_2025年SaaS安全现状调查报告_28页_3mb
报告摘要
Executive Summary
Software-as-a-Service (SaaS) security is increasingly a top priority for organizations, with rising investments in threat detection and posture management. However, challenges like poor visibility, weak access controls, decentralized adoption, and identity management persist. The report highlights risks from data exposure, GenAI integrations, and unmanaged third-party access, emphasizing the need for a unified, integrated SaaS security strategy to address gaps and mitigate evolving threats.
Key Findings
-
SaaS Security as a Growing Priority: Organizations prioritize SaaS security, with 86% ranking it highly and 76% increasing budgets. Key areas focus on threat detection and posture management, but confidence often masks implementation gaps.
-
Sensitive Data at Risk: Data exposure is high due to oversharing, weak access controls, and poor visibility. GenAI tools and third-party integrations exacerbate risks by requiring overprivileged access and lacking oversight.
-
Decentralized SaaS Adoption Risks: Employees adopt SaaS without IT involvement, leading to governance inconsistencies. Collaboration challenges and fragmented management hinder effective security, particularly for HR/marketing applications.
-
Human Identity Management Challenges: IAM issues persist, with 58% struggling to enforce proper privileges and 54% lacking automation. Breaches often result from weak MFA and overprivileged accounts.
-
Non-Human Identities and Integrations: Monitoring non-human identities (NHIs) is a blind spot, with GenAI amplifying risks through autonomous operations and overprivileged access.
-
Overconfidence and Tooling Gaps: Organizations overestimate their security capabilities due to reliance on fragmented tools (e.g., native app controls, manual audits), missing broader strategies like discovery and unified response.
Conclusion
SaaS security remains a work in progress, requiring a shift from reactive to proactive, integrated approaches. Organizations must address visibility, identity, and decentralized adoption issues to effectively manage risks and ensure secure SaaS adoption.
试读结束,高清完整版pdf/doc/ppt,请点下载