Your security team now manages 300+ different cloud apps. 50% of them have direct API access to your most sensitive customer data. Currently, 77% of cloud incidents began with stolen credentials and authentication bypass.
The annual security questionnaire will not prevent this from happening; it is important to have a solid SaaS risk management strategy and incident response plan for third-party applications.
Vendor Threat Realities
Vendor applications are one of the largest blind spots.
The Rise of Third-Party Breaches
A reassessment of the risks associated with third-party vendor applications within your organization is critical. Over the past two years, 30% of confirmed data breaches were directly tied to third-party vendors. This represents a 100% increase from the year before.
The average cost of data breaches across the globe is currently at $4.99 million. In the United States alone, the cost of data breaches can be as high as $11.5 million. The amount of ransomware disclosed due to vendor networks increased nearly 25% in one year.

Why Old Methods for SaaS Risk Management Fail
Before, most businesses checked their vendors using static checklists and frameworks that consisted of four basic phases; discover, assess, govern, and monitor.
This type of generic approach fails given that 59% of compromised accounts already have multi-factor authentication (MFA) enabled. Hackers don't simply guess passwords. They now break into accounts using stolen session cookies and target service accounts. There is a need for continuous monitoring and clear rules governing application access that extend beyond yearly compliance checks.
The 80/20 Prioritization Matrix for Applications
Treating a lunch ordering application in the same manner as a core database application will cause burnout for your entire team.
Determine which software has the highest risk (20% of software will have 80% of the risk).
Prioritize Data Type and User Access
To analyze data first, identify which software holds personal identifiable information (PII) or financial data, as these applications will present the greatest risk to the organization. S

econd, identify how users sign into these pieces of software as any software application that has a single sign-on (SSO) into your organization presents a means for that software application to provide direct access to your organization.
Categorize Software into Logical Tiers
Software can be broken down into three logical tiers:
Tier Zero: Applications that hold sensitive information and have extensive network access such as Salesforce, Microsoft 365, Okta, and Snowflake.
Tier One: Applications that hold a certain amount of sensitivity, but do not provide organization-wide access.
Tier Two: Applications that contain only public or minimal risk data.
The highest magnitude control should be placed on Tier Zero applications.
Mapping the Blast Radius of Integrating Applications
There are multiple instances where an application may communicate with another application. An organization could have its marketing application compromised by a hacker using some type of trivial or unwanted access (connections).
This connection could lead an attacker to your central sales database.
Identify all third-party tools that have read/write access to your core applications. Identify all third-party tools that demand higher permissions than they should. Identify all third-party tools that deny access to your core applications without a valid reason.
Deny any application that has a lower tier than your core application but has demanded the highest tier of permissions. Consider making vendors agree to a custom security agreement; for example, requiring vendors to notify you within 24 hours of a data breach on their software.
Establish a Process for SaaS Risk Management
Abstract rules will not stop a hacker from hacking. Establish a specific process for determining who will review which application and when.
Assign a specific person to own each application.
Weekly and Daily Cycles for Security Operations
Security operations require that you check for active threats on a daily basis by monitoring your system logs for unusual login attempts or if unknown devices are accessing any of the applications with the highest level of privilege.
Weekly activities include reviewing assets that have been added and the sudden occurrences that have occurred since the previous review.
During that timeframe, if new applications are being added to the company, the employee must review the appropriate high-severity alerts for that application. The security lead must review and approve any changes to privacy policies or configurations to any application that is tier-zero. Records of these weekly reviews should be kept clear for evidence purposes.
Monthly and Quarterly Audit Cycles
An inventory check should be performed each month. This check requires the comparison of the list of approved applications to what the company has recorded for billing.

Shadow IT is a huge, unreported problem for many companies.
When employees purchase tools with the company credit card without informing IT, it is discovered during this monthly inventory check. You should randomly sample system logs periodically to see if your ongoing monitoring solution is detecting errors as needed.
Quarterly, you should conduct a complete access audit. This will include reviewing who has administrative access to your top 20 applications. If anyone has left the company, or has changed jobs, be sure to terminate their access. Whenever possible, automate the offboarding of employees to eliminate the possibility of leaving their accounts open while employees are not present.
Incident Teardowns: Where Controls Have Failed
Analyzing actual incidents allows you to see precisely where certain generic security rules failed and why.
The Unfortunate Outcome of the Snowflake Incident
In June of 2024, adversaries attacked the systems connected to a significant data platform of over 165 client networks. Whereas previous attackers utilized sophisticated programs to access the underlying system, in this case, the adversaries simply utilized compromised credentials to gain access as a typical user.
These user account types, which were accessible via compromised credentials, did not require multi-factor authentication (MFA).
The adversaries purchased these compromised credentials online and were able to walk right in without any resistance at all. To prevent this from happening, organizations need to implement phishing-resistant MFA; this includes devices such as hardware tokens and/or physical security keys.
Organizations also need to implement strict session control policies. For example, if an account were to log in from its normal location and then attempt to download an extremely large database, the organization's system must automatically block that attempt, and require the user to log in again with additional confirmation steps.
The Instructure Canvas Data Incident
Another significant incident that occurred recently exposed approximately 275 million records held by many educational and corporate entities. The biggest weakness in this incident was data sharing.
The platform connects so many organizations at many levels, therefore if one segment of the ecosystem experiences a data breach, the entire ecosystem may become vulnerable to the same breach. Thus, it is vital to exercise caution and limit the amount of data shared with a particular vendor.
Vendors should be given the minimum permissions necessary to perform specified functions. Each vendor should also be set up to feed log data into a centralized security tool to make it easier to detect any anomalies in movement or access of sensitive data.
Exposing API Sprawl and AI Agent Threats
Recent changes in the threat landscape have been significant.
The average company, on a global basis, operates an average of 5,900 APIs. However, only 23% of organizations know which APIs deal with sensitive information. In the past year alone, the increase in API-based attacks has been 113%.
OAuth Grant and Service Account Audits
Today, attackers are increasingly targeting non-human identities.
When two machines exchange information, they typically do so through the use of service accounts (i.e., API keys). Service accounts often provide full administrative access, and unlike human accounts, there is no expiration date on these accounts.

