The Shadow IT Episode
Transcript
Introduction to the Guest and Topic:
Host Allie Krings introduces John Burkhart, a Senior Information Security Auditor at KirkpatrickPrice. The conversation focuses on Shadow IT, citizen development, and the risks and opportunities that come from employees building their own applications outside of traditional IT processes. John shares his background, explaining that his career includes leadership roles in healthcare, manufacturing, consulting, application deployment, and cybersecurity, giving him extensive experience managing large enterprise systems and security programs.
What Is Shadow IT?:
Shadow IT refers to technology solutions, applications, or development efforts that are created and used outside of an organization’s formal IT governance processes. This often occurs when employees or departments need to solve a business problem quickly and use tools such as Power BI, low-code platforms, AI-assisted development tools, or custom applications without going through traditional IT channels.
These solutions are usually created with good intentions and often solve real business problems. However, they can introduce security, compliance, and operational risks when they operate without oversight.
What Is a Citizen Developer?:
John suggests reframing the term “Shadow IT” and instead using “Citizen Developer.”
A citizen developer is a business user outside of the IT department who builds applications, reports, workflows, or automation tools to solve business problems. Citizen developers often leverage low-code and no-code platforms to create solutions quickly and efficiently without extensive formal development experience.
What Does Shadow IT Look Like Up Close?:
For Business Departments:
Departments such as Finance, HR, Sales, and Operations often create their own applications or reporting tools to solve immediate business challenges. These solutions help teams move quickly and gain insights without waiting for lengthy IT development cycles.
For IT Departments:
IT teams may be unaware that these applications exist. As a result, systems can operate without security reviews, formal testing, documentation, or support structures. This lack of visibility creates risk for the organization.
What Are the Biggest Gaps in Compliance?:
One of the biggest gaps is governance. Applications are created outside of established development processes, meaning there may be no documentation, testing, version control, ownership, or security oversight.
Another major gap is data visibility. Organizations often do not realize where sensitive information is being stored, processed, or transmitted when citizen-developed applications operate outside of approved systems.
How Can Shadow IT Create Security Risks?:
Shadow IT often involves production data being exported into tools that IT may not know exist. Because these tools are frequently outside established security controls, organizations may accidentally expose:
- Healthcare information
- Customer information
- Financial records
- Social security numbers
- Proprietary business information
John highlights examples where improperly governed applications exposed sensitive data publicly, resulting in significant security and privacy incidents.
Why Does Shadow IT Happen?:
The primary driver is speed.
Business users often need answers, reporting, or automation immediately. Traditional IT development may involve requirements gathering, testing, deployment cycles, governance reviews, and competing priorities.
Citizen development tools allow users to solve problems quickly without waiting for those formal processes. While this provides value, it also bypasses important safeguards.
How Can Organizations Identify Shadow IT?:
Perform Application Inventories
Review software and platforms being used throughout the organization and compare them against approved IT inventories. Unexpected applications often reveal shadow IT activity.
Analyze Data Flows
Track where data is moving, how it is processed, and what systems are receiving or sending information. Unexpected data movement may indicate undocumented applications.
Review APIs and Integrations
Examine application interfaces and integrations to understand how systems are communicating. Hidden integrations may reveal shadow development activity.
Interview Business Leaders
Conversations with department managers often uncover internally built tools that were never formally reviewed by IT.
What Makes Citizen Development Healthy vs. Risky?:
Healthy Citizen Development
Citizen development becomes beneficial when:
- Leadership is aware of it
- Governance exists
- Security controls are applied
- Training is provided
- Applications are inventoried and documented
- IT participates in oversight
These programs allow innovation while maintaining security and compliance.
Risky Citizen Development
Problems arise when:
- Applications remain hidden
- Production data is used without approval
- No security reviews occur
- No one owns the solution
- Data leaves the organization unknowingly
- Documentation does not exist
These situations can create significant compliance and security challenges.
How Can Organizations Support Citizen Developers Without Limiting Innovation?:
Organizations should avoid simply shutting down citizen development efforts.
Instead, they should:
- Make development efforts visible
- Establish governance structures
- Create security guardrails
- Provide training
- Define ownership responsibilities
- Build Centers of Excellence for citizen developers
- Offer approved tools and standards
John emphasizes that citizen development can be highly valuable when managed correctly and should be encouraged rather than suppressed.
What Should Organizations Do During Their First 90 Days of Addressing Shadow IT?:
Inventory Existing Applications
Identify all known citizen-developed applications, tools, workflows, and reports.
Identify Data Usage
Determine which applications handle sensitive, regulated, or critical business data.
Evaluate High-Risk Systems
Pause and assess citizen-developed solutions that directly impact customers, production systems, external websites, or sensitive information.
Establish Governance
Begin implementing development standards, testing requirements, naming conventions, version control, and security reviews.
How Can Companies Ensure Compliance?:
Compliance begins with awareness. Organizations should acknowledge that citizen development already exists and then bring those activities into a structured governance model.
The most successful organizations:
- Make shadow IT visible
- Train citizen developers
- Implement security guardrails
- Maintain inventories
- Monitor data movement
- Require testing and documentation
- Provide governance and oversight
Rather than eliminating citizen development, organizations should transform it into a managed and supported capability that delivers business value while maintaining security and compliance.
Final Thoughts:
John emphasizes that shadow IT exists because employees are trying to solve real business problems. The goal should not be to stop innovation but to support it through visibility, training, governance, and proper security controls.
When organizations recognize citizen developers as valuable contributors and provide the right framework around them, they can balance rapid innovation with strong cybersecurity and compliance practices.
Notes
In this episode, host Allie Krings sits down with John Burkardt to explore the growing challenge of Shadow IT, or Citizen Developers, and why it’s becoming a major concern for organizations. As employees adopt new software, AI tools, and applications to solve business problems faster, many companies find themselves with technology operating outside of established oversight and governance processes.
John explains that Shadow IT isn’t always bad. In many cases, it starts with employees looking for more efficient ways to work. The real challenge comes when those tools and applications are unknown to leadership, unmanaged by IT, or create security and compliance risks. The conversation covers AI coding tools, unauthorized software, the importance of visibility, and how organizations can support innovation without creating a “Wild West” environment.
At KirkpatrickPrice, we’re on a mission to help 10,000 organizations raise the bar for cybersecurity and compliance. Join Our Cybersecurity Mission. If you’re going to invest in an audit, it should deliver real value. That’s why we partner with you from audit readiness to final report, ensuring you get the assurance you deserve.
Ready to strengthen your security and compliance posture? Connect with an expert today and learn how we can help you meet your toughest goals.
Send a Question
Do you have a question for our podcast? Send it to us here.
