All right. Well, thanks very much. I'm a fellow analyst here at KuppingerCole, and I focus on mostly cybersecurity topics, but you can't separate identity, cybersecurity, and AI anymore. So we really have our hands in all those pies. Given it's a 20-minute session, I thought what I was going to do is tell you what I think you need to know right now, and then I'll give you a little evidence of why I think those things. So there's really four takeaways that I hope you walk out of this room, you know, taking away basically.
So first is that the world of SaaS application security has been a building exposure for years, whether you know it or not, and I'm going to explain some of the statistics that demonstrate that. It is an area that has a specialized set of vendors that I'll talk about it sort of at a high level. So that's one takeaway is if you're not focused on your SaaS application security as separate from cloud security or any other security, you probably have exposures that you're not aware of.
Second thing is right behind that is this thing we probably haven't heard much about is AI governance and security. So fast behind that is an explosion of agents that I'll give you some statistics saying that if you're not aware they're happening, they are happening in the vast majority of organizations, and that is at the same time creating exposures. The third takeaway is that those two worlds are very similar. SaaS application security and AI governance and security are very interrelated.
And so there is a initiative in vendor land to essentially solve SaaS security holistically and AI governance and sort of from a posture point of view from a single solution. So that's the third takeaway is that there is a new set of vendors for which I'm in actually in the midst of research leadership compass that will come out in September. So the third element is there's a leadership compass coming out in September. So I hope you take away from that.
If you if you're interested in SaaS security or AI governance, we're going to have a I'm going to have a perspective on that market by the end of the summer essentially. So those and then basically the fourth item is that is that the keep in mind September, August, September, there'll be a leadership compass that you can buy and see a more holistic view of this new marketplace. So basically this is a lot of a sort of a sneak peek on our my views of the market and the trends that are driving vendor investments. So the first topic is we're in the next cycle of lack of visibility.
You've probably already heard it many times already yesterday. It seems like every IT architectural change security and governance is a laggard and it's just sort of the nature of the world the the the pressure is to invest in those new techniques new approaches to you know, build and deploy applications security historically has to play catch-up and it's no different here in the SaaS application world and the AI governance world. So it's hard to the classic cliche.
It's hard to secure and govern what you can't see and so the history is is not good and we're repeating it this cycle around and specifically with AI governance. I would argue AI governance and security. I would argue that this is the biggest set of problems we've ever faced as an industry because there's so much of what historically we've done does not apply directly to how you govern and secure AI agents. So there's a lot of work in front of us as an industry.
So in terms of agenda, I'm just basically going to talk a little bit about the challenges that lead me to recommend thinking more about your SaaS application security. The challenges that lead me to you know, have you think start to think more about your AI agent security and governance. I'm going to preview a little bit of the the leadership compass.
I'm not going to talk about vendors per se but I'm going to talk about capabilities that are sort of burgeoning up and becoming common amongst the vendors in the space and then I have some recommendations some some action items you can take to start moving the needle to prepare to improve your SaaS security and AI governance. So hopefully that works for you.
So first statistic that drives the recognition that we have a SaaS challenge, SaaS application security challenge is if you actually look at the average large organization in this case, the average organization as from the from Tories 2026 recent research is that there's 830 831 SaaS applications that are deployed. The majority of which are unsanctioned the majority of which have been either signed up for by individuals signed up for by departments, but without knowledge or visibility from the from the IT team IT and security team. You might ask how does that happen?
You know, it's pretty simple in some applications. You just you know, your email is all you need and you signed up and you start sharing corporate data in other cases. Departments have the ability to purchase applications without, you know procurement or without IT involved.
Obviously, that's not a good thing. But this statistic is demonstration that it happens. And so this is where the lack of visibility props up is that, you know sanctions, it's hard enough to secure the 400 and or so sanctioned applications that are in use. But what about the ones that are unsanctioned? To make the matters more complicated even more complicated, even if you have sanctioned SaaS applications, often the administration happens out in the departments, not necessarily by an IT or security person.
So classically, you have a Salesforce administrator, which may not be in IT or you might have a workday administrator that may be in HR. Those applications change on a daily, weekly, monthly basis. Some of those changes have security implications that that person may not be aware of. And so unless you have visibility into the day-to-day configuration changes of the SaaS applications that you are, that are officially purchased by the company, you have no visibility into your exposures. So unfortunately, the reality is that it's corporate data.
It's, you know, business workflows. You're still responsible, you know collectively, we're still responsible for both the sanctioned and the shadow apps. So that drove the industry to create, you know, to create technologies to help with this problem. And some people think, I'm sure no one in this room, you probably recognize a version of this graphic that's talking about the security responsibilities of, you know, an on-premise application and infrastructure as a service, you know, platform as a service or SaaS. And you may think, oh, well, the responsibilities aren't so great.
