The Annual SaaS Security Report: 2025 CISO Plans and Priorities

June 18, 2024 at 07:30AM Organizations are increasingly prioritizing investment in SaaS security, with 70% establishing dedicated teams and boosting budgets and headcount, according to the Cloud Security Alliance’s “2025 CISO Plans and Priorities” survey. The report highlights improved security capabilities but also challenges in achieving visibility into business-critical apps. The adoption of SaaS Security … Read more

Scattered Spider hackers switch focus to cloud apps for data theft

June 14, 2024 at 11:06AM Scattered Spider gang, also known as Octo Tempest, engages in social engineering attacks to steal data from SaaS apps. They use SMS phishing and SIM swapping for on-premise access. Their tactics expanded to cloud infrastructures without ransomware. They create new virtual machines, disable security protections, and exfiltrate data to cloud … Read more

Why SaaS Security is Suddenly Hot: Racing to Defend and Comply

June 13, 2024 at 07:48AM Financial cyber-attacks prompt tighter compliance regulations in the financial sector, with other industries expected to follow. Many companies lack efficient methods for managing SaaS security and compliance tasks. Free SaaS risk assessment tools offer incremental upgrades to help meet budget and security needs. Understanding financial sector cyber compliance is key … Read more

Cloud Security Alliance Survey Finds 70% of Organizations Have Established Dedicated SaaS Security Teams

June 5, 2024 at 04:08PM The Cloud Security Alliance released the fourth Annual SaaS Security Survey Report, highlighting that 70% of organizations are prioritizing investment in SaaS security. It revealed the establishment of dedicated SaaS security teams and increased budgets. Despite challenges, companies investing in SaaS security are experiencing fewer security incidents, signaling a positive … Read more

The Next Generation of RBI (Remote Browser Isolation)

June 4, 2024 at 08:13AM Summary: The browser security landscape has evolved, with traditional Browser Isolation now inadequate. A new report recommends a shift to Secure Browser Extensions due to the limitations of Browser Isolation, impact on productivity, and changing web-borne threats. Secure Browser Extensions offer improved performance, visibility, risk analysis, and granular enforcement, with … Read more

New Research Warns About Weak Offboarding Management and Insider Risks

May 29, 2024 at 08:24AM Wing Security’s study highlights the risk of former employees retaining access to company data, emphasizing the importance of automating SaaS Security for effective offboarding. With organizations facing insider threats and compliance violations, manual offboarding proves time-consuming and error-prone. Automation emerges as a crucial tool for mitigating risks and safeguarding critical … Read more

The Ultimate SaaS Security Posture Management Checklist, 2025 Edition

May 22, 2024 at 06:49AM The Ultimate SaaS Security Posture Management (SSPM) Checklist, updated for 2025, addresses the growing challenge of securing the corporate SaaS sprawl. It emphasizes the need for a comprehensive SSPM solution covering misconfiguration management, identity security, permissions management, device-to-SaaS relationship, GenAI security posture, data leakage protection, and threat detection & response … Read more

A SaaS Security Challenge: Getting Permissions All in One Place 

May 8, 2024 at 11:07AM SaaS platforms like Salesforce, Workday, and Microsoft 365 offer precise permissions, dictating user access to data. However, managing these permissions can be complex and challenging, leading to security vulnerabilities. A centralized Permissions Inventory enables organizations to reduce their attack surface, improve regulatory compliance, and streamline SaaS security, with future tools … Read more

GenAI: A New Headache for SaaS Security Teams

April 17, 2024 at 08:00AM Open AI’s ChatGPT sparked a GenAI race in 2022, driving SaaS vendors to enhance productivity tools with generative AI capabilities. While enabling various applications, such as software development and content creation, the widespread adoption of GenAI raises concerns about data exposure and cybersecurity threats. Organizations face challenges in managing and … Read more

How the New NIST 2.0 Guidelines Help Detect SaaS Threats

March 18, 2024 at 09:54AM The SaaS ecosystem has rapidly expanded since NIST’s cybersecurity framework 1.1 and SaaS is now the main way businesses use software. The just-released NIST Cybersecurity Framework (CSF) 2.0 seem to prioritize SaaS security needs. Recent breaches highlight the importance of adhering to NIST standards. Applying NIST 2.0 guidelines through SSPM … Read more