Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Sep 02 2026
Digital Workspace

What Shadow IT Can Teach Higher Ed Tech Leaders About the Faculty Experience

Communicating and uncovering points of friction can reduce security concerns.

Higher education IT leaders increasingly aim to consolidate digital tools and reduce friction. To do so, they first must address the shadow IT concerns emerging from faculty going rogue and creating their own work-arounds.

By and large, higher ed faculty seek out shadow IT not to create problems but to solve problems their current technology setup cannot address. 

“Usually, shadow IT is not done for malicious reasons. It’s trying to meet a need within a certain time frame,” says Joel Larson, director of IT support, networking and disaster recovery planning at Kalamazoo Valley Community College.

By understanding faculty problems and needs, IT leaders can be better positioned to design frictionless workflows.

DISCOVER: CDW research shows how organizations are removing friction from the workplace.

What Triggers Faculty Shadow IT?

Typically, faculty members install free or cheap solutions on their own when their IT departments lack the time or resources to field their tech requests. Faculty often cannot wait for IT departments that put their requests on the back burner. 

“They may go down the path of shadow IT to move more quickly,” says Fred Kwong, vice president and CISO at DeVry University.

Shadow IT is more likely to occur in institutions with decentralized IT, Larson notes. Some larger research universities may have not just a central IT but also IT teams for separate academic departments. Even if these discrete IT teams are aware of faculty-installed solutions, central IT might not realize that employees have installed software that’s communicating across the entire network.

Also, at research institutions, faculty with research grants sometimes feel their grants place them outside the governance of central IT, so they bypass the tech review process, Larson finds: “They say, ‘I’m going to buy the technology I need with my money.’” 

Click the banner below to subscribe to EdTech’s weekly newsletter.

 

Security and Compliance Risks of Faculty Shadow IT

Faculty shadow IT results in considerable security and compliance risks.

A major risk, Kwong says, involves the potential exposure of sensitive data without proper controls in place. That’s a significant concern with AI tools, which more faculty members are using and which often request more access than they actually need, leading to greater exposure. 

“The biggest challenge we have today around shadow IT is really with AI,” Kwong says.

If a faculty-installed solution involves student data, that data falls under the Family Educational Rights and Privacy Act, which protects the privacy of students’ education records, Larson says. “If there’s a breach, the institution is still responsible, regardless of whether it knew there was a system that was vulnerable.”

When they download software on their own, faculty sign off on the consumer terms of agreement, which can carry legal ramifications for the institution, Larson says. There’s also an operational risk, he adds: A faculty member might install a tool and later leave the institution, so that a process becomes dependent on a tool no one can support.

“You can’t assess, protect and respond if you don’t know the solution exists,” Larson says. “With shadow IT, you don’t know it exists until it’s a problem, which is the scary part.”

READ MORE: Ask these five questions before adopting an AI tool.

Creating a Faculty-Centered, Frictionless Digital Experience

Given the risks, higher ed institutions have a clear stake in creating a digital workplace that keeps faculty from looking for quick fixes in the first place.

“A faculty-centered digital workplace should be a safe, institutionally supported path,” Larson says. “It should be the easiest path — a path that faculty want to use and have confidence in using.”

The first step in that path should be a single point of contact for faculty requests; an individual who communicates with all the relevant teams, such as IT, procurement and instructional design. “Faculty shouldn’t have to know the entire organizational chart to know whom to ask for things,” Larson says.

Critically, IT must reach out to faculty to understand their tech needs. “We can’t just sit at our computers waiting for support tickets to come in,” Larson says. “The IT department needs to be a department not of ‘no’ but of ‘know.’ They need to be connected with their end users and understand what their needs are.”

UP NEXT: AI risk frameworks help guide governance and tool adoption.

As a department of “know,” IT should ask faculty why and when they need a requested solution, then respond in a timely fashion. Often, IT can inform faculty that the university already has access to the solution or a similar, sufficient solution — vetted tools with data protections that faculty won’t get from free software.

When DeVry faculty want a tech solution, they submit a simple online request form, Kwong says. The IT department responds usually within half a day, letting faculty know if the request is approved or if the solution is already in the university’s software library. DeVry also leverages committees that include IT leaders, school deans and faculty members who assess and prioritize technologies for faculty and students.

AnnaStills/Getty Images