Valence Releases Its 2023 State of SaaS Security Report

Valence Releases Its 2023 State of SaaS Security Report

The News: SaaS security provider Valence Security announced the release of its 2023 State of SaaS Security report, which features five key types of SaaS breaches, how they happen, and real-world examples. The report also includes 14 SaaS security recommendations, based on the lessons Valence Security has learned from its customers, and three predictions about the near-term future of SaaS security and the most impactful trends on the SaaS security market.

Read the press release on Valence’s website.

Valence Releases Its 2023 State of SaaS Security Report

Analyst Take: As the SaaS market continues to increase its footprint across SMB, mid-market, and enterprise companies, the cybersecurity threats to organizations are rising in lockstep, according to the 2023 Valence State of SaaS Security report. The security vendor-authored report contains the company’s perspective on SaaS security, details the top threats to organizations using SaaS applications, and offers security recommendations and predictions for this increasingly vulnerable market.

SaaS Security Practices, Rather Than the Apps Themselves, Create Security Holes

SaaS platforms have become increasingly popular, as they can be deployed with far less effort, and far more quickly than traditional on-premises software, Further, because these software platforms can be accessed from any internet connection across a multitude of devices, many organizations, from SMBs through large enterprises, have implemented security practices that are inadvertently creating security holes.

For example, workers often complain that being required to input usernames and passwords each time they want to access the software can create excess friction, largely due to forgetting these credentials, and needing to reset them. To speed up access, SaaS apps have turned to authentication tokens, which permit users to bypass usernames, passwords, and two-factor authentication. According to commentary by Valence on the report, the use of these tokens grants easy access for users, tokens are trivial to steal. A stolen tokens let an attacker log in without needing to follow the authentication policies.

Indeed, it is not the SaaS applications that are security risks, but the relatively lax login procedures that create holes through which malevolent actors can use as an entryway to SaaS applications. Stolen authentication tokens, often from dormant accounts, can be used to access these applications easily, resulting in the potential for data theft and loss. As such, these security practices need to be re-evaluated and tightened to ensure that bad actors are not provided with red-carpet access to valuable company systems and data.

“Uncontrolled” File Sharing Is Creating Additional Risks

Another activity that is generating security risks is what Valence calls the increasing amount “uncontrolled file sharing,” which Valence defines as users sharing files with personal accounts, thereby bypassing any corporate security controls. Valence says that on average, there are 54 shared resources (e.g., files, folders, SharePoint sites) per employee, and 193,000 shared resources per company, most of which are idle and unused, creating unmonitored pathways for hackers to use to infiltrate SaaS platforms and software.
Some of other findings of the Valance report related to weak security practices include:

  • Over half (51%) of an organization’s SaaS third-party integrations are inactive
  • 90% of shared assets (files, folders, anyone-with-the-link permissions) remain unused for 90+ days
  • 1 in 8 employee accounts are dormant (1 in 3 in some companies)
  • 53% of CISOs do not have a process to ensure proper correlation between third-party risk management and integrations

Remedying and Closing Security SaaS Security Holes

Valence says that the key to ensuring better SaaS security practices will need to evolve beyond visibility to include automated remediation, and indicated that organizations need to take specific, proactive steps to address weak security practices. Some of their best security practices include:

  • Avoid SaaS misconfigurations by investigating how to leverage native security controls embedded into each SaaS application and configuring them according to industry best practices based on standards from NIST, CIS, and CSA
  • Extend threat detection to ensure maximum coverage and analysis of SaaS applications events, activities, and admin logs, to detect anomalous and malicious activities
  • For identities and permissions, closely manage accounts with high privilege and admin access and apply least privilege principles to ensure each user has the minimum required permissions
  • Ensure SaaS account deactivation is included in identity lifecycle processes and investigate idle accounts and deactivate if the employee has left the organization

In the quest to improve convenience, eliminate effort, and reduce time, many organizations have implemented processes that, on their surface, maintain the use of security protocols. But any process that makes it easier for legitimate users to access a system comes with tradeoffs that generally make it easier for bad actors to access resources as well. Ultimately, the strongest SaaS security practices do not come without some user friction, with which companies and the workers must learn to live.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other insights from The Futurum Group:

AWS re:Inforce: Bridging the Shared Responsibility Divide

Top Security Issues Organizations Need to be Paying Attention to in 2023: Six Five On the Road at .conf23

Dynatrace’s Hypermodal AI: Revolutionizing Observability and Security in the Digital Age

Author Information

Keith Kirkpatrick is VP & Research Director, Enterprise Software & Digital Workflows for The Futurum Group. Keith has over 25 years of experience in research, marketing, and consulting-based fields.

He has authored in-depth reports and market forecast studies covering artificial intelligence, biometrics, data analytics, robotics, high performance computing, and quantum computing, with a specific focus on the use of these technologies within large enterprise organizations and SMBs. He has also established strong working relationships with the international technology vendor community and is a frequent speaker at industry conferences and events.

In his career as a financial and technology journalist he has written for national and trade publications, including BusinessWeek, CNBC.com, Investment Dealers’ Digest, The Red Herring, The Communications of the ACM, and Mobile Computing & Communications, among others.

He is a member of the Association of Independent Information Professionals (AIIP).

Keith holds dual Bachelor of Arts degrees in Magazine Journalism and Sociology from Syracuse University.

Related Insights
Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market
August 22, 2026

Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market

Thales positioned cybersecurity as a core growth pillar at its November 2024 Capital Markets Day, targeting a market expanding from $195B to $338B by 2029 at 11.6% CAGR, driven by...
FPT IS Bets on Vietnam's Data Privacy Law as a Platform Moment
August 22, 2026

FPT IS Bets on Vietnam’s Data Privacy Law as a Platform Moment

Vietnam's strict new data protection laws drive enterprise urgency. FPT IS launches a four-layer Data Privacy Management Platform to meet compliance demands and position itself as a strategic infrastructure partner....
Cloudera Anywhere Cloud Targets Hybrid AI Complexity With In-Place Execution
August 21, 2026

Cloudera Anywhere Cloud Targets Hybrid AI Complexity With In-Place Execution

Brad Shimmin analyzes Cloudera Anywhere Cloud, examining how modular blueprints, Apache Iceberg, and zero-copy lakehouse architectures resolve data gravity and MLOps bottlenecks across hybrid enterprise AI estates....
DigiCert's PQC Event Franchise Shifts from Awareness to Action
August 21, 2026

DigiCert’s PQC Event Franchise Shifts from Awareness to Action

DigiCert's third annual World Quantum Readiness Day on September 17, 2026, marks a strategic shift from quantum awareness to active post-quantum cryptography deployment, addressing enterprises' top challenge: cryptographic agility....
OPSWAT's OTCEP Invitation: OT Security Credibility or Contract Pipeline?
August 21, 2026

OPSWAT’s OTCEP Invitation: OT Security Credibility or Contract Pipeline?

OPSWAT's CTO presentation at Singapore's OTCEP Forum signals peer-level recognition in OT Security, positioning the vendor to convert high-visibility relationships into durable contracts....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.