By Jim Lippie
The cloud revolution continues reshaping how businesses operate, with organizations now managing an average of 112 SaaS applications each. Yet, beneath this digital transformation lie dangers that many companies fail to recognise until it is too late.
Kaseya’s latest SaaS Application Security Insights (SASI) Report 2025 exposes the reality of modern SaaS security challenges through analysis of over 43,000 small and medium-sized businesses, encompassing nearly six million user accounts. The findings reveal a troubling disconnect between SaaS adoption rates and security preparedness:
Evolving attack strategies target cloud infrastructure
Today’s cybercriminals have abandoned unsophisticated approaches in favour of precision-targeted methodologies specifically designed for cloud environments.
Token harvesting, for example, has emerged as a particularly dangerous technique as it enables attackers to intercept authentication credentials and maintain persistent access without triggering conventional security systems.
The weaponisation of artificial intelligence has dramatically amplified these threats. Generative AI now powers automated phishing campaigns that adapt in real time, while Phishing-as-a-Service platforms have industrialised social engineering attacks, making advanced techniques accessible to novice criminals.
Geographic analysis reveals concerning attack patterns, with five regions (China, South Korea, India, Russia, and Australia) accounting for over half of all unauthorised access attempts in 2024. These concentrated threat origins suggest coordinated criminal infrastructure specifically targeting international SaaS platforms.
Platform vulnerabilities and unexpected risk concentrations
Enterprise productivity suites naturally attract criminal attention due to their valuable data repositories. Microsoft 365 and Google Workspace experience significant attack volumes proportional to their extensive user bases, but the research uncovered surprising vulnerability patterns elsewhere.
For instance, Slack demonstrated the highest percentage of critical security incidents relative to usage, with over 31 million security alerts generating a 12% critical classification rate – a dramatic increase from 3.8% in 2022. This escalation indicates that collaborative messaging platforms have become priority targets for sophisticated attack operations.
It is also important to note that the concentration on major platforms often overshadows equally serious risks in specialised applications. Organizations frequently implement comprehensive security for primary productivity tools while neglecting project management systems, financial software, and customer relationship platforms that handle equally sensitive information.
The guest account security crisis
One of the most significant vulnerabilities identified involves the explosive growth of external user access. Currently, 55% of all monitored SaaS accounts operate as guest users rather than licensed employees, which represents a massive expansion in organizational attack surface.
These external accounts typically originate from legitimate business needs – contractor collaboration, supplier integration, consultant access, or temporary project participation. However, convenience often trumps security as organizations grant broad permissions initially, then fail to implement proper governance over time.
Dormant guest credentials represent particularly severe exposure points. Accounts that remain active months or years after their original purpose has ended provide persistent entry vectors for credential-based attacks. These ‘zombie accounts’ frequently escape regular security audits because they do not appear in standard employee directories.
File sharing risks and data leakage
Cloud collaboration capabilities that drive SaaS adoption also create substantial data exposure risks through inadequate sharing controls. The Kaseya research indicates that 37% of all file sharing activity involves external recipients, suggesting that sensitive information regularly crosses organizational boundaries.
Temporary sharing mechanisms pose especially problematic challenges. Users routinely generate access links for specific meetings or project collaborations, but rarely revoke these permissions afterward. These orphaned links remain accessible indefinitely unless administrators actively terminate them – a manual process that organizations rarely execute consistently.
The scale of potential exposure becomes clear when considering that platforms monitored by the research processed over 15,787 file shares hourly throughout 2024. Even if only a fraction involve inappropriate external access, the cumulative risk represents significant data leakage potential.
Authentication weaknesses and security shortcuts
Meanwhile, password fatigue has driven widespread adoption of OAuth authentication, which allows users to access multiple applications through Microsoft or Google credentials. Although this approach reduces password management complexity, it creates dangerous single points of failure where one compromised account provides access to entire application ecosystems.
The SASI report reveals that 61% of SaaS accounts have disabled or never implemented multifactor authentication, despite MFA representing the most effective defence against account takeover attempts. This statistic becomes particularly alarming given the sophisticated credential theft techniques now available to cybercriminals.
Users frequently prioritise convenience over security, disabling protective measures they perceive as cumbersome without understanding the risk implications. The challenge for organizations lies in implementing robust security that does not create such significant friction that employees actively circumvent protections.
Building comprehensive defence strategies
Addressing these multifaceted security challenges requires systematic approaches that combine technological controls, administrative policies, and user education. Built-in platform security features provide foundation-level protection, but cannot address configuration errors and poor user practices that create vulnerabilities.
Mandatory multifactor authentication implementation across all applications represents the fundamental starting point. However, organizations must extend beyond basic MFA to include location-based access controls, device recognition, and behavioural analysis that can identify potentially suspicious access patterns.
Comprehensive monitoring must encompass every connected application, including third-party services integrated through OAuth or similar mechanisms. These connections often escape security reviews despite providing extensive access to organizational data and systems.
Guest account governance demands ongoing attention rather than initial configuration. Automated systems should regularly audit external account activity, identify inactive credentials for removal, and ensure access permissions align with current business requirements. All external accounts should operate under least-privilege principles with automatic expiration dates.
File sharing oversight requires both technological monitoring and clear policy frameworks. Automated tracking of external distribution combined with regular audits of active sharing links can identify and eliminate unnecessary exposure points. Organizations should also implement automatic expiration for temporary access links and require approval workflows for external sharing.
Advanced monitoring and incident response
Modern SaaS security demands sophisticated detection capabilities that can identify subtle compromise indicators across distributed cloud environments. Traditional security tools designed for on-premises infrastructure often lack the visibility necessary to detect advanced threats targeting cloud applications.
Behavioural analysis enables the identification of potentially malicious activity through pattern recognition. Unusual download volumes may indicate data exfiltration attempts, while unexpected upload activity could signal unauthorised data injection. Geographic anomalies, such as access attempts from countries where organizations do not operate, warrant immediate investigation.
Automated response capabilities enable rapid threat containment before security incidents escalate. Such systems can automatically suspend suspicious accounts, block problematic IP ranges, or require additional authentication when risk indicators exceed predetermined thresholds.
Moving forward securely
The shift towards cloud-based SaaS platforms represents an irreversible transformation in many organizational operations. Although this transition delivers substantial benefits in flexibility and cost-effectiveness, it also harbours risks which require dedicated security attention and resources.
Success requires continuous vigilance, regular policy updates, and ongoing user education. As cybercriminals develop increasingly sophisticated techniques targeting cloud platforms, organizations must evolve their security practices accordingly.
The most effective approach combines robust technological controls with comprehensive governance frameworks which address the human factors that contribute to security vulnerabilities. By understanding the true scope of SaaS security risks and implementing appropriate protective measures, organizations can harness cloud application benefits whilst maintaining essential security postures.
The author
Jim Lippie is chief product officer at Kaseya