One of the most common tactics used by attackers is the discovery of abandoned API keys that have been left in applications. As such, you should rotate all your API keys on a regular basis. Create a complete listing of all the APIs that connect to your network and if you find an API that has not been used within the last 30 days, disable it immediately.
Blocking Intent-Level Data Transmission
Daily, employees are submitting proprietary company information to publicly available AI applications.
Unfortunately, traditional data-loss prevention (DLP) solutions do not catch this activity. Standard DLP applications only look for specific patterns (e.g., a social security number or credit card number) and do not detect when an employee asks an AI to summarize an internal business strategy or improve proprietary code.
Organizations must focus on the intent behind data transmission to identify and block public AI websites within the enterprise and offer an internal, secure AI tool. This is a critical component of modern SaaS risk management.
SaaS Risk Management Tool Selection Criteria
Automation is critical to manage the ongoing data risk audits. The market can be separated into two distinct categories: compliance automation and comprehensive vendor risk management (VRM).
Never buy based on a generic features list.
Automated VRM tools will allow you to scan thousands of vendors with ease. There are many vendors that do not publicly post their prices. The information is available, however, on the internet.
1. UpGuard
UpGuard is an excellent option to scan large networks with an entry-level cost of approximately $1,750 per month for enterprise services.

The VRM vendor marketplace for enterprises can range from $40,000 to $500,000 per year, depending on how many vendors you have.
2. Nudge Security
Nudge Security takes a smarter approach to vendor risk management than UpGuard and other enterprise scanning solutions by scanning your employees' email inboxes instead of scanning the vendor's email inbox.

Nudge monitors any time an employee registers for a new application, stores that information in a database, and notifies you if you have registered for any unauthorized applications. Their pricing is only $5 per mailbox or $750 per month for teams with less than 150 mailboxes, which makes it an incredibly cost-effective way to mitigate unauthorized application usage very quickly.
3. Vanta and Sprinto
The primary purpose of Vanta and Sprinto is compliance tracking. If you are required to comply with an audit such as a SOC 2 or an ISO 27001, their cloud-based software makes collecting documentation easy by collecting evidence over time.

Both platforms integrate directly with the cloud application environment allowing you access to real-time data.
Vanta has an add-on focused on VRM costing approximately $300 to $600 per vendor that you review annually, while Sprinto functions in a similar manner as Vanta does, but also centralizes dashboards, allowing users to reduce the time necessary to prepare for a compliance audit from months to weeks. If you are a security firm or another company that needs to demonstrate security to enterprise customers, either of these programs would be the correct choice.
4. Secureframe, Drata, and Hyperproof
These software tools build on the automation of compliance items. They allow users to map controls in their company to standards such as ISO 31000, HIPAA, and NIST RMF.

They allow you to digitize manual spreadsheets into working dashboards.
If you are a startup trying to meet compliance requirements in less than 90 days, these tools are designed for your needs and include out-of-the-box security questionnaires (e.g., CAIQ, SIG, VSAQ) that you send to vendors to request their SOC 2 Type II reports and penetration tests.
5. AppOmni and DoControl
These tools assist users in remediating security configuration issues in their most critical (highest usage) applications.

They provide continuous monitoring and take immediate action to remediate any identified issues.
For example, if an employee accidentally disables multi-factor authentication (MFA) in Salesforce, AppOmni will enable MFA again immediately after the change was made. These tools will provide customers with complete visibility into their Tier Zero applications as well as continual monitoring of each application's security configuration.
Mitigating Vendor Security Risks
You cannot protect what you can't see.
Stop relying on outdated yearly audits and unrealistic vendor guarantees. You must categorize applications by risk levels, limit access to internal data, and monitor your environment continually. Every integration is a possible entry point for an attacker.
Manage API control, rotate access tokens and keys regularly, and implement strict access controls for every application. Secure your application stack now to minimize the risk of exploitation due to a vendor's security failure. Using comprehensive SaaS risk management ensures you are protected from these emerging threats.


