When You Acquire a Business, You Inherit Its IT

A large iceberg photographed at the waterline showing a small brilliantly lit portion above the surface and a substantially larger dark mass visible beneath the water, representing the hidden IT risk inherited through acquisition.

Private equity firms are adept at evaluating commercial risk. Revenue quality, customer concentration, debt structure, management capability — the diligence process is thorough and deliberate.

IT risk rarely receives the same scrutiny.

When a firm acquires a business, it does not simply acquire its contracts and its customers. It acquires every device on that network, every cloud account set up by a departing employee, every SaaS subscription approved by no one, and every server that has not been patched in three years. Most of that infrastructure is invisible. It is not on an asset register. It is not managed by anyone. It is simply there, quietly creating exposure.

This is the shadow IT problem. And in PE portfolio environments, it is structural, not incidental.

What Is Shadow IT, and Why Is It a PE Problem?

Shadow IT refers to any device, application, system or service operating within a business environment that has not been formally approved, managed or monitored by the IT function.

It is often thought of as a behaviour problem, employees using personal apps or unsanctioned tools. That framing undersells the risk. In most growing businesses, shadow IT accumulates over years as a natural result of operational decisions made without IT involvement.

A sales team adopts a CRM without an IT review. A finance manager connects a personal device to corporate email. A former employee's cloud storage account still holds sensitive data. A legacy server from a previous acquisition continues to run on the network because no one was sure it was safe to decommission.

In a single entity SME, this is manageable, if not ideal. In a PE portfolio, the problem compounds. Every acquisition brings a new IT estate, assembled under different standards, by different people, across different periods of time. The acquiring firm rarely audits what it has inherited in any technical depth. As a result, the portfolio carries risk it cannot see and, therefore, cannot govern.

A cross section of exposed rock face showing distinct horizontal geological strata in varying tones of ochre, sandstone, slate, and chalk, representing years of accumulated IT decisions layered invisibly beneath the surface of a portfolio company.

What Shadow IT Actually Looks Like Inside a Portfolio Company

Shadow IT is not always dramatic. Most of the time, it looks unremarkable — until something goes wrong.

Common examples across PE portfolio environments include:
Unregistered personal devices accessing corporate systems. Employees using personal laptops or mobile phones to connect to business email, file storage or financial systems. These devices are outside the firm's control and outside its security perimeter.
Unapproved SaaS (Software as a Service) applications holding business data. Tools adopted by individual teams for project management, communication, or document sharing, none of which have been reviewed for data governance or access controls.
Legacy servers not reflected in the asset register. Older infrastructure that was never formally decommissioned. It may still be running, still accessible, and still unpatched. It may also be the entry point a threat actor uses to move laterally through the network.
Cloud accounts and storage not managed by IT. Subscriptions created using personal credentials, often by employees who have since left the business. These accounts may still contain sensitive client or financial data.
Networked devices from previous acquisitions or office moves. Printers, access controllers, storage devices and other hardware that was carried through transitions without any security review.

None of these are unusual. All of them represent genuine attack surface.

The Risk Is Not Theoretical

The consequences of unmanaged shadow IT fall across three distinct areas.

Security: Every unmanaged device and unpatched system is a potential entry point. Threat actors actively probe networks for exactly this kind of exposure. An attacker does not need to breach a well defended perimeter if there is a legacy server running outdated firmware sitting quietly on the same network. Shadow IT expands the attack surface — the total set of points where an unauthorised actor could attempt to enter the environment — in ways the IT team cannot monitor, because they do not know it exists.
Compliance: For firms operating in regulated industries, or holding client financial data, the presence of unmanaged systems accessing or storing that data creates direct regulatory exposure. Data sovereignty (requirements governing where and how data is stored and accessed), access logging, encryption standards — these obligations do not distinguish between approved and unapproved infrastructure. The business is accountable for all of it.
Audit and due diligence: For PE firms, the compliance risk compounds at the portfolio level. An acquirer conducting vendor due diligence, or a regulator requesting evidence of controls, will expect a coherent picture of the IT environment. Shadow IT makes that picture impossible to construct. The inability to provide that evidence is, itself, a material risk.

The common thread is visibility. You cannot manage what you cannot see. You cannot evidence what you cannot document.

Network Discovery Is the First Step

Addressing shadow IT begins with understanding what is actually on the network. That requires a deliberate, structured assessment, not a review of the asset register.

A network visibility and infrastructure assessment typically involves:
Active network discovery: Scanning the environment to identify every connected device, including those not reflected in any existing inventory. This establishes a ground truth picture of the network topology.
Asset classification: Categorising discovered assets by type, ownership, patch status, and whether they are managed within current IT processes.
Risk identification: Flagging assets that represent immediate security risk — unpatched systems, devices with no endpoint protection (security software running directly on the device), open ports with no documented business purpose.
Gap analysis: Comparing the discovered environment against what should exist according to current policies and controls. The gap between the two is the shadow IT exposure.
Remediation recommendations: A prioritised plan to bring the environment under proper governance, whether through decommissioning, patching, enrolment in device management, or policy changes.

The output is not simply a list of devices. It is a defensible, documented picture of the IT environment that supports risk management, compliance obligations and ongoing governance.

You Cannot Govern What You Cannot See

For risk and compliance leaders in PE firms, the challenge is not identifying that shadow IT is a problem. The challenge is quantifying it in an environment that has been assembled through acquisition, staff turnover, and operational decisions made without IT oversight.

The first step is always the same: establish what is there.

BitLOGIC provides infrastructure visibility assessments and ongoing managed infrastructure services designed for exactly this environment. We work with PE firms and portfolio companies to surface what is on the network, identify what is unmanaged, and build the controls and governance structures that allow leadership to operate with confidence.

Ready to see what is actually on your network?

A single shaft of warm golden light enters a dim timber interior through a narrow wall gap, illuminating dust particles and aged floorboards in precise detail while the rest of the space remains in soft shadow, representing the act of making a previously invisible IT environment visible and governable.

Shadow IT creates risk you cannot manage until you can see it. BitLOGIC's infrastructure visibility assessment gives PE firms and portfolio companies a clear, documented picture of their IT environment — and a practical path to governance.

Related news