← Back to list

3 SaaS Security Threats You Must Defend Against in 2023

Attacks on SaaS applications are soaring in volume and complexity as organisations increase their reliance on interconnected third-party…

Tom Croll · 2023-01-10 10:23 · 100 claps · 3.6 min read
#sspm #saas-security #saas-tools #cybersecurity
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

3 SaaS Security Threats You Must Defend Against in 2023

Attacks on SaaS applications are soaring in volume and complexity as organisations increase their reliance on interconnected third-party platforms to process and store sensitive data outside the traditional corporate network. In this blog, we’ll explore three different SaaS security threats to prepare for in the new year and look at how automated tools like SaaS Security Posture Management (SSPM) can help protect applications and reduce the risk of data loss.

Overview

Account takeover, insider threats, and supply chain attacks using compromised third-party integrations pose the greatest threats to enterprise data stored in SaaS applications and attacks on data stored in SaaS are more likely to succeed than on any other platform. These SaaS attack vectors result from misconfigured applications, overprivileged user accounts, and unmanaged third-party integrations that go undetected by security departments without appropriate SaaS security posture management (SSPM) tools. This has been demonstrated in a number of recent, high-profile data breaches.

In the last year alone, a number of major enterprises including GitHub, Electronic Arts, and Okta fell victim to malicious campaigns that compromised their SaaS environments and exposed troves of internal data. In various cases, attackers were able to exfiltrate personally identifiable information, customer records, financial reports, and proprietary source code from the organisations.

For example, in June of 2021, hackers successfully breached Electronic Arts (EA), the video game maker of popular titles like the FIFA series. They stole 780 GB of data, including user records and source code, which they offered for sale on darknet markets. This attack resulted from bad actors accessing stolen Slack credentials of employees within EA.

Another report from Ponemon found that more than 50% of organisations have experienced a data breach from a third-party app or service. These opportunities for bad actors will only increase as SaaS adoption becomes ubiquitous. Use of SaaS applications has grown sixfold since 2015 and will account for 85% of enterprise software by 2025, leading to increased complexity and interconnectivity across the SaaS landscape.

As a new year begins and teams look ahead to try and build resilient security strategies, there are three particular threats to SaaS that should be factored into every approach. Below, we’ll look at account takeover attacks, insider threats, and third-party integration compromises, exploring how these vectors are exploited by adversaries and detailing how SSPM tools have evolved to mitigate exactly such attacks.

Account Takeover Attacks

Attackers will target existing user accounts by stealing passwords or session tokens from authenticated endpoints in order to gain access to SaaS data. Even using existing controls, such as single sign-on (SSO) and multi-factor authentication (MFA), SaaS applications remain vulnerable to account compromise (see fig. 1). This is due to most tools focusing on traffic flowing to and from individual applications without monitoring user behaviour across the enterprise. Effective SaaS security must monitor multiple SaaS applications concurrently in order to provide context and enhance anomaly detection.

Figure 1. Malware on compromised endpoints or man-in-the-middle redirects can intercept passwords and access tokens, exacerbating threats from bad actors (source: Obsidian SSPM).

Figure 1. Malware on compromised endpoints or man-in-the-middle redirects can intercept passwords and access tokens, exacerbating threats from bad actors (source: Obsidian SSPM).

SSPM tools integrate with multiple applications, collate data sources and use machine learning to create a baseline of SaaS user behaviour, enabling reduced time to detection and minimising the impact of account takeover attacks by remediating vulnerabilities before data can be exfiltrated.

Insider Threats

Sanctioned users pose the second major threat to SaaS data security. Rogue employees frequently download and leak sensitive data when leaving the company or following a negative event, such as a bad review. Some individual application suites, such as Microsoft 365, offer insider threat capabilities that can monitor user behaviour for suspicious activity that could indicate compromise. However, these tools are fundamentally limited in scope to their own application suites making this approach prohibitively expensive and unmanageable when purchased for multiple SaaS platforms.

SSPM tools can enforce controls across multiple application suites, ensuring all platforms are monitored for deviations from baseline behaviour, such as downloading multiple files, enhancing insider threat management capabilities and limiting the scope of data breaches.

Third-party Integration and Supply Chain Attacks

Attackers rarely attack SaaS applications directly, they will seek weak points in connected applications or third-party integrations to gain access to higher value data stores holding sensitive information. The ability for end users to use third-party integrations can be blocked or controlled by administrators, but this is not always possible and negatively impacts business output. As discussed in the aforementioned Uber and Electronic Arts examples, attackers used account takeover attacks to gain access to Slack accounts which were integrated with core business applications in order to gain access to sensitive business data.

SSPM tools can manage third-party integration risk by crawling through SaaS applications, identifying integrations and providing configuration guidelines to prevent vulnerabilities being exploited. They can also protect against supply chain attacks by continuously monitoring for configuration changes and undocumented feature releases which would otherwise go undetected by traditional point-in-time risk assessment procedures.

Concluding Thoughts

Security leaders wishing to enhance their SaaS protection capabilities should invest in SSPM tools to augment stretched security teams and provide an extensive view of SaaS user behaviour across multiple applications. Continuous management of configuration changes and SaaS application risk profiles is essential to protect business operations against account takeover attacks, insider threats and manage SaaS supply chain risk from third-party integrations. Security leaders should demand implementation support from SaaS security vendors to ensure optimal deployment, thus minimising their exposure to risk of data breaches and compliance failure.


메타데이터
post_id
da36eaf1a8dc
slug
3-saas-security-threats-to-prepare-for-in-2023-sspm-da36eaf1a8dc
url
https://medium.com/@tomcroll/3-saas-security-threats-to-prepare-for-in-2023-sspm-da36eaf1a8dc
canonical_url
https://medium.com/@tomcroll/3-saas-security-threats-to-prepare-for-in-2023-sspm-da36eaf1a8dc
author_url
https://medium.com/@tomcroll
status
ok
fetched_at
2026-06-29 22:44:20