SaaS Management

The Story Behind the Shadow IT Statistics

Aditi Sharma
Director, Strategy & GTM
Last Updated
February 25, 2026
8 MIn read

Ready to secure your identity surface?

About the author

Aditi leads Go-to-Market (GTM) and Business Strategy at Zluri, where she helps mid-market organizations modernize their identity governance and access management practices. Prior to Zluri, she was a Management Consultant at McKinsey & Company advising large enterprises on digital transformation, and part of the enterprise software investment team at B Capital. She holds an engineering degree from IIT Kharagpur and an MBA from Harvard Business School.

Most shadow IT roundups are fifty disconnected numbers in a row. Read them as a list and they blur together. Read them in order, and they tell one continuous story: how a single unapproved signup becomes an invisible sprawl, how that sprawl becomes real risk, and what it actually takes to see it before something forces the discovery.

A quick note on the numbers below, since the shadow IT statistics space is unusually noisy: a lot of what circulates under this topic traces back to aggregator sites recycling old survey data, sometimes years stale, occasionally uncredited or unverifiable. The figures in this piece are kept deliberately narrow, drawn from named, traceable research and real outcomes, rather than padded out with numbers that don't hold up to a second look.

Act One: The Signup Nobody Approved

The story always starts small. A team is stuck, the approved tool is too slow, too rigid, or just missing a feature someone needs today. Somebody signs up for an alternative with a work email and a free tier, no procurement, no ticket, no conversation with IT.

This isn't rare or reckless behavior, it's the default behavior of a product-led software market, and it's also become the structural norm rather than the exception. IDC research has found that roughly 70% of all application purchases now originate in business-unit budgets rather than IT's, which means the money for that signup was never going to route through IT in the first place, there was no budget line for anyone to notice it against.

SaaS vendors have spent a decade optimizing the signup flow specifically to remove every friction point between wanting a tool and having it, and IT approval was never part of that flow. Netskope's cloud security research has consistently found that the overwhelming majority of cloud application traffic inside enterprises runs through apps IT never sanctioned, a gap that exists precisely because signing up takes thirty seconds and asking permission takes a ticket queue.

One signup like this is a non-event. The story only becomes a story because it happens constantly, across every team, every week, for years.

Act Two: The Sprawl Nobody Can See

Multiply that first signup by every employee, every team, every quarter, and the result isn't a handful of extra apps. It's an environment where IT's mental model of "our software stack" and the actual software stack have quietly diverged, sometimes by an order of magnitude.

BetterCloud's State of SaaSOps research, tracking this gap across many organizations rather than one, has found that the actual number of SaaS applications running on a typical corporate network averages roughly three times what IT departments believe they have. That's not an outlier finding, it's the average, which means the gap this story is describing isn't a worst-case scenario, it's the typical case.

This gap is the part of the story that surprises people most directly, because it isn't abstract, it shows up as a specific, uncomfortable number the moment anyone actually looks. One organization, before running real discovery, believed it had a couple hundred applications in use. The actual count, once discovery ran, came back over 2,500. That's not an estimate off by a little. That's an organization operating with a picture of its own environment that was wrong by more than a factor of ten, well past even BetterCloud's already-striking 3x average.

Gartner's long-standing estimate puts a dollar figure on how much of the enterprise sits inside that gap: 30 to 40 percent of total IT spending in large enterprises, an analyst estimate rather than a direct measurement, but one that's been repeated consistently enough across years and independent research (Everest Group's own estimate runs even higher, 50 percent or more) that the range itself has become a reasonable planning assumption. Whichever number an individual organization lands closer to, the implication is the same: a meaningful share of what a company actually spends on software isn't a rounding error sitting outside the visible budget, it's a third to a half of the whole picture.

Verizon's long-running data breach research has found a similar pattern from the security side: a majority of the software and hardware connected to a typical corporate network qualifies as shadow IT, present and active, invisible to the team responsible for securing it. The sprawl isn't a future risk. It's already there, running, right now, in essentially every organization large enough to have more than one team making its own software decisions.

Act Three: What the Sprawl Actually Costs

This is where the story stops being about visibility and starts being about consequences, and they split cleanly into two kinds.

The security cost. Every app IT doesn't know about is an app nobody's reviewing, nobody's including in an offboarding checklist, and nobody's checking against a compliance requirement. A former employee's access to a shadow app doesn't get revoked when they leave, because revoking it requires knowing it exists. Data shared with a shadow app's third-party vendor is data outside the organization's actual security perimeter, regardless of what the official architecture diagram says.

The risk isn't hypothetical or distant. Gartner has estimated that organizations without a centrally managed SaaS lifecycle are roughly five times more likely to experience a data loss or security incident tied to misconfiguration, a direct, mechanical consequence of not knowing what's running well enough to configure it correctly. Set that against the broader cost of a breach once it happens, IBM's Cost of a Data Breach research has repeatedly put the average well into the millions, and the five-times multiplier stops being an abstract risk factor and starts looking like the actual gap between a bad year and a normal one.

