One Monday morning, in the middle of a closing period, Sophie B. stumbles on a harmless-looking detail: for months, one of her colleagues has been sending several clients' payroll slips through a small free file-sharing app installed on her personal phone. Nothing malicious — just faster than the internal mail system on a busy day. No one had decided it, no one had approved it, and above all no one in management knew about it. That is exactly how shadow IT takes root.
Shadow IT, the tools that slip out of the company's sight
Shadow IT means all the tools, applications and digital services used for work without management or the IT lead having chosen them, authorised them, or even noticed them. A personal email account to help a client out one evening, an online notes app, a PDF converter found on the web, a free file-sharing account, a spreadsheet parked on an employee's private cloud: each one is useful, none was ever a decision.
The term sounds a little frightening, but the phenomenon is ordinary — and usually well-meaning. Your people are not trying to break the rules: they are trying to work quickly, with tools they already use in their private lives. The problem is not bad intent, it is invisibility. What management cannot see, it can neither frame, nor protect, nor control.
For an accounting firm like Sophie B.'s, the stakes are immediate. A service business with no in-house IT relies heavily on trust: everyone gets organised with whatever is at hand. Except that the data moving around is not holiday photos — it is salaries, tax returns, bank statements belonging to dozens of client SMEs. The day one of those files lands on the free server of an app whose provider no one knows, it slips out of the company's control. And with it, part of the professional confidentiality the whole client relationship rests on.
That is where the real risk of shadow IT plays out: a data leak. Not necessarily a spectacular hack — far more often, simply a loss of control. A free account closed overnight, and the files become unreachable. The same weak password reused everywhere, and a single leak opens several doors. A service that stores documents on servers whose location you have no idea about — sometimes outside Switzerland — without your ever having signed a contract. Many free tools, in fact, are paid for with data: their terms of use, which nobody reads, often let them analyse or keep that data well beyond your use of it.
Yet the nFADP, Switzerland's revised Federal Act on Data Protection, expects a company to take "appropriate" security measures for the data it holds. It is hard to secure what you do not even know exists. Shadow IT, then, is not only a technical matter: it is a blind spot that lands squarely on your responsibility.
In plain terms. Shadow IT is not a hacker forcing the door. It is a door left ajar without anyone realising, because it was more convenient than the main entrance. The danger does not come from the tool itself — often perfectly decent — but from the fact that it lives out of your sight: no one knows who has access, where the files end up, or what remains of them the day the colleague who used it leaves the company.
What to take away
Three ideas are enough to frame the topic.
First, shadow IT is not a fault to punish, it is a signal to listen to. If a colleague works around the official tool, it is often because that tool is too slow, too complicated, or simply missing. The right response is not to sanction, but to understand the need and offer a clean alternative. Otherwise the shadow tool will come back through another door.
Second, invisibility is the heart of the problem. Data that flows through a known channel can be controlled; data that flows through an unknown one cannot. Taking back control therefore starts with seeing, even before locking anything down.
Third, for a Swiss SME handling sensitive data, the responsibility stays yours, whatever the tool. Entrusting a payroll file to a free app does not transfer that responsibility to its provider: in the event of a leak, it is your organisation that will have to deal with the consequences — and, where required, report the breach to the Swiss data protection authority (the FDPIC). A client whose data has leaked will not ask which tool was to blame: they will ask why you did not know.
The steps to put in place this week
Good news: taking back control needs no budget, no IT specialist, no major project. Three simple steps are enough to get going, and they all fit into an ordinary week, between two files.
1. Take stock, without judging
Take thirty minutes as a team and ask a single question: "which tools do you actually work with, day to day?" Not to monitor — to discover. Note every application, every service, every account used to handle company data, including those installed on personal phones. The goal is an honest list, which is only possible if no one fears a sanction. Present the exercise for what it is: not an audit, but a way to equip the team better. You will probably be surprised by how long the list is — that is normal, and it is already half the journey, because you can only properly protect what you have first set down in writing.
2. Decide what counts as "official"
For the most common needs — sharing a large file, exchanging a sensitive document, taking notes, signing a document — choose an official tool and say so clearly. In an SME already equipped with a professional office suite, most of those functions already exist, in-house, with nothing extra to install. The idea is not to ban ten tools, but to name one, simple and familiar to all, for each use. An obvious official channel makes a large share of shadow IT disappear without even having to forbid it.
3. Set one simple rule for sensitive data
A single sentence is enough, as long as everyone understands it: client data — salaries, accounting records, tax documents — never leaves the company's approved tools. No personal accounts, no unapproved free apps, no USB stick loose in a bag. Write it down, share it, repeat it to every new hire. A short, living rule protects better than a ten-page policy that no one ever opens.
Where do you really stand?
These three steps push shadow IT back, but on their own they do not answer the real question: where, exactly, is your organisation solid, and where does it still rest on habits no one has ever checked? That is the whole point of a structured self-assessment.
Cyber Passport certifies nothing and declares you "compliant" with no standard: it helps you walk through your digital practices, question by question — which tools, which data, which channels — to turn a vague unease into a clear picture you can share with your clients and auditors. The rest, meaning the detailed action plan to bring your tools under lasting control and pull shadow IT back into the light, is the subject of a dedicated blueprint.



