2025 has marked a turning point for SaaS security. In a recent webinar hosted by Obsidian Security, Dylan Owen, Sr. Director, Strategy & GRC at Arcova, shared insights on the evolving threat landscape. Building on that discussion, this article explores three critical shifts every security leader must address: the surge in SaaS supply chain attacks, the rise of identity as the new endpoint, and the governance required for agentic AI.
SaaS Supply Chain Attacks Are Surging
Attackers are moving beyond one-to-one compromises. Today’s threat actors target shared SaaS platforms and integrations to gain access to dozens — even hundreds — of downstream organizations. This one-to-many model is efficient for adversaries and devastating for enterprises.
What’s driving this trend?
- Help desk exploitation: Attackers use voice-based social engineering to reset authenticators or phone numbers, then pivot into SaaS apps.
- SSO abuse: Once inside, attackers leverage single sign-on to move laterally across multiple applications.
- Integration sprawl: Unmonitored tokens and third-party connectors create hidden entry points.
Action steps:
- Maintain a live inventory of SaaS apps, integrations, and tokens — including scopes and owners.
- Demand full audit logs from vendors and budget for premium telemetry.
- Apply zero trust principles to SaaS: enforce MFA, conditional access, and geo-based restrictions.
Key takeaway: If you can’t see it, you can’t secure it. Visibility is non-negotiable.
Identity Is the New Endpoint
Devices matter, but identities unlock everything in a SaaS-driven enterprise. Compromised credentials — human or nonhuman — provide attackers with broad access across collaboration tools, HR systems, and IT management platforms.
High-risk scenarios:
- Overprivileged accounts with permanent admin roles.
- Nonhuman identities reused across multiple integrations.
- Weak help desk workflows for password resets.
Controls that work:
- Enforce least privilege with just-in-time elevation for admins.
- Separate human and service identities to simplify monitoring.
- Lock down self-service password reset (SSPR) and require multi-factor verification for authenticator changes.
Key takeaway: Identity governance and behavior monitoring are your first line of defense.
Agentic AI Requires Governance Before Automation
Low-code and no-code AI agents promise efficiency — but they also amplify risk. Without guardrails, these agents can inherit overprivileged credentials, chain insecure workflows, and expose sensitive data.
Governance blueprint:
- Assign dedicated identities for agents — never run under human accounts.
- Apply least privilege scopes mapped to exact tasks.
- Implement guardrails and allowlists for permitted actions.
- Log every agent action for auditability.
- Require security review before publishing agents.
Key takeaway: Treat AI agents like production software — with identity isolation, scoped permissions, and rigorous monitoring.
Practical Steps for CISOs
- Governance: Build a SaaS system of record tracking apps, integrations, tokens, and owners.
- Monitoring: Ingest full audit logs into your SIEM or SaaS monitoring platform. Normalize identity data for actionable alerts.
- Help Desk Hardening: Require strong caller verification for authenticator changes and notify users immediately.
- SSO Hygiene: Enforce MFA everywhere and validate conditional access policies regularly.
- AI Agent Controls: Provision per-agent identities, enforce scoped permissions, and monitor continuously.
Closing Thoughts
SaaS and AI are transforming enterprise operations — and expanding the attack surface. The fundamentals still win: governance, least privilege, strong help desk controls, and real monitoring. The challenge is applying them at scale.
Ready to assess your SaaS posture and AI governance? Contact Arcova for a SaaS threat review and governance workshop.
