Shadow IT exists because the approved path for adopting a new tool is slower than a team's need for it. A marketing team wanting a design tool this week will not wait six weeks for procurement to review it — they'll sign up with a company card, and by the time IT finds out, customer assets and possibly customer data are already inside a tool nobody vetted for security or data residency.
Finding it starts with looking at expense reports and card statements for recurring software charges, which is a faster and more honest source than asking teams to self-report, because self-reporting relies on people remembering that the tool they adopted eight months ago was technically unauthorised. This is the same exercise covered in the piece on reducing subscription spend, run here for security rather than cost reasons.
Network-level visibility catches what expense reports miss — free-tier tools nobody paid for, or ones expensed by an individual rather than the company. A firewall or proxy log showing which external services employees connect to regularly surfaces tools that never appeared on any invoice.
The response that actually reduces shadow IT long-term isn't stricter enforcement, it's making the approved path faster. If a team can get a new tool vetted and approved within a few days rather than weeks, using the sanctioned process stops being the slow option, and the incentive to go around it disappears. Punishing shadow IT after the fact treats a symptom; fixing the approval bottleneck treats the cause.