Governance Risk in Digital Collaboration: What It Is and How to Manage It
Governance risk in digital collaboration covers shadow IT, WhatsApp and Signal at work, and access control. See the risks and how to reduce them.
Shadow IT is any tech used without IT's approval. Learn what causes it, the security risks it creates, and how to manage it at your company.
Since all these apps typically fall entirely outside enterprise management, using them makes it nearly impossible for a security team to maintain compliance and safety.
Employees use personal Google Drive, Dropbox, or similar accounts when the company’s approved file-sharing process feels restrictive. According to our State of Secure Collaboration report:
But the issue can extend beyond the original upload because those files can be copied, downloaded, shared again, or left in a personal account after the employee leaves the organization. In fact, our survey found 61% say access to shared files remains active longer than intended, at least sometimes after a project ends. IT teams may have no reliable way to revoke access or determine who still has a copy when employees use multiple tools.
There is now a SaaS application for every type of work your employees do. These can be project management tools, productivity apps, design software, and workflow automation platforms, all of which make up a large share of shadow IT applications, largely because so many of them are free, low-cost, or offer generous trial periods that require nothing more than a work email address to activate.
A single employee or team adopting one of these tools might seem low risk on its own, but across a large organization, this pattern can compound into dozens or hundreds of unmanaged subscriptions, each with its own data-handling practices and security posture that nobody in IT has reviewed. But that doesn’t mean you should not encourage employees to try out new tools that might increase their efficiency. We’ll discuss more about balancing innovation with shadow tools management later in the blog.
This involves employees using personal laptops, smartphones, email addresses, or accounts for company work without appropriate controls. When we surveyed IT security and compliance leaders, we found that 75% use email as their primary method of external collaboration! Meanwhile, only 28% use dedicated secure tools externally.
This can be particularly easy with remote teams, where employees work outside the corporate office and may have company and personal devices within reach. For example, a remote employee may use their personal laptop when their work device is unavailable or email a document to a personal account so they can access it from another device. In both cases, company data moves outside normal security, retention, access, and offboarding processes.
Bring-your-own-device (BYOD) arrangements can make this manageable when they're properly governed, but in practice, many organizations end up with a meaningful volume of corporate data flowing through devices and accounts their security team has never configured or monitored.
The newest and fastest-growing form involves employees entering company information into generative AI tools that haven't been vetted or approved. This might look like pasting a contract into a public chatbot to summarize it, or feeding proprietary code into an AI coding assistant for debugging help.
The risk here differs from older forms of shadow applications, since data entered into a public model can (depending on the tool's data-handling terms) become part of that model's training data or otherwise persist somewhere the organization has no visibility into or control over.
Shadow IT usually happens when employees need a faster or easier way to get their work done. They may turn to unauthorized tools when approved technology lacks the functionality they need, creates too much friction, or takes too long to access.
Sometimes the sanctioned tool genuinely lacks a feature a team depends on, or it was selected for one part of the business and doesn't fit another. For example, an employee may need to communicate with an external organization, collaborate on a particular file type, automate a repetitive task, or access a specialized capability that the approved applications do not provide.
If the requirement occurs regularly, employees may eventually find their own solution.
Repeated use of new, unapproved applications can therefore reveal gaps in the technology, and IT teams should investigate which tasks employees are trying to complete and why sanctioned tools aren't supporting them.
The shift to remote and hybrid work has made it considerably easier for employees to adopt tools without anyone noticing. When most collaboration happens outside a shared office, there's less informal visibility into which applications a colleague has open, and that can make shadow tools harder to identify because the organization may never see a traditional software installation.
If an approved application requires several authentication steps, works poorly on mobile devices, makes external collaboration difficult, or requires employees to move between several disconnected applications, a familiar consumer product can become an attractive shortcut.
Communication is particularly sensitive to this problem because people expect messaging to be immediate. For example, if bringing a new employee into the approved collaboration platform requires a lengthy administrative process, the team may simply message them through WhatsApp.
IT teams need to understand how applications handle data, what permissions they require, how they integrate with existing systems, and whether they meet governance requirements.
However, employees may be trying to solve a problem that exists today. If requesting a relatively simple application requires weeks of approvals with little visibility into the process, employees may create their own account instead.
This is one of the main reasons for shadow IT because your team members already know how to create a WhatsApp group, upload something to Google Drive, or start a video call in a consumer application. There is no need for training, and external partners may also already use the same service.
Enterprise security teams must account for this ease of use when selecting sanctioned tools. An application can meet an extensive list of security requirements and still fail to reduce shadow software if employees find it unnecessarily difficult to use.
The main risks of shadow IT include loss of visibility, data leakage, inconsistent access controls, an increased attack surface, and noncompliance.
An organization typically maintains an inventory of the applications and systems that store or process its information. Security teams can evaluate those systems, configure appropriate controls, monitor access, and respond when something goes wrong. Unsanctioned applications create gaps in that inventory.
IT may not know what external tools contain company information, who has accounts, how those tools connect to other systems, or whether external users still have access. That makes every subsequent governance task more difficult.
Employees can upload sensitive information about customer data, contracts, intellectual property, credentials, employee information, and internal conversations into shadow applications.
For example, someone at your company may upload confidential files to a personal storage account and share them via a public link. Even if the underlying service provides strong security controls, the organization does not control how the employee configures or shares the data. It increases the risk of data leakage or access by someone who shouldn't have it.
Most companies have a system for managing who has access to their systems. They may use tools like single sign-on, SCIM provisioning, and multi-factor authentication to ensure security.
However, unapproved consumer tools can bypass these security controls, so access isn't automatically revoked when an employee changes roles or leaves the company. A former employee retaining access to a shadow file-sharing account months after departure is a common and often overlooked version of this problem.
