In this blog, we will discuss how Shadow IT can create security gaps outside a CERT-In audit scope, how businesses can identify unapproved applications and APIs, and how these assets can be brought into security testing and audit documentation.
What Is Shadow IT in the Context of a CERT-In Security Audit?
Shadow IT refers to applications, cloud services, APIs, and other technology used by employees or teams without being formally approved or recorded by the organisation. When these assets are not included in the organisation’s asset inventory, they may also remain outside the defined security audit scope.
1. Unapproved Cloud Applications
Employees may use cloud applications for file sharing, project management, communication, or other work without informing the security team. These services may handle business information without being included in security assessments.
2. Employee-Used SaaS Platforms
Teams may sign up for SaaS platforms to support daily work. If these services are not reviewed and recorded, the organisation may not know what information is being shared or what security controls are in place.
3. Personal Cloud Storage
Employees may use personal storage accounts to save or transfer business files. This can create problems when sensitive information is stored outside systems managed by the organization.
4. Unregistered APIs and Integrations
Teams may connect applications through APIs, webhooks, or third-party integrations without updating the central asset inventory. These connections can create additional points where data enters or leaves the organization.
5. Unmanaged Software and Tools
Unapproved software installed on business systems may not receive security updates or follow the organisation’s security requirements. Such tools can also remain outside regular security testing.

Why Shadow IT Can Fall Outside the CERT-In Audit Scope?
An audit is performed against a defined scope. If an application, API, cloud service, or other asset is not identified during scope preparation, it may not be included in the assessment.
1. Assets Missing from the Application Inventory
If an asset is missing from the inventory, the audit team may not know that it needs to be assessed.
2. Services Not Included in the Audit Scope
A business may use several services while the audit covers only specific applications or systems. Services outside that scope may remain untested.
3. Unknown Internet-Facing Systems
An application or service exposed to the internet can create a security concern if it is not known to the security team and is therefore not considered during testing.
4. Unreported Third-Party Integrations
A new payment service, SaaS platform, API, or external integration can change the application’s data flow without appearing in the existing audit documentation.
5. Applications Added After the Audit
An application introduced after the assessment will not normally be covered by an earlier report unless it is specifically added through a follow-up assessment.
How Can Shadow IT Create Security Gaps?
Shadow IT can create security gaps when systems are not managed, updated, configured, or tested according to the organisation’s security requirements.
1. Unpatched Applications
Unmanaged applications may miss important security updates, leaving known vulnerabilities unresolved.
2. Weak Authentication
Some services may use weak passwords or lack stronger authentication controls, increasing the risk of unauthorized access.
3. Excessive User Permissions
Users may receive more access than required, allowing them to view or modify information beyond their work responsibilities.
4. Exposed APIs
Unregistered APIs may expose application functions or information without being included in regular security testing.
5. Misconfigured Cloud Storage
Incorrect permissions on cloud storage can make business files accessible to unintended users.
6. Unprotected Sensitive Data
Business or customer information stored in unapproved services may not receive the same security controls as information stored in approved systems.
7. Unknown Internet-Facing Services
Unidentified systems accessible from the internet can provide an entry point that the security team has not assessed.
How Can Shadow APIs Create Risks Outside the Audit Scope?
APIs created or connected without proper tracking can introduce additional data flows and application functions that may not be covered by an existing audit.
1. Undocumented API Endpoints
Endpoints that are not recorded in the API inventory may remain outside regular security testing.
2. Unapproved Third-Party Connections
An application may exchange information with an external service without the connection being reviewed by the security team.
3. Weak API Authentication
An API without appropriate authentication controls may allow unauthorized users or systems to access its functions.
4. Missing Authorization Controls
Even authenticated users should only be able to access the data and functions assigned to them. Missing authorization checks can allow broader access.
5. Excessive API Data Exposure
An API may return more information than the user or application needs, increasing the amount of sensitive data that could be exposed.
6. Unmonitored API Traffic
If API activity is not properly monitored, unusual access or unexpected data transfers may be harder to identify.
Can Shadow SaaS Applications Expose Business Data?
Yes. SaaS applications can handle business information, customer records, documents, credentials, and other sensitive data. If these platforms are not approved or reviewed, the organization may have limited visibility into how that information is protected.
1. Customer Data Stored in Unapproved Services
Customer information uploaded to an unapproved SaaS platform may not receive the same security controls as data stored in approved systems.
2. Business Files Uploaded to Personal Accounts
Employees may transfer business documents to personal accounts for convenience, creating additional access and storage risks.
3. Sensitive Data Shared with External Platforms
Information sent to third-party services can create new data-sharing relationships that should be reviewed and documented.
4. Weak Access Controls on SaaS Accounts
Poor account configuration or excessive permissions can allow users to access information they do not need.
5. Former Employee Access
If SaaS accounts are not connected to the organisation’s employee access process, former employees may retain access after leaving.
6. Unclear Data Retention
Businesses may not know how long information remains stored in an unapproved service or how it is removed when no longer required.
How Does Shadow IT Affect CERT-In Audit Evidence?
Shadow IT can affect the accuracy of audit evidence when applications, APIs, cloud services, or other assets are not included in the defined assessment scope. If these assets are missing from the inventory, the audit report may not represent the organisation’s current technology environment.
