惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
美团技术团队
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
V
Visual Studio Blog
Google DeepMind News
Google DeepMind News
Hugging Face - Blog
Hugging Face - Blog
云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
T
The Blog of Author Tim Ferriss
WordPress大学
WordPress大学
月光博客
月光博客
宝玉的分享
宝玉的分享
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
Apple Machine Learning Research
Apple Machine Learning Research
A
About on SuperTechFans
J
Java Code Geeks
博客园_首页
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
Netflix TechBlog - Medium
Vercel News
Vercel News
博客园 - 聂微东

Latest from TechRadar in Security

Robots are fighting wars and helping to quash riots — China is arming riot police with squads of AI controlled drones and Ukraine wants to man the frontlines with 25,000 robots US security agency still using Mythos despite ban – government using new security tool despite Pentagon's… Struggling to launch Teams? Microsoft recalls update causing failed startup and infinite loading loops –… NIST is cataloging so many vulnerabilities it can only assign severity scores to the highest priority threats How to meaningfully measure the effectiveness of cyber resilience 'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale… How EU organizations can turn sovereign cloud theory into action 'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to… 'They mopped the floor with me and pulled every childish game they could': Disgruntled researcher releases second major Windows zero-day — claims Microsoft 'would ruin my life, and they did' 'As threats evolve, Gemini keeps our defenses one step ahead': Google claims its AI helped it block over 8.3… Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe Agentic swarms will change how everyone uses AI – but how can organizations deploy them securely? Europol launches Operation PowerOFF — warns 75,000 DDoS users and takes down 53 domains China completes testing on ‘deep-sea electro-hydrostatic actuator’ capable of slicing undersea cables as deep as 3.5 kilometers – new compact subsea vessel testing bridges the ‘last mile’ and could deploy in 2026 Many are still leaving the door open': Security experts warn FIFA World Cup partners could be putting customers at… 'Anyone with $10 could have walked straight through': Report warns this legit-looking software is actually… An ancient Microsoft Excel security flaw could let hackers hijack your entire system, so patch now 'This is not a traditional coding error': Experts flag potentially critical security issues at the heart of Anthropic's MCP, exposes 150 million downloads and thousands of servers to complete takeover Your OpenClaw agents can empty your inbox and leak your data. Here's how to secure them Russia hits European thermal power plant in attempted ‘destructive’ cyberattack – Pro-Kremlin hackers are engaging in ‘riskier and more reckless behavior’ in latest attempt to cripple Western critical infrastructure The war in Iran is reaching cyberspace - here’s how to prepare Millions of hotel goers may have been exposed after hackers steal data and leak it on Telegram 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… Dozens of WordPress plugins hijacked to target thousands of sites 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… McGraw Hill becomes latest to see its Salesforce data hacked Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy
Solving the shadow IT crisis in travel
Paul Dear · 2026-04-17 · via Latest from TechRadar in Security

From digital transformation and the advent of mainstream AI, technology has become integral to business travel. But as your IT estate expands, so does its shadow.

The unsanctioned use of technology at work, better known as shadow IT, is a pervasive challenge for security, finance, and regulatory compliance.

Regional Vice President for Supplier Services, EMEA at SAP Concur.

Today, tools are compounded by AI, with 78% of employees admitting to using unapproved AI systems at work. While media conversation has shone a light on shadow IT, there’s little discussion around the granular impact on individual business functions like travel.

When employees face obstacles in authorized tools, they turn to unapproved platforms due to poor user experience. Slow, rigid, or unintuitive workflows drive them towards convenient, consumer-grade tools with the appeal of user familiarity.

For example, if it takes too long to load listings or a traveler can’t use their preferred payment method, they may switch to an alternative platform.

The emergence of consumer-oriented AI tools has complicated the shadow IT landscape. AI-enabled travel booking platforms promise massive efficiency gains, but many employees are unaware of the potential risks they pose.

AI models are known to scrape outdated or invalidated data at times, leading to inaccurate outputs. Or, if employees use AI tools to find “better deals” outside of established booking platforms, this can once again undermine corporate travel strategy.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Moreover, if employees input sensitive corporate data or travel itineraries into unmanaged tools, it can also lead to data breaches, travel safety risks, and non-compliance with privacy regulations.

For example, if an employee uses consumer scanning apps, unauthorized receipt capture applications, or unapproved browser extensions, receipts that contain personal information may be uploaded to non-approved cloud storage.

A free OCR (optical character recognition) app could store images on third-party servers. Such a breach could expose employees’ travel patterns and transaction details.

The fallout of travel shadow IT

When shadow IT finds its way into travel and expense (T&E) processes, it can have costly impacts on the bottom line.

Bookings on unauthorized systems can result in scam purchases, chargebacks, lost discounts, and surplus administrative burden that add up to millions of pounds worth of expenses and lost savings. These are the main sources of financial loss:

  • Direct fraud and reimbursement losses: Fake receipts, inflated claims, and duplicate expense filings are potentially harder for businesses to track and assess when bookings are made in third-party tools.
  • Illegitimate bookings and rogue vendors: Scam booking sites and compromised portals can cause direct card fraud, requiring investigation and chargebacks
  • Inefficient spending: Employees lose access to negotiated corporate rates and discounts when booking via unapproved channels.
  • Increased administrative overhead: The need for manual expense reports, receipt chasing, and coordination of multiple payment sources increases workload and processing costs. In addition, fragmented data results in inadequate reporting and inconsistent analytics, increasing processing time for T&E reports.

The impact of shadow IT is felt in many aspects of travel. Third-party bookings can undermine an employer’s ability to fulfil their duty of care when employees fail to log details of their travel, or plans change at the last minute

Without a digital audit trail to follow, travel managers lack visibility on employee movements and may struggle to contact them in emergencies.

Unapproved T&E systems also increase security vulnerability. These tools typically handle sensitive data, including personal employee information, financial transactions, and travel itineraries.

Without robust protections, they’re a prime entry point for threat actors, putting travelers and organizations of all sizes at risk of fraud, identity theft, and financial harm.

Lastly, shadow IT can jeopardize regulatory compliance.

As strict frameworks such as General Data Protection Regulation (GDPR), Sarbanes-Oxley Act of 2002 (SOX), and Payment Card Industry Data Security Standard (PCI DSS) places increasing demands on organizational data practices, many are falling foul of mandates around data privacy and retention, financial reporting, and more – which can result in permanent reputational harm, not to mention fines into the billions.

Strategies to secure travel management

Legal, IT, finance, operations, and HR teams must work together to deter employees from using unauthorized tools. But beyond a blanket ban on third-party tools - which the data tells us isn’t effective - what policy changes and change management strategies can they implement?

Employee education is the first line of defense. Regularly training staff in shadow IT risks, security standards, and compliance requirements is an important step in this process. This will enable employees to better understand how approved systems are imperative to protecting the organization's data, financial well-being, and duty of care.

If your business hasn’t yet, it may be time to establish guidelines around AI usage. Communicate the benefits and risks and create a culture that encourages responsible AI implementation and healthy experimentation, so people don’t feel they have to use AI tools in secret.

You can also take inspiration from shadow IT. While it might sound counterintuitive, uncovering the tools employees use can help illustrate where there are gaps in the organization's tech stack, and the kinds of features and workflows employees expect from travel tools.

Ultimately, the biggest counter to shadow IT is a technology portfolio that incorporates consumer-grade, secure T&E platforms. Invest in user-friendly tools that empower travelers to book with ease; they shouldn’t feel obliged to use corporate apps - they should want to.

We've featured the best business plan software.

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro