Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementSecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Observing Privilege to Reduce Risk in Software-as-a-Service (SaaS)

By Chris Morales
Software-as-a-Service
April 21, 2020

Risk remains the top concern for organizations adopting software-as-a-service (SaaS) models and this is an issue that is only getting worse. What is needed today is the ability to remove the dependency on human behavior and human error, bringing control back to the security team.

Risk in a SaaS environment is largely an identity problem. Specifically, it is a misuse of identity and the privilege access granted to that identity. Before implementing any SaaS platform, you must consider how much access is really being granted in the cloud. More importantly, how is that privilege access being used? The principle of least privilege is even more important in these SaaS environments where identity is the only thing within control of the organization and data and resources are highly consolidated. A service or user should have no more permissions than absolutely required in order to do a job.

Within the SaaS world, Microsoft Office 365 has dominated the productivity space, with more than 180 million users. For many of those users, Office 365 is the core of enterprise data storage and communication, meaning it is an incredibly rich treasure trove. It was only natural Office 365 would become the latest focus of cyberattackers. Even considering the increasing adoption of security postures such as multi-factor authentication (MFA), 40 percent of organizations still suffer from Office 365 breaches, which is leading to massive financial and reputational losses.

Of those breaches, account takeover attacks are one of the fastest growing and prevalent problems for most organizations. It used to be that email and accounts were used to gain an initial foothold into a network. Now those same accounts are used for lateral movement to other users and privileged resources. The problem has become severe, and analyst firm Forrester Research puts the cost of account takeovers at $6.5 billion to $7 billion in annual losses across multiple industries.

The most common technique of account takeover is a behavior MITRE defines in the ATT&CK framework as internal spearphishing. It is an interesting use of spearphishing as a method of lateral movement by leveraging existing compromised accounts to further compromise other users in the same organization by posing as a trusted user. It is difficult to discern an email from a legitimate user asking for information as malicious or not, and prevention and detection controls are not designed to stop legitimate communication.

MITRE notes that internal spearphishing has been used in the wild by several threat actors. Those include the Eye Pyramid campaign who used malicious attachments to allows movement from Office 365 accounts to physical systems, compromising nearly 18,000 email accounts in the process. This type of lateral movement is also known to be a technique used by The Syrian Electronic Army (SEA) targeting the Financial Times. The SEA posed as the IT department further compromising systems even when the Financial Times knew it was a target.

So, how do we detect these stealthy attacks that blend into normal behavior?

Identifying the misuse of user access has largely been treated as a static problem, with approaches that are prevention-oriented or rely on manual entitlements that identify threats the moment they occur, leaving little time to properly respond. This type of access monitoring simply states an approved account is being used to access resources, but it doesn’t define how or why those resources are being used.

Rather than relying only on the granted privilege of an entity or being agnostic to privilege, security operations needs to include context on how entities are utilizing their privileges within SaaS applications like Office 365, e.g. observed privilege. This viewpoint is like how attackers observe or infer the interactions between entities. A defender should think in a similar fashion to their adversaries.

This can occur in two parts:

  • Observe the interactions between entities. Based on the behavioral interactions between entities and the sensitivity of assets that are eventually accessed, dynamically determine each entity’s level of privilege. Entities with similar access patterns are grouped as peers. This can be achieved using artificial intelligence and machine learning models.
  • Determine abnormalities of interactions between privileged entities. Compare a given access request to the access history to determine distance from normal group distance. Focus on the abnormalities that have security implications and consequences.

For Office 365, this translates to understanding how users’ access Office 365 resources and from where, but without prying on the data itself to protect privacy. It is about the usage patterns and behaviors, not the static access.

The importance of monitoring the misuse of user access cannot be overstated given its prevalence in real world attacks. As SaaS platforms like Office 365 have proven to be lucrative for lateral movement in organizations, it is critical to have additional focus around accounts and services. Ideally, when security operations teams have solid information about expectations for that infrastructure, malicious behaviors and privilege abuse will be much easier to identify and mitigate.

KEYWORDS: cyber security data breaches risk management software as a service (SaaS)

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Chris Morales is head of security analytics at Vectra, where he advises and designs incident response and threat management programs for Fortune 500 enterprise clients. He has nearly two decades of information security experience in an array of cybersecurity consulting, sales and research roles.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

Popular Stories

Tree shaped as dollar sign

The Salary of a Chief Security Officer

Classroom with rows of desks facing a chalkboard

The AI Powered Classroom Network of the Future: Because Hackers Never Take Recess

Jaguar logo

New Update on Jaguar Land Rover Cyberattack: Q3 Wholesales Down 43%

Cloud icon

Google Cloud Service Exploited in New Phishing Campaign

Person holding phone to smart lock

Why it’s Time to Move on From Legacy Access Control Systems

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

February 26, 2026

Zero Incidents vs. Zero Tolerance – Workplace Violence Prevention Best Practices that Work

Workplace violence remains one of the most complex challenges facing healthcare organizations today. For executive security professionals, the stakes have never been higher: protecting staff, patients, and visitors while preserving a culture of compassion, dignity, and service.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • SEC0620-Prods-slide7_900px

    Software-as-a-Service (SaaS) and Rapid Deployment Templates to Protect People and Maintain Operations

    See More
  • SEC0720-Prods-slide2_900px.jpg

    Software-as-a-Service (SaaS) and Rapid Deployment Templates to Protect People and Maintain Operations

    See More
  • 5 mins with Soby

    5 minutes with Brian Soby - Understanding Software as a Service (SaaS)

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • school security.jpg

    School Security: How to Build and Strengthen a School Safety Program

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing