Editorial

The growing SaaS attack surface: Risks, realities and remedies

As SaaS adoption expands, so too does the attack surface. Jim Lippie, chief product officer at Kaseya, examines the identity, access and data-sharing risks emerging across SaaS environments – and how organisations can strengthen their defences.

Posted 16 September 2026 by Christine Horton


From AI tools to cloud-based platforms, SaaS ecosystems have become foundational across many industries.

Today, the average organisation now relies on close to 100 applications. Yet, despite the productivity benefits and capability improvements they provide, there are several drawbacks of SaaS that cannot be overlooked.

Indeed, organisations need to provide not only their employees but contractors and guest users with access to various applications on a remote basis, rendering traditional network-led defences redundant. As a result, identity has become the new perimeter, leaving many of those organisations faced with managing a complex web of accounts that each have different permissions.

Alarmingly, based on the analysis of more than 27.6 billion SaaS security events across 50,000 SMB environments, Kaseya’s 2026 SaaS Security Report shows that almost seven in 10 (69 percent) SaaS accounts are guest accounts as opposed to licensed users.

Typically, the purpose of guest accounts is to provide temporary access to applications, for file sharing or otherwise. However, when guest accounts remain, they can pose significant identity-related security issues that threat actors can exploit.

All too often, we see guest accounts being granted the same permissions and privileged access as employees – and cybercriminals know this. Indeed, many are now using their own AI tools to seek out guest accounts and target them with credential stuffing or password spraying.

The security issues with OAuth integration and external file sharing

These identity-related threats aren’t limited to lesser-known SaaS tools.

AI assistants, automated solutions and collaboration platforms across Microsoft 365 and Google Workspace notably use a feature known as OAuth that enables employees to sign into tens or hundreds of applications using one login, rather than creating unique passwords for each.

This is highly useful from a productivity perspective. However, the fact that OAuth-connected applications request broad permissions that give ongoing access to collaborative tools can create problems. If a user were to connect to a malicious or compromised application via OAuth, they may inadvertently grant threat actors with persistent access to sensitive business data, email conversations, shared documents and more. Further, even if passwords are changed or reset, OAuth access can remain active through persistent tokens.

Cloud-based models have rightfully been acclaimed for their ability to improve collaboration, enabling employees, contractors and partners to access files anywhere, anytime, and work on them simultaneously. Yet this culture of sharing now more regularly results in company information and sensitive data being distributed outside of organisational boundaries.

In 2025, Kaseya’s SaaS Alerts platform monitored more than 277 million shared files across SaaS environments – double the volume observed in 2024 – 34.75 percent (96.6 million) of which were shared externally.

The likelihood of sensitive or personal data being leaked through file sharing doesn’t just apply to person-to-person file sharing, but also through interacting with AI assistants. Samsung previously made headlines after employees from its semiconductor business accidentally leaked confidential source code by plugging lines of it into OpenAI’s ChatGPT.

Be it code, citizen information, financial records, internal communications or intellectual property, information shared with external tools or individuals are a major driver of shadow IT, leading sensitive information to slip outside of the organisation’s control.

Cybercriminals are evolving their attack methods

Threat actors themselves are also evolving their methods to capitalise on the weaknesses, security gaps and vulnerabilities emerging from the adoption of SaaS applications.

Some, for example, are working to mask the origin of their attacks by routing them via VPNs, proxy networks, cloud hosting providers and compromised systems in the aim of bypassing security tools reliant upon geolocation and IP reputation. Others, meanwhile, are finding ways to blend into day-to-day traffic to avoid rousing suspicion.

Critically, the growing web of complex SaaS applications is making it harder for already stretched security teams to distinguish between malicious activity and legitimate user behaviour. Kaseya SaaS Alerts’ statistics show that 98.9 percent alerts present little to no risk. Yet with 27.6 billion SaaS events having been monitored last year, that remaining 1.1 percent translates to a whopping 278.9 million medium and critical severity alerts.

On top of that, many low and medium severity alerts, such as OAuth access from foreign applications, can appear relatively harmless, but may indicate signs of account compromise.

Simplifying the security stack and getting the basics right

From OAuth integrations and third-party connections to file sharing and misconfigured permissions, SaaS applications present a host of potential risks for companies today that must be managed and monitored.

With identity having become the new security perimeter, robust governance and tighter controls over who has access to what has never been more important, yet many organisations are currently falling short on the basics. Indeed, Kaseya research shows that 56 percent of accounts are not currently protected by multi-factor authentication (MFA), while only 27 percent of SMBs enforce MFA organisation-wide.

Additionally, behavioural monitoring and automated response solutions should also be considered given their ability to contain threats at speed through session termination, access revocation and policy enforcement.

This is not to say that the security stack needs to become more complex. Rather, organisations should focus on the exact opposite. By integrating solutions across detection, response, access management and recovery, security operating models can be simplified, helping teams to move faster and reduce the risk of threats slipping between siloed systems.

In the evolving attacks, these modernised approaches can fundamentally strengthen the attack surface in a new identity-led environment.

Event Logo

If you are interested in this article, why not register to attend our Think Digital Identity and Cybersecurity for Government conference, where digital leaders tackle the most pressing issues facing government today.


Register Now