It's only application configuration and identity and access controls that we're partially responsible for. But now multiply that by 400 sanctioned SaaS applications that, you know, the problems I talked about that you're not, this IT and security team are not managing on a day-to-day basis the configurations. And now you have essentially what looks like a small problem is actually, has become over the past few years a relatively large exposure.
So any good identity person or identity team, when they have these sanctioned SaaS applications, the one thing you do is you set up an identity provider and you authenticate and you use MFA, of course. Nobody would not use MFA these days.
Of course, the reality is that when you centralize your access, which is obviously great from a visibility and control and great from the user's point of view, you've, of course, advertised that to the threat actors how to get access to your SaaS applications, which are all wired up as relying parties to these identity providers. And so what happens, not surprisingly, is the threat actors attack the authentication and the single sign-on service, essentially. And the statistics, these are actually statistics from Proofpoint.
And if you look what they've done here, they looked at thousands of their customers over a 12-month period and they came up with four stats, three of which I've put up here, that 99% of those thousands of customers experience attempts at account takeovers. So they're attacking the identity provider or the account in the identity provider. So you think, okay, well, you don't get much more ubiquitous than 99% experience attacks. But where the problem really comes is that 67% of those organizations actually experience successful attacks, meaning accounts were taken over in that 12-month period.
After that, what happens when a threat actor gets access to the account that has an identity provider single sign-on is that they go into the applications that are sitting behind it, of course, M366, SharePoint being a great example, or the profile of that user, they set up OAuth connections. They do, 88% of the accounts that had compromises had post-access abuse. So something the malicious actor did soon after getting access. And you might be thinking, well, I'm sure most of these accounts didn't have MFA. And if you thought that, you'd be incorrect.
But the majority of those accounts had MFA, at least traditional MFA. And what the threat actor obviously did is they did some sort of session takeover to get access. So if you think about, if you go back to this issue, you have responsibility for your identity and access controls. You set up your identity provider. The threat actor has been able to breach your accounts on a fairly easy, regular basis. And now all of your SaaS applications, however they're configured, are in the hands of a threat actor.
So that's the sort of the very high-level problem with SaaS application exposure that needs to be better managed in most companies. If I flip over to the AI world, now that world has obviously come upon us in the last year or two. So not surprisingly, the problem is we're further behind, I'd say, in this area. And it's probably going to surpass the SaaS application exposures pretty quickly. But if you look at, this is data from the Cloud Security Alliance, that 82% of organizations have discovered shadow AI agents. So there's that shadow term again in their enterprise.
So you have shadow SaaS, you have shadow AI. And so that's the linkage that I'm starting to try to pull together between those two worlds. And why a set of, one reason why a set of vendors have come up to try to address both at the same time. So if you think you're in control of your agent usage, you're probably mistaken.
And, you know, that's just the reality of where we are. If you think, another way to look at the lack of control is the registry side of things. So obviously these agent registries have not existed for that long. So it's not that surprising that they aren't in heavy usage yet. But when you actually look, again, at Cloud Security Alliance report, that 21% of organizations, only 21% of organizations maintain a registry. So the lack of visibility is most visible by having a lack of registry.
Even though, you know, the classic registry of the universe, Microsoft, has a registry that you can register your agents and who owns them and other metadata about them. But only now are organizations starting to think about doing that. And how do you tell all the creators of these agents that they should do that is another problem. So registries exist, but as an industry, we're not really using them to any great extent yet. But should be, of course. So the thing I'll point you to is, this is intended to be frighteningly and confusing.
And on the chart on the right, actually AI, of course, helped me create that. So it was very helpful in that sense. But just to help you navigate, this is what you're responsible for securing and governing. So just go do it. That's easy, right? Just to navigate a little bit, you know, you have basically three types of agents that you have to be thinking about. You have personal agents that are either created or spawned on behalf of a person. So that's the agents a lot of people think about.
But then there are departmental agents that are sort of, you know, doing some sort of function that are not centrally attached to an individual, per se. And then you have this third class of agents that are inside SaaS applications. So pretty much every major SaaS application is creating agents inside of its application to do special, you know, specific specialized work. But from the point of view of security and governance, there's the mesh. Hopefully you get the sense that there's this mesh problem.
There's, you know, agent-to-agent conversations. There's delegation happening here. And the question is, how do you secure and govern this? And that is, you know, the problem of our age is essentially thinking about this complex mesh of people, applications, and the three flavors of agents. So it's a huge identity problem.
You know, there's all these identity classes or problem classes. You know, if I said this was user identity, you'd recognize all these classes. But now these classes of controls have to apply to agents. And the question is, you know, the world that we're dealing with now is, how do you do that? So the answer is, you really can't do it right now. In the words of Martin Kupinger, there's no vendor or even set of vendors that you could acquire right now that would cover this whole mesh sufficiently. So that's the state of play right now.
