Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Leadership and ManagementLogical SecuritySecurity & Business Resilience

Lessons from the Snowflake breach: SaaS security needs collaboration

By Guy Guzner
Shaking hands

Image via Unsplash

August 15, 2024

The recent Snowflake attack is an important reminder that data remains king when it comes to cyberattacks, and identities are the gateway for threat actors to access this coveted information. While in the event of an attack, service providers typically take the brunt of the blame. In this case, Snowflake reflected that it was actually how the company’s customers — including major companies like Ticketmaster and Advanced Auto Parts — chose to leverage its SaaS product that created the risk.

The implication is that because the victims failed to enable multi-factor authentication (MFA), they left themselves open to attacks such as phishing, credential stuffing and credential theft. Although the accusations might not have been off base, finger-pointing at customers rarely builds trust or regains loyalty. Instead, this is an opportunity to foster collaboration and discuss the importance of shared responsibility between SaaS service providers and customers to prevent future incidents. 

All businesses can take away lessons on the critical importance of understanding and utilizing a shared responsibility model for better SaaS security. This model is pivotal for effectively managing and mitigating SaaS security risks, especially in cloud environments where responsibilities are distributed between service providers and customers. But what should both service providers and their customers know for successful implementation?

The solution for proper SaaS identity security

The Snowflake attack underscores how poor identity hygiene leaves companies vulnerable. This incident leveraged compromised credentials and exploited weak security practices in SaaS environments, and it has had a negative impact on 165 customers to date.

According to Verizon’s 2024 Data Breach Investigations Report, the number one way a hacker gains access to a system in a web-based application attack is through stolen credentials (77% of the time). This challenge grows more complex as organizations grapple with the explosion of SaaS apps in modern environments. Today it is common for businesses to use multiple apps in order to increase productivity and streamline workflows. Because of this, there are many points of entry into organizations, making these common workplace tools a potential security risk. 

A shared responsibility model is essential to combat such threats. In this model, the SaaS provider and users play active roles in maintaining robust security. Shared responsibility is pivotal for effectively managing and mitigating risks, especially in cloud environments, where responsibilities should be distributed between service providers and customers. Putting the onus on only one party is ineffective and only solves only half the problem, which is why sharing responsibilities is the key to robust identity management. 

But who is the customer in the shared responsibility model? It’s the business leaders downloading and implementing SaaS tools within organizations. To be most effective, these business leaders need to adopt a secure business-led IT mindset. Business-led IT is the idea that employees are empowered to make their own decisions when it comes to work-related tools or apps they would like to use and download, without approval from IT. It helps increase productivity and innovation by giving them autonomy over solutions to enhance their workflow, but also creates risk within companies. As leaders in different departments — marketing, security, finance, etc. — adopt SaaS tools to be more efficient, they need to also share the burden created by the risk and champion "secure business-led IT.” This is how the shared responsibility model becomes effective. 

Breaking down the shared responsibility model for SaaS security

Both parties should be clear on expectations for proper security and to avoid the blame game if an incident occurs. By understanding who owns what responsibilities, companies will be better equipped to identify gaps and improve protocols on their end, while collaborating with providers to ensure that they are playing their roles in proper security hygiene.

The responsibilities should be broken down as the following:  

Service provider responsibilities

  • Securing the underlying cloud infrastructure. Providers must ensure that their infrastructure complies with relevant regulatory standards and certifications, facilitating a secure customer environment.
  • Ensuring that the cloud infrastructure is continually monitored, updated and compliant with security standards.
  • Offering tools and guidance to help customers secure their data and applications.
  • Producing software that is free from defects and known software vulnerabilities that could lead to unauthorized access. 

Customer responsibilities

  • Securing access to their apps and having processes and identity security tools in place to manage user access.
  • Securing their data, including implementing robust encryption, access controls and backup procedures.
  • Implementing robust security practices (including enforcing MFA and regular user access audits) and ensuring that all apps and accounts are accounted for, configured securely and promptly offboarded when no longer needed.

The importance of proper identity hygiene

The Snowflake attack is a lesson in the importance of proper identity hygiene. To prevent similar incidents, companies should align their SaaS security strategies with their service providers so that everyone is clear on what role they should play in mitigating threats. While not all threats can be avoided, being proactive can dramatically reduce risk to ensure that critical data is safe and identities don’t become easy entry points for bad actors. 

KEYWORDS: collaboration consumer confidence risk mitigation saas Software-as-a-Service

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Guy Guzner is Co-Founder and CEO of Savvy.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • lessons-ideas-freepik1170x658.jpg

    3 security lessons we haven’t learned from the Kaseya breach

    See More
  • Crumpled paper and paper airplane

    Navigating Data Security in Financial Services: Lessons from the TeleMessage Breach

    See More
  • 4 Security Lessons From the White House Network Breach

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • The Complete Guide to Physical Security

See More Products

Events

View AllSubmit An Event
  • January 30, 2025

    Iconic and Secure: Security Lessons Learned at Georgetown University

    ON DEMAND: Georgetown University, a major international research university with nine schools, an affiliated hospital, and many highly-ranked academic programs, has a mature, layered security program.
  • January 6, 2011

    From Here to There - Advancing in the Security Field

    Learn the three components that are critical for your advancement.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing