Russell Spitler, CEO and co-founder of Nudge Security, delves into the complexities of securing SaaS tools in a rapidly evolving landscape. He highlights the shift from 'verify then trust' to 'trust and verify' models, emphasizing teamwork among IT, security, and users. The conversation also tackles shadow IT challenges and the importance of clarity in security responsibilities. Spitler advocates for innovative approaches to safeguard data and strong authentication measures to manage access, ensuring organizations can effectively handle post-employee departure security.
The traditional shared responsibility model is inadequate for SaaS security, requiring clearer ownership of roles among IT and users.
Organizations must cultivate a culture of accountability among all employees to effectively manage data security in a SaaS environment.
Deep dives
Challenges of the Shared Security Model
The traditional shared responsibility model between IT and SaaS providers encounters significant challenges due to the nature of SaaS applications. Unlike the typical cloud security model, SaaS often presents difficulties in verifying security controls, as users cannot fully trust the service while also struggling to check its security features. This issue stems from users frequently signing contracts without understanding the associated security responsibilities, as many applications are adopted outside of IT's purview. Consequently, this environment requires a new SaaS security model that assigns clearer ownership for tasks related to identity management and data protection among all relevant teams.
The Impact of Shadow IT and User Adoption
With a large percentage of SaaS applications being introduced by non-IT staff, organizations face the risk of shadow IT policies being enacted in silos. Employees often turn to external tools when their internal IT department fails to meet their needs, resulting in a disjointed approach to SaaS security. Reliable governance becomes complex as IT may not even be aware of the tools being utilized, leading to an uncoordinated security posture. This highlights the necessity for both security teams and SaaS providers to collaborate in order to define and enforce clear security responsibilities.
The Need for Organizational Change
To effectively manage the risks associated with SaaS applications, organizations must acknowledge that security is a shared responsibility across all employees, rather than solely an IT issue. This involves engaging users and raising their awareness about the security measures necessary in a SaaS environment. As businesses increasingly rely on SaaS solutions, the pressure mounts for employees to understand their role in the secure usage of these applications, including the proper management of service and administrative accounts. Establishing a culture of accountability can help reduce security breaches stemming from unauthorized access and oversight.
Evolving Security Practices and Responsibilities
As organizations shift to a data-centric approach, traditional security practices become inadequate for today’s SaaS-driven landscape. The conversation must pivot from merely managing SaaS applications to effectively governing data and its security across multiple platforms. Enterprises need to implement robust identity and access management mechanisms while acknowledging that suppliers should not bear the full burden of security. It’s crucial for organizations to embrace innovative strategies that reflect the evolving dynamics of SaaS security, ensuring that employees take an active role in protecting sensitive data.
Get a full inventory of all SaaS accounts ever created by anyone in your org, in minutes, along with automated workflows to scale SaaS security and governance. No agents, browser plug-ins or network changes required. Start today with a free 14-day trial.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode