Home
Blog
MSP Tips

Shadow IT: Lock everything down or allow access?

Elvira ZaltaneSeptember 13, 2026

Shadow IT: Lock everything down or allow access?

At affire, with the team, we decided to start doing video series. Yeah, yeah, i know - again some content some new startup's creating. But actually it's not really about content for content's sake. It's about bringing conversations around both comfortable and uncomfortable topics, and speaking to fellow IT teams / MSPs to see what's going on behind the curtain.

While we anticipate to bring in more peers to have interviews and share their stories, first episodes we kick-started ourselves on a few topics. To make it a bit more interesting, we're also starting this newsletter, to share our own raw opinions on the issues discussed in videos. So if you missed it - here's the first series we did on Shadow IT, with a bit of our thoughts on the issue here in the Newsletter.

While companies spend millions on cybersecurity, one of the biggest risks a company might have actually is an employee just wanting to do their work in a more productive way.

Working to build affire has highlighted to us that sometimes the villain isnt the hacker in a hoodie, but rather Shadow IT, where the same employee is just using Trello or Canva without permission, uploading unauthorised information in the platforms, or.. sharing accounts with colleagues to that same Canva account. (which is actually a whole separate problem we'll talk about in one of our next newsletter editions on shared accounts, but that's for later).

In the video we highlight that according to Gartner, by 2027, 75% of employees will be using tech outside of IT’s visibility, so the question that we bring to the table is - which approach is the best one, whether to lock access down to everything and allow just the apps that have been approved by IT, or to allow complete (or almost complete) freedom for the employee, but to then monitor their activity so you can still keep tabs on any risks?

And while the modern approaches now talk about monitoring and being flexible, rather than locking everything down, we can understand the second variant being appropriate in specific industries or situations as well.

I guess we can talk about an organisation in a non-critical sector where productivity tools become a must, as marketing or project management departments might raise their eyebrows if they can't just open up a browser and sign up to the new cool tool their friend at work said works really well for image generation. Which is completely valid, cause noone wants to go to IT to ask for permission for a silly image generation app you might use once. We don't comment on video the opinion of what we personally think about the approaches, however, if we would have to give an opinion, it would be completely industry and case-by-case basis. A marketing agency would rather benefit from the flexibility but monitor approach, while a company in the defence or military sector might pose more risks with flexibility than another industry's player. We highly doubt that anyone in the military sector on their computer will want to generate a funny GIF for their campaign or project. Probably not.

The main takeaway from this is that there are many pro's and con's for both approaches:

Cons for allowing access:

  • Employees can work fast, flexible, modern, and IT has complete observability over what is happening

Minuses:

  • It asks for more expensive resources and technological means, including, constant attention from the IT's side, unless there are tools doing it for them and notifying.

While we believe that being productive, flexible and innovative is the way, there is the golden middle: the reality is that complete blocking doesnt work these days anymore, but there are hybrid approaches anyone can adapt, that is to:

  • block when only necessary and last resort, like blocking suspicious or dangerous apps
  • give safe alternatives. E.g. instead of not allowing ChatGPT enable a corporate version of any other LLM model thats monitored, safe, allowed and within companys toolstack
  • monitor and educate - allow the safe version access, monitor data flow and constantly educate the employees about the use of those tools. E.g. to say that you can use a tool for writing an email, but you cannot put client's personal ID code there.
  • Create internal rules of app use, including teaching on AI ethics, to help employees navigate how the tools can be used appropriately to lessen any cybersecurity risks

That's all, what's your opinion on it? Let us know if you have any comments on this topic, enjoy the video and if you ever want to be featured in any of our future videos - ping us!

https://www.youtube.com/watch?v=mlwHmwgS6QA