Shadow IT
Shadow IT refers to devices, applications and services in use within an organisation without the IT function knowing about them or having approved them.
It covers the router someone brought into the warehouse, a cloud service a department subscribed to on its own, and the maintenance access a contractor set up years ago.
Shadow IT almost never comes from bad intent. It comes from someone needing to get something done when the official route would have taken too long. The result is the same either way: systems nobody maintains, nobody updates and nobody has on the list when the question is what actually runs on this network.
Unrecorded systems do not get patched, do not get monitored and appear in no inventory. That makes them attractive to an attacker. There is also an evidence problem: an organisation required to demonstrate which systems it operates and how they are secured cannot do so for systems it does not know exist.
Visibility into network traffic surfaces shadow IT without requiring a list to exist first. Whatever communicates gets recorded, documented or not. In practice this is often among the first findings of such an exercise. The limit: what appears is what is on the network. A cloud service someone uses exclusively over their own mobile connection will not show up.
