What is shadow app? - Definition from WhatIs.com
Part of the Network security glossary:

A shadow app is a software program that is not supported by an employee's information technology (IT) department.

In the past, shadow apps were often installed locally by impatient employees who wanted immediate access to software without going through normal corporate channels. With the growth of software-as-a-service (SaaS) and cloud computing, however, the meaning has expanded to include third-party consumer software that is accessed over the Internet.

Skype, Lucidchart, Dropbox, Google Spreadsheets, Docusign and CloudOn are all popular shadow apps. Although many shadow apps can improve productivity and collaboration with little or no financial cost to the company, their use comes with risks. If an employee accesses a cloud app with his personal account, for example, corporate data may be put at risk or even lost if the employee leaves the company. Shadow apps can also cause bandwidth issues on the corporate network, slowing things down and impacting everyone's productivity.

To prevent problems, an IT department should have a service audit process in place to inspect outbound packets and verify ownership of company-owned services in the cloud. The organization should also have policy in place that requires employees to use corporate accounts for web-based applications and restrict network privileges so end users cannot install software locally. If a large group of employees is using a particular cloud app, the IT department should consider providing the service in house and finally, the IT department should educate employees about the value of corporate data and the risks that shadow apps present.

See also: shadow IT, rogue IT

This was last updated in August 2014
Contributor(s): Matthew Haughn
Posted by: Margaret Rouse

Related Terms


  • going dark

    - The going dark problem, as described by the FBI, is the Bureau’s inability to access legally intercepted communications and information because of the encryption technologies used for data privacy ... (WhatIs.com)

  • threat actor

    - A threat actor is an entity that is partially or wholly responsible for an incident that impacts – or has the potential to impact -- the security of an organization. (WhatIs.com)

  • threat intelligence service (TI service)

    - A threat intelligence service (TI service) is a provider of information about current or emerging threats that could negatively impact the security of a customer’s organization. (WhatIs.com)


  • Network security

    - Terms related to network security, including definitions about intrusion prevention and words and phrases about VPNs and firewalls.

  • Internet applications

    - This WhatIs.com glossary contains terms related to Internet applications, including definitions about Software as a Service (SaaS) delivery models and words and phrases about web sites, e-commerce ...

Ask a Question About shadow appPowered by ITKnowledgeExchange.com

Get answers from your peers on your most technical challenges

Tech TalkComment



    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.