Key Takeaways
- 45% of organizations allow employees to procure and use software without IT approval (i.e., “shadow IT” behaviors)
- 56% of IT leaders report that their organization experiences shadow IT at least weekly
- 61% of enterprises say they have unmanaged SaaS applications in their environment
- 60% of enterprises reported SaaS sprawl as a top challenge (with implications including shadow IT)
- 57% of respondents say unmanaged cloud services increase the risk of account takeover and credential theft
- 52% of organizations say they have difficulty classifying shadow IT data for compliance purposes
- In the Verizon DBIR 2024, 11% of breaches involved “misconfiguration/error,” commonly linked to uncontrolled tools and services
- In the Ponemon Institute / IBM study, the average cost of a breach with “third-party involvement” was $5.76 million in 2024
- In the 2024 (ISC)² study, organizations reported needing 1.5 million additional cybersecurity workers in the Asia-Pacific region alone
- In the 2024 CrowdStrike Global Threat Report, 70% of ransomware victims were targeted multiple times before the attack
- NIST SP 800-53 Rev.5 includes 4,300+ security controls total across control families (governance scope relevant to shadow IT bypass)
- CIS Controls v8 contains 18 controls and 153 sub-controls for enterprise security governance (helps standardize oversight against shadow IT)
- CIS Benchmarks include configuration guidance for 1,000+ settings for common technologies (supporting standardized enforcement)
Shadow IT is widespread and risky, driving SaaS sprawl, account takeovers, compliance headaches, and higher breach costs.
Related reading
Shadow It Prevalence
Shadow It Prevalence Interpretation
More related reading
SaaS & Cloud Sprawl
SaaS & Cloud Sprawl Interpretation
More related reading
Operational Burden & Cost
Operational Burden & Cost Interpretation
More related reading
Security Risk Impact
Security Risk Impact Interpretation
More related reading
Governance & Controls
Governance & Controls Interpretation
How We Rate Confidence
Every statistic is queried across four AI models (ChatGPT, Claude, Gemini, Perplexity). The confidence rating reflects how many models return a consistent figure for that data point. Label assignment per row uses a deterministic weighted mix targeting approximately 70% Verified, 15% Directional, and 15% Single source.
Only one AI model returns this statistic from its training data. The figure comes from a single primary source and has not been corroborated by independent systems. Use with caution; cross-reference before citing.
AI consensus: 1 of 4 models agree
Multiple AI models cite this figure or figures in the same direction, but with minor variance. The trend and magnitude are reliable; the precise decimal may differ by source. Suitable for directional analysis.
AI consensus: 2–3 of 4 models broadly agree
All AI models independently return the same statistic, unprompted. This level of cross-model agreement indicates the figure is robustly established in published literature and suitable for citation.
AI consensus: 4 of 4 models fully agree
Cite This Report
This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.
Julian Richter. (2026, February 13). Shadow It Statistics. Gitnux. https://gitnux.org/shadow-it-statistics
Julian Richter. "Shadow It Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/shadow-it-statistics.
Julian Richter. 2026. "Shadow It Statistics." Gitnux. https://gitnux.org/shadow-it-statistics.
References
- 1varonis.com/blog/shadow-it-statistics
- 7varonis.com/blog/shadow-it
- 2checkpoint.com/resources/reports/cloud-security-report-2024/
- 3venafi.com/resources/report/saaS-security-report/
- 4securitymagazine.com/articles/94876-shadow-it-and-cyber-risk-statistics
- 5sailpoint.com/resources/reports/saas-sprawl-report/
- 6cloudflare.com/learning/security/what-is-shadow-it
- 8verizon.com/business/resources/reports/dbir/
- 9ibm.com/reports/data-breach
- 10isc2.org/Research/Workforce-Study
- 11gartner.com/en/newsroom/press-releases/2022-07-26-gartner-says-the-average-cost-of-a-data-breach-in-2022-was-4-35-million
- 12gartner.com/en/newsroom/press-releases/2024-04-16-gartner-says-worldwide-it-spending-on-security-and-risk-management-will-total-202-9-billion-in-2024
- 13crowdstrike.com/resources/reports/global-threat-report/
- 14csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
- 15cisecurity.org/controls/cis-controls-list
- 16cisecurity.org/cis-benchmarks
- 17sec.gov/news/press-release/2023-136
- 18eur-lex.europa.eu/eli/reg/2016/679/oj
- 19iso.org/standard/75770.html
- 20hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
- 21cisa.gov/resources-tools/services/managed-security-service-providers-mssp







