Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»The dark side of widespread SaaS adoption (Page 10)
Cyber resilience

The dark side of widespread SaaS adoption

August 27, 20256 Mins Read
Three dark clouds above a computer with three flows of information. Depicting SAAS usage and associated security issues that need managing.

By Jim Lippie

The cloud revolution continues reshaping how businesses operate, with organizations now managing an average of 112 SaaS applications each. Yet, beneath this digital transformation lie dangers that many companies fail to recognise until it is too late.

Kaseya’s latest SaaS Application Security Insights (SASI) Report 2025 exposes the reality of modern SaaS security challenges through analysis of over 43,000 small and medium-sized businesses, encompassing nearly six million user accounts. The findings reveal a troubling disconnect between SaaS adoption rates and security preparedness:

Evolving attack strategies target cloud infrastructure

Today’s cybercriminals have abandoned unsophisticated approaches in favour of precision-targeted methodologies specifically designed for cloud environments.

Token harvesting, for example, has emerged as a particularly dangerous technique as it enables attackers to intercept authentication credentials and maintain persistent access without triggering conventional security systems.

The weaponisation of artificial intelligence has dramatically amplified these threats. Generative AI now powers automated phishing campaigns that adapt in real time, while Phishing-as-a-Service platforms have industrialised social engineering attacks, making advanced techniques accessible to novice criminals.

Geographic analysis reveals concerning attack patterns, with five regions (China, South Korea, India, Russia, and Australia) accounting for over half of all unauthorised access attempts in 2024. These concentrated threat origins suggest coordinated criminal infrastructure specifically targeting international SaaS platforms.

Platform vulnerabilities and unexpected risk concentrations

Enterprise productivity suites naturally attract criminal attention due to their valuable data repositories. Microsoft 365 and Google Workspace experience significant attack volumes proportional to their extensive user bases, but the research uncovered surprising vulnerability patterns elsewhere.

For instance, Slack demonstrated the highest percentage of critical security incidents relative to usage, with over 31 million security alerts generating a 12% critical classification rate – a dramatic increase from 3.8% in 2022. This escalation indicates that collaborative messaging platforms have become priority targets for sophisticated attack operations.

It is also important to note that the concentration on major platforms often overshadows equally serious risks in specialised applications. Organizations frequently implement comprehensive security for primary productivity tools while neglecting project management systems, financial software, and customer relationship platforms that handle equally sensitive information.

The guest account security crisis

One of the most significant vulnerabilities identified involves the explosive growth of external user access. Currently, 55% of all monitored SaaS accounts operate as guest users rather than licensed employees, which represents a massive expansion in organizational attack surface.

These external accounts typically originate from legitimate business needs – contractor collaboration, supplier integration, consultant access, or temporary project participation. However, convenience often trumps security as organizations grant broad permissions initially, then fail to implement proper governance over time.

Dormant guest credentials represent particularly severe exposure points. Accounts that remain active months or years after their original purpose has ended provide persistent entry vectors for credential-based attacks. These ‘zombie accounts’ frequently escape regular security audits because they do not appear in standard employee directories.

File sharing risks and data leakage

Cloud collaboration capabilities that drive SaaS adoption also create substantial data exposure risks through inadequate sharing controls. The Kaseya research indicates that 37% of all file sharing activity involves external recipients, suggesting that sensitive information regularly crosses organizational boundaries.

Temporary sharing mechanisms pose especially problematic challenges. Users routinely generate access links for specific meetings or project collaborations, but rarely revoke these permissions afterward. These orphaned links remain accessible indefinitely unless administrators actively terminate them – a manual process that organizations rarely execute consistently.

The scale of potential exposure becomes clear when considering that platforms monitored by the research processed over 15,787 file shares hourly throughout 2024. Even if only a fraction involve inappropriate external access, the cumulative risk represents significant data leakage potential.

Authentication weaknesses and security shortcuts

Meanwhile, password fatigue has driven widespread adoption of OAuth authentication, which allows users to access multiple applications through Microsoft or Google credentials. Although this approach reduces password management complexity, it creates dangerous single points of failure where one compromised account provides access to entire application ecosystems.

The SASI report reveals that 61% of SaaS accounts have disabled or never implemented multifactor authentication, despite MFA representing the most effective defence against account takeover attempts. This statistic becomes particularly alarming given the sophisticated credential theft techniques now available to cybercriminals.

Users frequently prioritise convenience over security, disabling protective measures they perceive as cumbersome without understanding the risk implications. The challenge for organizations lies in implementing robust security that does not create such significant friction that employees actively circumvent protections.

Building comprehensive defence strategies

Addressing these multifaceted security challenges requires systematic approaches that combine technological controls, administrative policies, and user education. Built-in platform security features provide foundation-level protection, but cannot address configuration errors and poor user practices that create vulnerabilities.

Mandatory multifactor authentication implementation across all applications represents the fundamental starting point. However, organizations must extend beyond basic MFA to include location-based access controls, device recognition, and behavioural analysis that can identify potentially suspicious access patterns.

Comprehensive monitoring must encompass every connected application, including third-party services integrated through OAuth or similar mechanisms. These connections often escape security reviews despite providing extensive access to organizational data and systems.

Guest account governance demands ongoing attention rather than initial configuration. Automated systems should regularly audit external account activity, identify inactive credentials for removal, and ensure access permissions align with current business requirements. All external accounts should operate under least-privilege principles with automatic expiration dates.

File sharing oversight requires both technological monitoring and clear policy frameworks. Automated tracking of external distribution combined with regular audits of active sharing links can identify and eliminate unnecessary exposure points. Organizations should also implement automatic expiration for temporary access links and require approval workflows for external sharing.

Advanced monitoring and incident response

Modern SaaS security demands sophisticated detection capabilities that can identify subtle compromise indicators across distributed cloud environments. Traditional security tools designed for on-premises infrastructure often lack the visibility necessary to detect advanced threats targeting cloud applications.

Behavioural analysis enables the identification of potentially malicious activity through pattern recognition. Unusual download volumes may indicate data exfiltration attempts, while unexpected upload activity could signal unauthorised data injection. Geographic anomalies, such as access attempts from countries where organizations do not operate, warrant immediate investigation.

Automated response capabilities enable rapid threat containment before security incidents escalate. Such systems can automatically suspend suspicious accounts, block problematic IP ranges, or require additional authentication when risk indicators exceed predetermined thresholds.

Moving forward securely

The shift towards cloud-based SaaS platforms represents an irreversible transformation in many organizational operations. Although this transition delivers substantial benefits in flexibility and cost-effectiveness, it also harbours risks which require dedicated security attention and resources.

Success requires continuous vigilance, regular policy updates, and ongoing user education. As cybercriminals develop increasingly sophisticated techniques targeting cloud platforms, organizations must evolve their security practices accordingly.

The most effective approach combines robust technological controls with comprehensive governance frameworks which address the human factors that contribute to security vulnerabilities. By understanding the true scope of SaaS security risks and implementing appropriate protective measures, organizations can harness cloud application benefits whilst maintaining essential security postures.

The author

Jim Lippie is chief product officer at Kaseya

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleThe organizational embedded software landscape is changing rapidly: AI governance is failing to keep up and shadow AI is gaining ground
Next Article The urgent need to implement protective AI controls

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Mature businessman smiling talking on smartphone drinking coffee.

A hidden dependency: when trust becomes a vulnerability

June 2, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?