A recent report by Grip Security has unveiled a significant security concern for enterprises, highlighting that a striking 90 percent of Software as a Service (SaaS) applications and 91 percent of Artificial Intelligence (AI) tools within businesses remain unmanaged. This widespread lack of oversight suggests rising vulnerabilities in organisational cyberspace.
This comprehensive study underscores the inadequacy of conventional security measures in addressing what is termed 'SaaS risk creep'. This phenomenon has seen the number of SaaS applications used within an enterprise rise by 40 percent over the past two years. Concurrently, there has been an 85 percent uptick in the number of SaaS accounts per employee, despite 73 percent of users never actually utilising their provisioned SaaS licenses.
AI applications show a similar trajectory of concern. Since its launch, ChatGPT has been found within 96 percent of the organisations analysed, with its usage expanding 24-fold. Of the widely-used AI applications, 42 percent have Security Assertion Markup Language (SAML) capabilities that facilitate secure interoperability between systems. Nonetheless, 80 percent of these applications are left unmanaged and are not federated with the SAML protocol, exacerbating the security risks.
Lior Yaari, co-founder and CEO of Grip Security, expressed his concerns, highlighting the disparity between perceived and real security within businesses due to the high volume of unmanaged SaaS apps and AI tools. Yaari emphasised the importance of real-time application visibility and the development of a comprehensive risk governance program for these entities to manage their risks effectively.
The report raises alarms regarding the surge of Shadow SaaS and Shadow AI, referring to applications that operate unbeknownst to IT departments, thereby potentially exposing organisations to data breaches, non-compliance issues, operational inefficiencies, and leaks of confidential information. According to a prediction by Gartner, by 2027, it is expected that 75 percent of employees will be utilising technologies not controlled by IT, signalling an urgent need for enterprises to revamp their security frameworks in light of unmanaged application use.
"SaaS is growing too quickly for outdated tools to keep up," Yaari remarked, urging a shift towards an identity-driven approach as crucial for effective SaaS security and risk management. He cautioned about severe consequences if enterprises continue to ignore this escalating risk, reiterating the necessity for businesses to reevaluate their security strategies to align with the rapid pace of SaaS adoption.
The full findings of the report are accessible through Grip Security's website.
Source: Noah Wire Services