying the security gaps they don’t.

If you need help shining a light on shadow IT, let’s talk. We’d be happy to help secure your business.

About The 20 MSP

As a leading provider of managed IT services, The 20 MSP serves thousands of businesses nationwide, providing each one with white-glove service, secure and streamlined IT infrastructure, and 24/7/365 support. We believe in building lasting relationships with clients founded on trust, communication, and the delivery of high-value services for a fair and predictable price. Our clients’ success is our success, and we are committed to helping each and every organization we serve leverage technology to secure a competitive advantage and achieve new growth.