Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Why security leaders are concerned about the SaaS sprawl, and how to get a grip on it

By Lior Yaari
SaaS-security-freepik
August 5, 2021

Software as a service (SaaS) has taken over, and the average enterprise now uses hundreds of unique SaaS applications to accelerate their digital transformation and business velocity. Though it was already on the rise, the global pandemic and widespread Work From Home (WFH) policies dramatically accelerated enterprise dependence on SaaS across every market sector—even traditional laggards like health and finance. 

However, while SaaS has fulfilled its growth-enabling potential, most organizations have lost their grip on its consumption and use. SaaS is internet accessible, and IT and security teams can no longer depend on network or endpoint controls to govern application access. In other words, traditional security teams are left blind to actual activity. The only way forward is to keep updated on all SaaS-related technological developments as they happen. However, is that realistic for already swamped IT and security managers?

 

The rise of the SaaS Sprawl?

Unlike traditional, on-prem third-party software, SaaS applications users can bypass IT review, approval and installation. Steeping security leaders in darkness, this is the origin of the SaaS sprawl. The sprawl is dangerous; Despite often holding sensitive information, many of the applications within it lack the bare minimum of security features of sanctioned SaaS-SSO, security configurations, and vendor approvals. 

IT and security managers who fail to appreciate the inherent risk of this shadow world can no longer maintain an accurate sense of their security posture. The numbers are telling. According to Okta, a SSO provider, only 88 apps use SSO in the average enterprise. Imagine what that means when average industry use often surpasses hundreds of applications per enterprise. 

We must be better prepared, and the very first step in building a viable SaaS threat model is to establish and analyze organizational SaaS inventory. The more granular, the better. At the very least, they should communicate which apps are operating in an organization’s environment and which individuals are using them. To fill in this knowledge gap quickly and without doing so at the expense of other critical operations, we must introduce more automation to SaaS security. 

 

Shadow Applications and their Risks

Shadow SaaS apps are not dangerous because they are unknown. In fact, users tend to work with viable solutions that, in most cases, would have received approval. Rather, real SaaS risk lies in the combination of SaaS app internet accessibility and its separation from IT workflows.

Unlike SSO-connected or self-hosted apps, access to the information stored on SaaS apps is solely controlled by users—the weakest link in our security chain. Access to shadow apps cannot be revoked by IT and security teams due to a lack of awareness over app use or the technical means to revoke access. This creates dangling access to critical information as users change their roles or leave the organization. 

Mindful security leaders must consider how they can leverage SaaS security innovation to unify offboarding for all discovered SaaS, as well as accelerate internal risk assessments and SSO integrations. Remember, users are susceptible to password phishing attacks, which can be significantly reduced by SSO and MFA integrations. However, achieving a security baseline with these integrations is hardly trivial. When discovering new application use within the organization, IT teams are required to detect the administrator of the application itself. Traditional discovery tools, such as network proxies or financial record analyzers fail to accomplish this and increase the friction required to secure the app. In many cases, the app itself does not support SSO or requires additional payment for an enterprise license, known as the SSO Tax. 

 

Getting a Grip on SaaS Access

For too long, access monitoring has relied on network or endpoint-centric solutions despite malicious access to SaaS, both internal and external, rarely ever originating from the office itself. Without visibility into asset access patterns, enterprises have been left with a legacy of missed sensitive connections and meaningful insight into their security postures. Moreover, though traditional data loss prevention DLP requires a closed perimeter in which data moves freely—limiting exfiltration of data from the perimeter—SaaS usage requires breaching this perimeter by design. Understanding that SaaS users always upload data to an internet-based third-party vendor, security leaders understand that the definition of DLP for SaaS must change. Today, the definition must focus on data movement in the SaaS app itself, as well as user devices.

The predominance of WFH and BYOD requires that these measures include a risk-based approach to secure user access based on location, device and identity. Moreover, vendor approval processes are an integral part of a good security posture. Nevertheless, once an app is approved, additional security measures must follow to ensure continued safe use. High-risk applications access, for example, should be limited to corporate devices with active EDR solutions. Access from personal devices, even after approval, must still be logged and monitored. 

SaaS access managers must enforce coherent access policies for every SaaS connected to their organization’s environment and continuously track and limit data movement. Even beginning with read-only SaaS access - viewing without downloading files or expiration dates for downloaded information is a massive step in the right direction.

According to a survey by PTC, 59% of experts polled see security as the critical barrier to selecting SaaS solutions. This decision-making should not be so complex, and, clearly, IT and security leaders have a lot to do to survive the future’s SaaS-dominated landscape. Luckily, the market has taken notice, and IT and security leaders hardly have to go it alone anymore. With automation and a growing selection of new SaaS-centric governance technologies, these leaders can finally adapt to persistent WFH and BYOD trends by governing access to get the grip they need on SaaS security.

This article originally ran in Today’s Cybersecurity Leader, a monthly cybersecurity-focused eNewsletter for security end users, brought to you by Security Magazine. Subscribe here.

KEYWORDS: application security cyber security risk management software as a service (SaaS) software security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Lior yaari

Lior Yaari is CEO of Grip Security.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • half open laptop with pink and blue lights

    72% of security leaders are concerned about the adverse effects of AI

    See More
  • Golden lock and credit cards on keyboard

    90% of Americans are concerned about the rise in fraud

    See More
  • Black keyboard with blue letters

    64% of Leaders are Highly Concerned About Data Sovereignty Amid Tariff Uncertainty

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • school security.jpg

    School Security: How to Build and Strengthen a School Safety Program

  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing