For more than a decade security teams have wrestled with Shadow IT. However, more recently Shadow IT has transformed into Shadow SaaS and at the same time morphed from a minor security exposure into a major one. For an enterprise user to “acquire” access to a SaaS-based application often only takes an email address and credit card. What began as unsanctioned file sharing and collaboration tool usage has expanded into a sprawling ecosystem of business-critical SaaS applications adopted outside formal corporate purchasing processes or supporting IT security reviews.
According to the Cloud Security Alliance, 55% of respondents to a 2025 survey reported that employees are adopting SaaS applications without security involvement. How many unsanctioned SaaS applications this adds up to is hard to guess. But in my opinion this statistic underestimates the unsanctioned SaaS application usage problem.
AI-powered SaaS applications such as embedded copilots, analytics engines, and third-party integrations are now also being acquired and permissioned directly by business users or functions. The applications promise speed, insight, and productivity. What they also introduce is unmanaged risk. Data flows, access permissions, and integrations are created with minimal friction and even less oversight. Can you be sure that sensitive corporate data is not housed within them? What happens if one of these services has a data breach? How would you respond to that incident for a service you didn’t even know you had? The resulting security exposure gap is growing faster than many organizations realize.
SaaS Security Incidents Are a Customer Problem, not a Cloud Provider One
The Cloud/SaaS shared security responsibility model is well understood in theory, but poorly operationalized in practice. Cloud service providers are responsible for securing the underlying infrastructure and application platforms. Customers, however, remain fully responsible for application configuration, identity and access management, data governance, and usage monitoring. But who is conducting these for the multitude of unsanctioned applications? Answer, no one.
It is therefore no surprise that most SaaS-related security incidents are rooted in customer-side failures. Misconfigurations, over-privileged users, weak password management, lack of MFA, account takeovers (ATOs), and poorly governed third-party integrations continue to dominate incident reports.
As SaaS applications increasingly replace on-premises systems for core business processes, this imbalance has become one of the most significant sources of enterprise risk. Security systems invented for the on-premises world are challenged to make the SaaS transition.
Why “Why Now” Is the Wrong Question
Asking “why now” misses the point. Most organizations are already late.
Over the past five years, sensitive data and mission-critical business processes have migrated en-masse into sanctioned and well-vetted SaaS applications such as Microsoft 365, Google Workspace, Salesforce, ServiceNow, Slack, and Workday. However, even with these officially purchased applications security teams have lost direct control, and in many cases, even awareness of how they are currently configured and being used. Security teams were often involved in the original setup of these applications, but not in the day-to-day user management and configuration changes post implementation. Perhaps there has been some important configuration “drift” since the initial deployment?
Each SaaS application introduces its own permission model, security settings, and capability configurations. And as SaaS applications will, the associated capabilities and configurations can change daily as vendors evolve their solutions. Manual reviews and periodic audits cannot keep up. At the same time the explosion of shadow SaaS, AI-driven tools, and OAuth-based third-party access has created ideal conditions for data leakage, compliance failures, and undetected account compromise.
SaaS Application Security as a Distinct Discipline
SaaS Security Posture Management (SSPM), or what I more broadly refer to as SaaS Application Security, has emerged to address this situation. These solutions are not just incremental improvements to CASB or cloud security tooling, although they do share some similarity. They represent a fundamentally different and broader approach, focused on continuous visibility, automated assessment, threat detection, and actionable remediation across a large number of highly distributed SaaS applications. These systems better secure sanctioned SaaS applications and discover and provide automatable governance controls over the unsanctioned ones.
Automation is not a “nice to have” in this space, it is the only scalable operating model. Without it, security teams are guaranteed to fall behind or lean on the Sargeant Shultz defense: “I see nothing, I know nothing!”
What Capabilities Actually Matter to SaaS Application Security
- Comprehensive SaaS and AI application discovery
- Continuous configuration monitoring with prioritization and remediation guidance
- Identity and Access Governance exposing excessive privileges and weak authentication
- Third-party application and OAuth risk analysis
- Data privacy and compliance mapping
- Threat detection and user behavior analytics
- Managed and automated remediation
Our Research Focus
At KuppingerCole we see SaaS application security moving rapidly from a niche concern to a foundational security control. And interestingly, the domain contains elements of both general cybersecurity and identity security issues. As part of our upcoming in-depth research into this market, we will focus on several critical questions.
- How effectively do solutions discover and normalize SaaS and AI application configurations and usage?
- To what extent do vendors move beyond discovery into meaningful, automated remediations?
- How well are identity risks handled across heterogeneous SaaS environments?
- Which vendors demonstrate the policy depth, API integration, and automation maturity required for real-world enterprise deployment?

From Afterthought to Key Security Control Domain
Shadow IT is no longer the issue. Shadow SaaS and AI now are. Organizations that continue to treat SaaS application security as an afterthought will face repeated, avoidable incidents, data leakage, and compliance failures. Those that elevate it to a first-class security control will be far better positioned to manage the next phase of their organization’s SaaS and AI-enabled business transformation.
A recent KuppingerCole Buyer’s Compass on SaaS Security Posture Management provides an excellent market overview, discussion of top use cases, and key solution functions. But there is much more to come from us on this topic!