# Shadow IT Discovery for Security

*/Opportunities/Shadow_IT_Discovery_for_Security*

## Opportunity Overview

**Wedge**: Target corporate finance and expense platforms to identify expense-expensed SaaS as the primary discovery vector. This approach bypasses IT gatekeepers, delivering immediate shock-value to security leaders by revealing exactly what employees buy on company cards. Expand from expense-based discovery into OAuth token analysis via Google Workspace, and eventually into automated vendor risk assessments and access revocation.
**Timing**: Widespread adoption of product-led growth SaaS and generative AI tools routinely bypasses traditional IT procurement. Concurrently, API access to corporate financial systems and identity providers enables zero-install discovery methods to ingest disparate signals into a unified security graph.
**Why This I C P**: Mid-market organizations experience high employee autonomy and massive SaaS sprawl but lack the dedicated security headcount required to deploy enterprise-grade monitoring. They face acute compliance risks but demand zero-friction, fast-deployment tools.
**Size Of Prize**: Approximately 35,000 mid-market organizations in the US employ between 500 and 5,000 workers. Each spends roughly $20,000 annually on manual shadow IT audits and disjointed SaaS management tools, yielding an addressable prize of $700M.
**Gap Narrative**: Mid-market security teams lack visibility into employee-procured SaaS applications. Existing Cloud Access Security Brokers require heavy network-level integration, leaving a blind spot for browser-based, self-serve applications purchased via corporate cards. These teams need a lightweight mechanism to discover, categorize, and assess the risk of unmanaged SaaS tools without deploying endpoint agents.
**Defensibility**: Defensibility stems from workflow lock-in and a compounding proprietary risk taxonomy. As the platform maps the long tail of shadow IT applications across multiple customers, it builds a shared knowledge graph of vendor risk profiles. Switching costs increase significantly once security teams embed these continuous discovery alerts into their core incident response and compliance reporting workflows.
**Why This Thesis**: An API-driven software approach maps directly to the mid-market reality of heterogeneous, cloud-first environments. Integrating directly into existing systems of record for finance and identity extracts discovery signals passively, avoiding the friction of network traffic interception.

## Opportunity Linked Thesis

**Thesis**: [Software](/Theses/Software)

## Opportunity Linked I C P

**Icp**: [Financial Institution](/CompanyTypes/Financial_Institution)

## Opportunity Market Sizing

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**S A M**: ~$400-600M US and EU mid-to-large financial institutions
**S O M**: ~$15-30M
**T A M**: ~30k global financial institutions × ~$50k/yr average security discovery spend ≈ $1.5B
**Growth Rate**: ~18-24%/yr, driven by tightening financial resilience regulations and decentralized SaaS purchasing by business units
**Paid Comparable Spend**: ~$30k-100k/yr on partial CASB deployments, legacy IT asset management subscriptions, and manual compliance audits

## Opportunity Incumbents

- [Netskope CASB](/Products/Netskope_CASB) — Tool
- [BetterCloud SaaS Management](/Products/BetterCloud_SaaS_Management) — Tool
- [Vendor Review Spreadsheets](/Products/Vendor_Review_Spreadsheets) — Spreadsheet
- [Firewall Log Scripts](/Products/Firewall_Log_Scripts) — DIY
- [Zscaler Internet Access](/Products/Zscaler_Internet_Access) — Tool

## Opportunity Win Conditions

**Kill Thresholds**:
- Zero high-risk unmanaged applications discovered during the 14-day proof of concept
- Deployment approval requires more than 45 days of internal security architecture review
- Less than 20 percent of trial users log in weekly to review new application connections
- Customer churn exceeds 30 percent after the first 90 days of continuous monitoring
**Leading Metrics**:
- Hours to first unmanaged application discovered
- Undocumented SaaS apps found per 100 endpoints deployed
- Percentage of discovered apps categorized by compliance risk tier
- Rate of discovery-to-block rule conversions
- Weekly active usage of the compliance reporting dashboard
**What Proves Right**: Financial security teams deploy the discovery agent and uncover at least 20 unmanaged SaaS applications within the first 14 days of deployment. Users transition from passive monitoring to actively generating compliance reports and creating domain blocking rules directly through the interface. Cohorts retain at over 80 percent after 90 days when priced at a 30,000 dollar annual contract value.
**What Proves Wrong**: The opportunity fails if financial security teams refuse deployment due to endpoint performance degradation or insurmountable data privacy objections. It is also wrong if the tool only surfaces previously known applications, resulting in zero remediation actions taken by the customer within the trial period. The bet is invalid if buyers churn after a single initial audit, treating the software as a one-time scrub rather than a continuous monitoring subscription.