But, you know, there is a light at the end of the tunnel. There is hope, you know, for the future.
You know, the good side of the force is battling the bad side currently. So practitioners in the identity space, including Kupinger analysts and many others, are converging on this idea that essentially AI agents need to be first-class identities, which is why, for example, Microsoft has rolled out their registry in a way treating them like individual entities with their own metadata and descriptors. So now I'm going to shift into just basically a tease for the leadership compass.
As I mentioned up top, it's planned to come out in September, currently right in the midst of questionnaires and working with the vendors, trying to understand their take on the market. And I think as I mentioned on top, most of the vendors in this space came from the SaaS security side of the equation. So they were in the business of posture management, threat detection, but specifically focused on connecting to your SaaS applications and helping you discover your unsanctioned SaaS.
But because there's so much commonality and the need for AI governance is emerging, basically all of those vendors have stretched their solutions into discovering AI agents, discovering AI applications, and bringing that together from a SaaS application point of view. So specifically, if you have AI agents in your SaaS applications, it makes sense that a SaaS security solution has visibility into that. So this is my genericized, no one particular vendor view of the SaaS and AI governance world.
The commonalities or the capabilities, if you will, of the solutions really fall into a number of categories. First, there's the problem of shadow. So both SaaS applications and AI, AI has a shadow problem. And essentially what the vendors, they do is they just, it's the sniffer. They put sniffers everywhere they can think of putting a sniffer to find these applications and AI agents.
So that can mean they're sniffing the identity system, they're sniffing the network, they're looking at the OAuth grants that are persisting in your identity provider in most cases, they're sniffing the endpoint, they're sniffing code repositories, really anywhere. If you assume no one's going to tell you that these things exist, you have to find them. And so that's a key capability of the product is helping organizations find the shadow of SaaS and AI. And then of course, helping with a process to make shadow sanctioned or get rid of them is the other option, of course.
Once they become sanctioned, the applications and the AI development platforms and the SaaS platforms that have AI agents in them are increasingly exposing their API to give visibility to third-party systems. So another value proposition of these solutions is they provide these API integrations into those platforms, both SaaS and AI. And then once they do that, they've collected their telemetry on an ongoing basis. They can deliver against all these other capabilities. And they have to work well with inside your enterprise.
And so they connect up to security automation systems, SOC, SOAR, AI SOC systems. They connect up to your identity provider, et cetera. So that's the basic idea of what the solutions do. So my final recommendation to you is as you think about maturing your SaaS security and AI governance program, you know, start at the left, do the basics, discover shadow. And that's actually something that, you know, a typical selling proposition for these companies is they help you discover your problem.
But when you discover your SaaS apps and the AI agents that you didn't know you had, you can take that to your, you know, management to say, this is the exposure that we're building. You know, there are other things you can do.
Like, you continue to use your IDP. Your IDP is a great source of registry and of control.
So, you know, they can provide a lot of value in this process. You know, even if you don't have a way of enforcing your data policies, you should have them.
You know, governance starts with a policy and then gets enforced through posture management, basically. So, you know, sharing with AI agents what is allowable, not allowable should be something that you can at least reference and maybe start training on. And then as the enforcement abilities, you know, come into play, you can apply enforcement against them. This clearly, the AI agents are privileged identities and should be treated accordingly. So register them, but also control them as autonomous, you know, relatively highly privileged entities.
And then this is really where the solutions come into play is, you know, on an ongoing basis, though it's a dynamic world, so you're going to need, for the most part, you're going to need a platform that will help you discover and manage and fix the problems that are discovered. And so that is the solution area. The final advice is get ready for my report and please, you know, read it from beginning to end. And that is my session. Thank you. We are looking forward to read your report in September. Me too. I am as well, actually.
So are there any questions from the audience you want to ask Matthew so far? Matthew, maybe I have a question for you. Okay. So many organizations still treat SaaS security as an extension of traditional IAM cloud security. What makes SaaS governance fundamentally different, especially in highly distributed AI-enabled environments? I guess my first reaction is it isn't fundamentally different. It's been fundamentally, on the SaaS application side, fundamentally forgotten. Partly because that chart I put up, you know, a lot of people think, oh, well, it's a SaaS application.
It's the responsibility of the SaaS provider to secure it, which is mostly true except for those top two areas that you're responsible for. So the reality is it's sort of, it's grown over time without much notice.
And when, you know, when you have 400 sanctioned and 400 non-sanctioned, you now have a large problem, even though you have a small sliver of responsibility. So I don't know if that answers the question, but it isn't fundamentally different, but it's been fundamentally forgotten. Okay. Thanks a lot for that. My pleasure.