Shadow IT is just a euphemism for any connected device inside a private network (your LAN) that can send and receive data through your firewall (or gateway) without any permissions or port controls.  As such you will always be at risk depending upon the activity itself.  Whether or not your user is trustworthy is rarely the issue because so much malware and cybercrime is hidden from the user.

