The bottom line: Organizations lose control over permissions, configurations and integrations on SaaS platforms because they lack the necessary visibility and monitoring tools.
Security teams have no transparency over most SaaS applications in their infrastructure, even though these contain business-critical data. The problem is not negligence, but tools that were never designed for this type of monitoring.
Typically, organizations estimate their SaaS applications at 30 to 50 systems. In reality, however, they often operate over 300 of them. AppOmni’s 2024 research makes the problem even clearer: 49 percent of Microsoft 365 organizations believed they had fewer than ten apps connected to their tenant, while the actual average was over 1,000. Critically: security teams have visibility over approximately one tenth of these applications. The remaining 90 percent — where customer data, source code and financial reports reside — are not monitored. This is not due to a lack of awareness, but because the tools in use were not designed for this type of control.
Concrete incidents illustrate the reality of this “SaaS blind spot”: In April 2023, KrebsOnSecurity uncovered that Salesforce Community websites were systematically exposing sensitive data from government agencies, banks and insurance companies. The cause was not a platform security vulnerability, but a misconfiguration of guest access profiles. Unauthenticated external users could access records via an API interface containing social security numbers, account details and private addresses. Over 150,000 companies may have been affected. A similar pattern emerged in 2022 with GitHub: attackers used stolen OAuth tokens from Heroku and Travis CI to download private repositories. The vulnerability was not with GitHub itself, but with third-party integration programs whose tokens had been operating for years without verification.
Particularly revealing is the 2023 Microsoft case: Microsoft’s own AI team exposed 38 terabytes of internal data — private keys, passwords and over 30,000 internal Teams messages — through a misconfigured Azure access token. The token was intended for only a single training dataset but was configured far too broadly. This scenario illustrates: even well-resourced organizations lose control when configuration is done under time pressure, default settings are too permissive and no one reviews them later.
The central problem for CISOs is the lack of continuous monitoring. SaaS Security Posture Management (SSPM) solutions could help by providing transparent representation and monitoring of admin access, permission assignments, authorized third-party applications and configurations. Without this visibility, organizations leave undetected misconfigurations for months and years — not because teams act negligently, but because their tools do not cover these areas.
Source: www.csoonline.com · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.