It's time to start intense scrutiny of SaaS apps as more organizations fall prey to exploits despite higher budgets

SaaS Concept, Software as a Service, A man types smartphone with digital icons representing various aspects of Software as a Service (SaaS), emphasizing modern technology platforms and cloud computing
(Image credit: Shutterstock / jittawit21)

Software as a Service (SaaS) is a cloud-based software delivery model where apps are hosted by a service provider and made available to users over the Internet. With this model, apps are easy to adopt and use.

However, a recent report from AppOmni reveals that one-third of companies surveyed reported experiencing a data breach this year, marking a 5% increase from the previous year.

AppOmni's State of SaaS Security 2024 Report is based on a survey conducted with cybersecurity decision-makers from 644 organizations across the United States, the United Kingdom, France, Germany, Japan, and Australia, with nearly half of these organizations employing over 2,500 people.

Why focus on SaaS security?

One of the most pressing issues identified is the risk associated with Generative AI, with 38% of respondents expressing worries about data and intellectual property vulnerabilities stemming from this technology.

Confidence in data security within SaaS applications is notably declining as only 32% of organizations feel secure about their data. This is a sharp drop from 42% in the previous year which is particularly concerning given the backdrop of rising breaches, as 58% of organizations reported experiencing a security incident in the past year.

While 90% of organizations claim to have policies restricting unauthorized application use, 34% admit these policies are not enforced—a significant increase from the previous year. This gap between policy and practice exacerbates security risks, as organizations struggle to maintain oversight of their SaaS applications. In fact, 34% of respondents are unaware of how many SaaS applications are deployed within their organizations, complicating management and security efforts. About 50% of respondents believe that Microsoft 365 does not have up to 10 connected apps, however, AppOmni’s research reveals that on average, it has 1,000.

SaaS exploits are expanding, mainly thanks to the tussle for whose responsibility it is to secure the apps. From the survey, 50% of respondents believe that this is the primary duty of business owners or stakeholders, while only 15% attribute this responsibility to cybersecurity teams. This distribution can lead to confusion and inadequate security measures as responsibilities are not clearly defined.

Concerns regarding data loss are also prevalent, with organizations citing the loss of intellectual property (34%), reputational damage (30%), and customer data compromise (27%) as their top fears related to SaaS security. These findings emphasize the urgent need for organizations to enhance their SaaS security strategies, ensuring robust policies, clearer accountability, and improved visibility into their SaaS environments to mitigate risks effectively.

Looking ahead, the report indicates a shift in organizational priorities regarding cybersecurity. Approximately 69% of respondents anticipate increased spending on cybersecurity measures in the next 12 months. Also, 29% expect discussions around return on investment (ROI) on cybersecurity investments to become a focal point, emphasizing the need for quantifiable risk reduction.

Brendan O’Connor, CEO of AppOmni said: “SaaS has come a long way from its early days of use in isolated departments, and now underpins modern businesses across every function. But attackers continue to wreak havoc by stealing data, holding companies ransom, disrupting business operations, and damaging organizations’ reputations. Our survey findings, conversations, SaaS war stories over the last year, and the current regulatory environment make it clear that SaaS security must mature.”

“As attacker TTPs and preventable security issues are becoming more widely-known, there are signs that CISOs and their teams are prioritizing SaaS risks among their cloud security initiatives—even as budget pressures intensify. The days of waiting on SaaS vendors as the primary security providers for your SaaS estate are over. As the operating system of business, your SaaS estate requires a well-structured security program, organizational alignment on responsibility and accountability, and continuous monitoring at scale.” O’Connor concluded.

More from TechRadar Pro

Efosa Udinmwen
Freelance Journalist

Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity. Upon joining TechRadar Pro, in addition to privacy and technology policy, he is also focused on B2B security products. Efosa can be contacted at this email: udinmwenefosa@gmail.com

Read more
Security
Protect your network with an AI-secure browser and SASE framework
API
Businesses are being plagued by API security risks - with nearly 99% affected
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
A padlock resting on a keyboard.
AI-powered cyber threats demand enhanced security awareness for SMEs and supply chains
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space