
SaaS risk and shadow IT: what IT does not see in your SMB
Inventory of unapproved SaaS, data risk, and governance without blocking productivity.
Employees at Puerto Rico SMBs register Notion, Canva Pro, ChatGPT Plus, and personal file sharing with client data — shadow IT IT does not see until audit or breach. SaaS risk management is not block everything; it is inventory, classification, and guardrails enabling safe productivity. OWASP does not cover shadow IT directly, but data exposure via third-party SaaS is real vector documented on Krebs on Security.
Discovery: SSO logs (if exists), expense reports, DNS/firewall analytics (Cloudflare, Zscaler), honest department interviews. Quarterly shadow IT inventory — approved vs discovered SaaS. Classify by data sensitivity: marketing tools low tier; HR/payroll critical tier.
Pragmatic governance: self-service catalog of pre-approved SaaS, lightweight 48h exception process for new tool, ready DPA template. Block is not default — guide is default. Mainland companies with PR subsidiaries need consistent cross-border data policy.
Technical controls: lite CASB or M365/Google SaaS app discovery, block unauthorized app OAuth on corporate tenant, email DLP for PHI/PCI outbound to personal cloud. Bruce Schneier notes total prohibition generates evasion — channel legitimate need.
SaaS incident response: vendor breach notification terms, data export if canceling tool, continuity if vendor disappears. NIST privacy framework helps evaluate third-party data risk. Puerto Rico SMBs compete for talent — shadow IT sometimes signals gap in approved tools; listen and formalize.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