Regulations including GDPR, HIPAA, and the EU's NIS2 Directive require organizations to demonstrate control over how data is stored, accessed, and retained. When conversations or files exist inside unsanctioned tools, producing an accurate audit trail becomes difficult or impossible, which can create serious liability risks for your company.
One of the main risks of using unsecured shadow tools is increasing the attack surface of the organization while having no security control over it. Every additional application, account, integration, and device creates another potential route to organizational information.
As part of cyber resilience, approved technology is usually assessed and managed as part of the organization’s broader security program. Shadow applications may never receive the same review. So a forgotten SaaS account or unmanaged integration can remain connected to company information long after the employee who created it stops using it, increasing the risk of security attacks.
Information stored in personal accounts or third-party apps often outlives the project or the employment relationship that created it, creating additional risks. This is especially risky if your organization is part of critical national infrastructure.
When teams independently adopt overlapping SaaS subscriptions without visibility into what other departments are already paying for, the organization ends up carrying redundant costs.
You can detect unauthorized tools and platforms within your organization by maintaining an inventory of approved applications, monitoring network usage, reviewing identity and access activity, and by simply talking to employees.
Once you’ve detected unapproved tools at your company, the solution isn’t to simply ban everything. As we mentioned, in most cases, employees use other tools for productivity rather than harm. Read on to see how you can manage this effectively without hampering employee productivity.
Managing shadow IT risks requires discovering unauthorized tools, improving approved software options, educating employees about the risks, and setting clear governance rules.
When you discover an unauthorized application, investigate the business requirement before deciding how to respond. Find out what the application is being used for, which teams depend on it, what information it contains, and why existing tools were insufficient. The answer can determine whether you should block the application, approve it formally, replace it, or improve an existing sanctioned platform.
For instance, you may discover employees using WhatsApp (which has end-to-end encryption risks) for communication and file sharing because doing so in the current messenger is complicated. So you may decide to choose an alternative enterprise communication solution like Wire that offers E2EE across messaging, calls, conferencing, and file sharing while providing an intuitive user interface.
Employees need to know what technology they can use for work and how to request something new.
Your shadow IT policy should explain:
Once this is in place, the next step is to make software approval easier while maintaining security.
For this step, you can create different review paths based on risk. For instance, a collaboration software that processes sensitive customer information may require a detailed security assessment, while a lower-risk application may qualify for a faster review. Clear timelines also help since employees are less likely to bypass IT when they know who is reviewing the request and when they can expect a decision.
Where possible, approved applications should integrate with the organization’s identity and access management processes.
Relevant controls can include:
Centralized identity controls help IT manage access throughout the employee lifecycle and reduce the number of independent accounts employees need to maintain.
As part of your security training, explain to employees the risks of sharing company information outside approved applications, as it increases the risk of phishing and cyberattacks significantly.
Moreover, shadow IT incidents can spike right after a security breach because during an active incident, employees still need to coordinate, and they'll reach for whatever channel is fastest and most familiar in the moment. Under pressure, that channel is very often a consumer app already installed on their phone, precisely at the moment when sensitive coordination about the incident itself matters most.
Learn more about how you can avoid this in our detailed article about business continuity. Or, see how you can create an effective incident response plan.
On a typical workday, employees text, join video or voice calls, or share files with colleagues or external partners. But when they have to switch between applications for each of these tasks, it increases the risk of shadow applications.
While popular messengers like MS Teams or Slack provide collaboration features, you also have to consider the level of security they offer for each. For instance, MS Teams doesn’t offer E2EE for group calls, while Slack doesn’t provide post-compromise security and perfect forward secrecy.
Giving teams a single, secure environment for messaging, meetings, file sharing, and external collaboration like Wire removes much of the practical reason to look elsewhere.
A tool that met your requirements two years ago may not be the right choice today. Your security needs change, new risks may emerge, and vendors themselves evolve. Some continue investing in security and usability, while others may not keep pace with what your organization needs.
For example, new AI integrations can change how data moves through an existing tool and introduce risks that weren't there when you first approved it. We recently looked at this in our analysis of the OpenAI Apple Messages plugin. At the same time, some tools can also become more capable over time. For instance, Wire recently introduced enterprise content replication to support secure communication across isolated networks, ensuring data remains current and compliant.
Wire specifically helps organizations address two common areas where shadow IT develops: communication and file collaboration.
Employees can use Wire for messaging, calling, conferencing, and file sharing within an enterprise-controlled environment. Wire Drive offers file management, helping employees keep communication and related content inside the secure collaboration platform rather than moving files into personal storage accounts or other unofficial services.
For both communication and collaboration, Wire offers:
Wire is designed to give employees a collaboration environment they can use for everyday work while giving IT and security teams the governance they require.
This also becomes important during incidents. Wire can be deployed as a secure, out-of-band communication channel so response teams have a predefined alternative if their primary collaboration platform becomes compromised or unavailable.
For organizations trying to reduce shadow communication and unmanaged file sharing, the objective is straightforward: provide a secure, governed environment that employees can realistically use for the work they already need to do.
See how Wire can help your organization keep sensitive communication and file collaboration inside a secure, governed environment. Request a demo with our experts.
Governance risk in digital collaboration covers shadow IT, WhatsApp and Signal at work, and access control. See the risks and how to reduce them.
Learn what HIPAA-compliant texting actually requires, why standard SMS and consumer apps fall short, and how to evaluate a compliant messaging...
Evaluating enterprise messaging platforms? Most don't offer true E2EE. Discover what security-first organizations look for and how Wire is built...