ChaptersEventsBlog
How is your organization adopting AI technologies? Take this short survey to help us identify key trends and risks across FSI →

State of SaaS Security Report 2025

Released: 04/21/2025

State of SaaS Security Report 2025
State of SaaS Security Report 2025
Software-as-a-Service (SaaS) applications have become foundational to modern business operations. However, organizations are also facing a rising tide of security challenges, including visibility gaps, shadow IT, over-privileged access, and unchecked third-party integrations. Considering these conditions, Valence Security commissioned CSA to develop a survey and report to better understand the current state of SaaS security. CSA conducted the survey in January 2025 and received 420 responses from IT and security professionals. 

The main goals of the study were to: 
  • Understand who is responsible for SaaS security management, along with what tools they use and how security is enforced
  • Identify top SaaS security risks and challenges
  • Evaluate how organizations prioritize SaaS security, allocate budgets, and adopt security solutions
  • Examine the impact of emerging threats, including AI-driven integrations, SaaS-to-SaaS connections, and non-human identities

The survey findings reveal that SaaS security continues to be an afterthought. Despite clear progress, most organizations are still relying on tools and strategies not built for the realities of SaaS. They are working with incomplete coverage and inconsistent enforcement. To keep pace with the speed of SaaS and AI innovation, organizations must act now. They must embrace proactive risk reduction and understand what tools and strategies best support SaaS security as a connected ecosystem.

Key Findings:
  • SaaS security is now a high priority for 86% of organizations, with 76% increasing budgets. The focus is on key areas like threat detection and posture management.
  • 63% of organizations report external data oversharing and 56% say employees upload sensitive data to unauthorized SaaS apps, often without sufficient visibility or enforcement. 
  • With 55% of employees adopting SaaS without security’s involvement and 57% reporting fragmented administration, many organizations struggle to maintain consistent oversight. 
  • Identity and Access Management remains a challenge, with 58% of organizations struggling to enforce privileges and 54% lacking automation for lifecycle management.
  • GenAI tools and SaaS-to-SaaS integrations are expanding the attack surface. 46% of organizations struggle to monitor non-human identities and 56% report concerns about overprivileged API access.
  • Despite confidence, many organizations rely on vendor-native tools and manual audits. These fragmented strategies leave critical gaps across the SaaS environment.

Partner Event Spotlight

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.