Download Publication
The Annual SaaS Security Survey Report 2025 Plans and Priorities
Release Date: 06/03/2024
Working Group: Security as a Service
In 2024, Software-as-a-Service (SaaS) platforms are integral to most businesses. Unfortunately, inventive threat actors regularly breach SaaS applications from large organizations, underscoring the fragility of even the most secure systems. Against this backdrop of relentless SaaS threats, Adaptive Shield commissioned CSA to develop this survey and report. The goal of the report is to better understand the industry’s knowledge and opinions regarding SaaS application security.
Conducted in January 2024, the survey examined:
- How organizations prioritize SaaS security
- The tools used to secure SaaS applications
- The successes organizations are experiencing in their SaaS security efforts
- SaaS security risks that organizations still struggle to address
The subsequent report serves as a timely exploration into how security measures are evolving in the era of SaaS.
Key Findings:
- 70% of organizations have dedicated SaaS security teams
- 70% of organizations have moderate to full visibility into their SaaS applications
- 65% of organizations struggle with tracking and monitoring risks from third-party integrated apps and rectifying SaaS misconfigurations
- SaaS Security Posture Management (SSPM) users reported little difficulty with managing misconfigurations (56%), monitoring third-party applications (52%), and governing identity security (56%)
Download this Resource
Sponsor
Are you a research volunteer? Request to have your profile displayed on the website here.
Interested in helping develop research with CSA?
Related Certificates & Training
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more
For those who want to learn from the industry's first benchmark for measuring Zero Trust skill sets, the CCZT includes foundational Zero Trust components released by CISA and NIST, innovative work in the Software-Defined Perimeter by CSA Research, and guidance from renowned Zero Trust experts such as John Kindervag, Founder of the Zero Trust philosophy.
Learn more
Learn more