1. The Audit Report May Not Cover the Unapproved Asset
An application or service that is not part of the agreed audit scope may not appear in the security assessment or its final report.
2. Vulnerabilities May Remain Outside Testing
If an unapproved system is not identified, security weaknesses in that system may not be tested or reported.
3. Security Controls May Not Be Verified
Authentication, access control, encryption, logging, and other controls may remain unchecked when an asset is outside the assessment scope.
4. Asset Inventory May Become Incomplete
Shadow IT can make the official asset inventory inaccurate by leaving out applications, APIs, cloud services, or integrations that are being used.
5. Audit Findings May Not Reflect the Current Environment
When the technology environment changes after an audit, older findings and evidence may no longer represent the current application scope.
CERT-In guidance states that audit reports should include details about the audit scope, limitations, exemptions, and methodology. Accurate asset identification therefore helps ensure that audit evidence matches the systems being assessed.
How Can Businesses Identify Shadow IT Before a CERT-In Audit?
Finding unapproved technology before an audit can help businesses build a more complete view of their environment and review whether additional systems need to be assessed.
1. Review Cloud and SaaS Usage
Identify cloud and SaaS services being used by different teams and check whether they are approved and recorded.
2. Identify Unknown Internet-Facing Assets
Review internet-facing domains, applications, servers, and services to find systems that may not appear in the official inventory.
3. Review DNS and Subdomains
Check DNS records and subdomains for applications or services that may have been added without being documented.
4. Check API and Integration Inventories
Compare known APIs and integrations with the current application architecture to identify missing entries.
5. Review User-Installed Software
Identify software installed on business systems that has not gone through the organisation’s approval process.
6. Compare Assets With the Official Inventory
Match discovered applications, cloud services, APIs, and infrastructure against the organisation’s approved asset list.
7. Review Third-Party Connections
Identify external platforms that exchange data with business applications and confirm whether these connections are documented.
How Can Shadow IT Be Included in Security Testing?
Once an unknown asset is identified, the business should determine whether it needs to be added to the security assessment scope.
1. Update the Asset Inventory
Add confirmed applications, APIs, cloud services, and other relevant systems to the inventory.
2. Identify Newly Discovered Applications
Review each discovered application to understand its purpose, users, data, and exposure.
3. Review New APIs and Integrations
Document APIs, webhooks, payment services, and other external connections linked to the application.
4. Assess Internet-Facing Assets
Determine whether newly discovered systems are accessible from the internet and require security testing.
5. Define Testing Requirements
Select the appropriate security assessment based on the type and importance of the asset.
6. Update the CERT-In Audit Scope
Discuss changes with the CERT-In empanelled auditor and update the agreed scope where required.
7. Perform Follow-Up Testing After Major Changes
Conduct additional testing when significant application or infrastructure changes affect the previously assessed environment.
CERT-In guidance recommends audits after changes in infrastructure and applications and periodic audits based on the criticality of cyber assets.
What Should Businesses Do When Shadow IT Is Discovered?
Discovering Shadow IT should be followed by a review of ownership, data, access, and security controls.
1. Identify the Asset Owner
Determine which team or individual is responsible for the application, service, or integration.
2. Determine What Data the Asset Handles
Check whether the asset stores or processes customer, employee, financial, or other sensitive information.
3. Review Its Security Controls
Assess authentication, authorization, access permissions, configuration, logging, and other relevant controls.
4. Remove Unnecessary Access
Disable unused accounts, permissions, applications, or connections that are no longer required.
5. Add Approved Assets to the Inventory
Record approved systems in the organisation’s central asset inventory.
6. Include Relevant Assets in Security Testing
Where appropriate, include the discovered asset in VAPT or other security assessments.
7. Update Audit Documentation
Update relevant scope documents and audit evidence so they reflect the current application environment.
Why Should Shadow IT Be Considered During CERT-In VAPT?
Shadow IT matters during VAPT because security testing depends on knowing which applications, APIs, infrastructure, and services are included in the assessment.
1. Unknown Assets May Remain Untested
An asset that is not identified may not be included in VAPT.
2. Unapproved APIs Can Create New Attack Paths
Undocumented APIs may provide access to application functions or sensitive information without being tested.
3. SaaS Services Can Handle Sensitive Information
Unapproved SaaS platforms may store or process business and customer data outside the systems covered by the assessment.
4. Cloud Misconfigurations Can Expose Data
Unmanaged cloud resources can contain incorrect access permissions or other configuration issues.
5. Application Changes Can Affect Audit Scope
New applications, APIs, integrations, and infrastructure can change the systems that need to be considered during an assessment.
6. Complete Asset Visibility Supports Accurate Audit Scope
Maintaining an updated asset inventory helps businesses and auditors understand what needs to be included in security testing and supporting audit evidence.
Conclusion
Shadow IT can create security gaps when applications, APIs, cloud services, or software are used without being added to the organisation’s asset inventory and audit scope. Regular asset discovery, change tracking, and security testing can help businesses identify these systems and decide whether they need to be included in a CERT-In security assessment.
Enjoyed the read? There’s more to explore!
Stay curious, stay informed, and keep coming back to the Peneto Labs Blog for more insights, ideas, trends, and expert perspectives on Cybersecurity. Check back soon for our latest blogs!