UPDATED 09:00 EDT / AUGUST 24 2021

SECURITY

Report finds 40% of all SaaS data is unmanaged, creating significant threats

A new report today from software-as-a-service company DoControl Inc. has found that 40% of all SaaS data access is unmanaged, creating significant insider and external threats.

Described as a wakeup call to chief information officers and chief information security officers and the enterprises they protect, the report details the significant threat of unchecked and named data access by the SaaS provider and how it is often underestimated.

The findings came from a study of an average 1,000-person company with data stores of between 500,000 and 10 million assets in SaaS applications. Companies enabling public sharing may face up to 200,000 of these assets being shared publicly.

Insider threats are said to be a significant concern, with an average of 400 encryption keys shared internally to anyone with a link. A fifth of SaaS assets were found to be shared internally with a link, exposing many employees to data points they are not authorized to consume. Some 8% of employees share assets from their corporation with their personal accounts, exposing many former employees to ongoing company data.

With external threats, between 1,000 and 15,000 external collaborators, including vendors, contractors, customers, partners, prospects, media and analysts, were found to have access to company data. Between 200 and 3,000 external, specifically third-party, companies have access to the assets of the companies studied. And 18% of SaaS application assets were found to be shared externally and remain shared externally even after deleting users.

“The past year forced many organizations to collaborate with many external parties and adjust their existing workforce to support remote collaboration,” explained Adam Gavish, co-founder and chief executive officer of DoControl. “To date, security practitioners focused on enabling SaaS access in a secure manner, now is the time for them to prioritize the relevancy of this data access internally and externally.”

Noting that unmanageable data access poses a significant risk and increases the likelihood for a data breach, Gavish added that “while SaaS apps are designed to promote collaboration, in this ever-growing attack surface security teams must pay attention to ongoing data access at scale.”

Image: DoControl

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.