## Opportunity Build Profile

**Hardest Part**: Extracting high-fidelity application identities from noisy telemetry like generic OAuth grants and ambiguous billing descriptions without overwhelming security teams with false positives.
**Min Viable Scope**: Identify unauthorized OAuth grants and active sessions tied to the central corporate identity provider. Deliberately exclude endpoint agent deployment, network firewall log ingestion, and automated access revocation workflows.
**Cold Start Problem**: The engine requires a massive mapping of URLs, IP blocks, and OAuth scopes to specific SaaS products to detect usage. Seed the initial graph by scraping public software directories and manually profiling the network footprints of the top 500 B2B applications.
**Time To First Value**: Same-day value, gated entirely by the customer granting read-only API access to their Google Workspace or Okta environment.
**Data Moat Available**: true
**Technical Difficulty**: Moderate

## Neighborhood

### Incumbent in

- [BetterCloud](/Products/BetterCloud) — incumbent in · Products
- [Firewall Log Scripts](/Products/Firewall_Log_Scripts) — incumbent in · Products
- [Vendor Review Spreadsheets](/Products/Vendor_Review_Spreadsheets) — incumbent in · Products
- [Zscaler Internet Access](/Products/Zscaler_Internet_Access) — incumbent in · Products
- [Netskope CASB](/Products/Netskope_CASB) — incumbent in · Products

### Applies thesis

- [Financial Institution](/CompanyTypes/Financial_Institution) — applies thesis · CompanyTypes

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### Similar Opportunities

- [Shadow IT Detection For Enterprises](/Opportunities/Shadow_IT_Detection_For_Enterprises) — similar · Opportunities
- [Enterprise Shadow IT Mapping](/Opportunities/Enterprise_Shadow_IT_Mapping) — similar · Opportunities
- [Overhead Discovery Fabric](/Opportunities/Overhead_Discovery_Fabric) — similar · Opportunities
- [Rogue Spend Interceptor](/Opportunities/Rogue_Spend_Interceptor) — similar · Opportunities
- [Shadow Spend Controller](/Departments/Example_Two/Opportunities/Shadow_Spend_Controller) — similar · Opportunities
- [Vendor Risk Profiling for IT](/Opportunities/Vendor_Risk_Profiling_for_IT) — similar · Opportunities
- [Maverick Spend Triage](/Opportunities/Maverick_Spend_Triage) — similar · Opportunities
- [AI Vendor Deduplication for Procurement](/Opportunities/AI_Vendor_Deduplication_for_Procurement) — similar · Opportunities
- [Algorithmic Access Auditing for VMOs](/Opportunities/Algorithmic_Access_Auditing_for_VMOs) — similar · Opportunities
- [Autonomous Spend Enforcement](/Opportunities/Autonomous_Spend_Enforcement) — similar · Opportunities
- [Spend Interception Engine](/Opportunities/Spend_Interception_Engine) — similar · Opportunities
- [Security Architecture Auditing](/Opportunities/Security_Architecture_Auditing) — similar · Opportunities
- [Continuous Vendor Auditing](/Opportunities/Continuous_Vendor_Auditing) — similar · Opportunities
- [Supplier Risk Assessment](/Opportunities/Supplier_Risk_Assessment) — similar · Opportunities
- [Vendor Assessment Automation](/Opportunities/Vendor_Assessment_Automation) — similar · Opportunities
- [Vendor Deduplication Agent](/Opportunities/Vendor_Deduplication_Agent) — similar · Opportunities
- [Compliance Audit Defender](/Opportunities/Compliance_Audit_Defender) — similar · Opportunities
- [Continuous Audit Compliance](/Opportunities/Continuous_Audit_Compliance) — similar · Opportunities
- [AI Token Revocation for SecOps](/Opportunities/AI_Token_Revocation_for_SecOps) — similar · Opportunities
- [AI Expense Auditing](/Opportunities/AI_Expense_Auditing) — similar · Opportunities