The cost cost. Two teams paying for two tools that do the same job. A department still billed monthly for a tool three people used for one project that ended a year ago. Redundant spend doesn't announce itself as a single alarming number, it accumulates in amounts small enough to individually ignore and large enough, in total, to matter. Organizations that finally run real discovery and cleanup routinely find six-figure annual savings sitting in exactly this kind of accumulated redundancy, one recent case reclaiming $172,000 in six months purely from eliminating inactive users and optimizing licenses across a newly visible app landscape, a small fraction of the 30 to 40 percent of IT spend Act Two put a number on, made concrete for one specific organization.

Both costs trace back to the identical root cause: access and spend that exist outside anyone's active field of view.

Act Four: The Moment the Story Turns

Every organization's shadow IT story reaches the same fork eventually. Either something forces the discovery, an audit, a breach investigation, a cost review that finally asks the right question, or the organization builds the discovery capability deliberately, before being forced into it.

The forced version is expensive and stressful: finding out during an incident response that the compromised account belonged to an app nobody remembered existed, or finding out during an audit that "who has access to what" doesn't have a confident answer. The deliberate version looks different: continuous discovery that treats new, unsanctioned app adoption as a normal, expected signal to catch and evaluate, rather than a crisis to react to after the fact.

The difference between those two versions of the story isn't luck. It's whether visibility was built proactively or extracted under pressure.

How Zluri Closes the Gap Between the Two Versions

Zluri is an identity security platform for autonomous enterprises, built as four products on one platform: Identity Visibility & Intelligence (IVIP), Identity Governance & Administration (IGA) with its four modules (Access Management, Access Requests, Access Reviews, and SoD), Identity Security Posture Management (ISPM), and SaaS Management (SMP).

IVIP is built specifically for Act Two of this story, the gap between what IT thinks it runs and what's actually running. Using 8 discovery methods, including signals that don't depend on an app ever touching SSO, it surfaces the applications that individual, unapproved signups create, the exact category of access a federation-only approach never sees. SMP turns that discovery into the cost side of the story: identifying redundant tools, inactive users, and underused licenses, the same category of waste behind six-figure recovery numbers like the one above. IGA and ISPM close the loop on the security side, bringing newly discovered apps under the same lifecycle governance and continuous monitoring as everything else, so a shadow app discovered today doesn't just get logged, it gets governed.

The Numbers Were Never the Point

A list of fifty shadow IT statistics is easy to skim and easy to forget, because a list doesn't explain why any of the numbers are connected. The actual story is simpler than the list makes it look: individual signups accumulate faster than anyone tracks them, the resulting gap between believed and actual environment is often enormous, that gap carries both a security cost and a financial one, and organizations only get to choose whether they discover it on their own terms or someone else's.

Frequently Asked Questions

What percentage of enterprise IT spending is shadow IT?

Gartner's widely cited analyst estimate puts shadow IT at 30 to 40 percent of total IT spending in large enterprises; Everest Group's independent estimate runs higher, at 50 percent or more. Both are estimates rather than direct measurements of any single organization, but the consistency of the range across years and independent firms makes it a reasonable planning assumption rather than an outlier claim.

What percentage of enterprise cloud app usage is shadow IT?

Independent cloud security research, including Netskope's ongoing cloud traffic analysis, has consistently found that the large majority of cloud application activity inside enterprises runs through apps that were never formally sanctioned by IT. BetterCloud's State of SaaSOps research separately found that the actual number of SaaS applications running on a typical network averages about three times what IT departments believe they have.

Why is there such a large gap between what IT thinks it manages and what's actually running?

Because most shadow IT enters through individual or team-level signups that never generate a procurement record, an IT ticket, or any other formal trail, a pattern reinforced by the fact that IDC research puts roughly 70% of application purchases as originating in business-unit budgets rather than IT's. Each individual signup is invisible in isolation; the gap only becomes visible when an organization runs deliberate discovery, at which point the actual application count is frequently many times higher than IT's prior estimate.

What are the two main costs of unmanaged shadow IT?

Security risk and financial waste, both stemming from the same root cause: access and spend existing outside active oversight. On the security side, Gartner has estimated that organizations without a centrally managed SaaS lifecycle are roughly five times more likely to experience a data loss or security incident tied to misconfiguration. On the cost side, financial waste shows up as redundant tools, unused licenses, and forgotten subscriptions that accumulate quietly, often recoverable in six figures once an organization runs real discovery and cleanup.

How do organizations typically discover the true scale of their shadow IT?

Either reactively, through an audit, a security incident, or a cost review that forces the question, or proactively, through continuous discovery tools built to surface unsanctioned application usage as it happens rather than waiting for an external trigger. The proactive path is generally far less costly and disruptive than the reactive one.

Can shadow IT ever be a net positive for an organization?

Individual instances sometimes surface genuinely useful tools that later get formally adopted; product-led growth exists partly because bottom-up tool discovery does occasionally find something better than the sanctioned option. But this potential upside doesn't offset the risk of the aggregate, ungoverned pattern, which is why the goal for most organizations is visibility and governance rather than elimination, evaluating what's discovered rather than assuming all of it should be blocked.

Ready to secure your identity surface?