Valence Releases Its 2023 State of SaaS Security Report

Valence Releases Its 2023 State of SaaS Security Report

The News: SaaS security provider Valence Security announced the release of its 2023 State of SaaS Security report, which features five key types of SaaS breaches, how they happen, and real-world examples. The report also includes 14 SaaS security recommendations, based on the lessons Valence Security has learned from its customers, and three predictions about the near-term future of SaaS security and the most impactful trends on the SaaS security market.

Read the press release on Valence’s website.

Valence Releases Its 2023 State of SaaS Security Report

Analyst Take: As the SaaS market continues to increase its footprint across SMB, mid-market, and enterprise companies, the cybersecurity threats to organizations are rising in lockstep, according to the 2023 Valence State of SaaS Security report. The security vendor-authored report contains the company’s perspective on SaaS security, details the top threats to organizations using SaaS applications, and offers security recommendations and predictions for this increasingly vulnerable market.

SaaS Security Practices, Rather Than the Apps Themselves, Create Security Holes

SaaS platforms have become increasingly popular, as they can be deployed with far less effort, and far more quickly than traditional on-premises software, Further, because these software platforms can be accessed from any internet connection across a multitude of devices, many organizations, from SMBs through large enterprises, have implemented security practices that are inadvertently creating security holes.

For example, workers often complain that being required to input usernames and passwords each time they want to access the software can create excess friction, largely due to forgetting these credentials, and needing to reset them. To speed up access, SaaS apps have turned to authentication tokens, which permit users to bypass usernames, passwords, and two-factor authentication. According to commentary by Valence on the report, the use of these tokens grants easy access for users, tokens are trivial to steal. A stolen tokens let an attacker log in without needing to follow the authentication policies.

Indeed, it is not the SaaS applications that are security risks, but the relatively lax login procedures that create holes through which malevolent actors can use as an entryway to SaaS applications. Stolen authentication tokens, often from dormant accounts, can be used to access these applications easily, resulting in the potential for data theft and loss. As such, these security practices need to be re-evaluated and tightened to ensure that bad actors are not provided with red-carpet access to valuable company systems and data.

“Uncontrolled” File Sharing Is Creating Additional Risks

Another activity that is generating security risks is what Valence calls the increasing amount “uncontrolled file sharing,” which Valence defines as users sharing files with personal accounts, thereby bypassing any corporate security controls. Valence says that on average, there are 54 shared resources (e.g., files, folders, SharePoint sites) per employee, and 193,000 shared resources per company, most of which are idle and unused, creating unmonitored pathways for hackers to use to infiltrate SaaS platforms and software.
Some of other findings of the Valance report related to weak security practices include:

  • Over half (51%) of an organization’s SaaS third-party integrations are inactive
  • 90% of shared assets (files, folders, anyone-with-the-link permissions) remain unused for 90+ days
  • 1 in 8 employee accounts are dormant (1 in 3 in some companies)
  • 53% of CISOs do not have a process to ensure proper correlation between third-party risk management and integrations

Remedying and Closing Security SaaS Security Holes

Valence says that the key to ensuring better SaaS security practices will need to evolve beyond visibility to include automated remediation, and indicated that organizations need to take specific, proactive steps to address weak security practices. Some of their best security practices include:

  • Avoid SaaS misconfigurations by investigating how to leverage native security controls embedded into each SaaS application and configuring them according to industry best practices based on standards from NIST, CIS, and CSA
  • Extend threat detection to ensure maximum coverage and analysis of SaaS applications events, activities, and admin logs, to detect anomalous and malicious activities
  • For identities and permissions, closely manage accounts with high privilege and admin access and apply least privilege principles to ensure each user has the minimum required permissions
  • Ensure SaaS account deactivation is included in identity lifecycle processes and investigate idle accounts and deactivate if the employee has left the organization

In the quest to improve convenience, eliminate effort, and reduce time, many organizations have implemented processes that, on their surface, maintain the use of security protocols. But any process that makes it easier for legitimate users to access a system comes with tradeoffs that generally make it easier for bad actors to access resources as well. Ultimately, the strongest SaaS security practices do not come without some user friction, with which companies and the workers must learn to live.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other insights from The Futurum Group:

AWS re:Inforce: Bridging the Shared Responsibility Divide

Top Security Issues Organizations Need to be Paying Attention to in 2023: Six Five On the Road at .conf23

Dynatrace’s Hypermodal AI: Revolutionizing Observability and Security in the Digital Age

Author Information

Keith Kirkpatrick is VP & Research Director, Enterprise Software & Digital Workflows for The Futurum Group. Keith has over 25 years of experience in research, marketing, and consulting-based fields.

He has authored in-depth reports and market forecast studies covering artificial intelligence, biometrics, data analytics, robotics, high performance computing, and quantum computing, with a specific focus on the use of these technologies within large enterprise organizations and SMBs. He has also established strong working relationships with the international technology vendor community and is a frequent speaker at industry conferences and events.

In his career as a financial and technology journalist he has written for national and trade publications, including BusinessWeek, CNBC.com, Investment Dealers’ Digest, The Red Herring, The Communications of the ACM, and Mobile Computing & Communications, among others.

He is a member of the Association of Independent Information Professionals (AIIP).

Keith holds dual Bachelor of Arts degrees in Magazine Journalism and Sociology from Syracuse University.

Related Insights
How Genesys and AWS Are Redefining AI-Driven Customer Engagement
July 24, 2026

How Genesys and AWS Are Redefining AI-Driven Customer Engagement

Keith Kirkpatrick, Vice President & Research Director, Enterprise Software & Di at Futurum, Genesys Cloud's expanded AWS partnership leverages agentic AI to transform enterprise customer engagement and enable autonomous interactions...
So This Is How AIs Attack- Observations From the OpenAI & Hugging Face Incident
July 24, 2026

So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident

Fernando Montenegro and Mitch Ashley, VPs at Futurum, read the OpenAI and Hugging Face agentic incident as a live test of enterprise readiness to detect and contain AI agents that...
WEKA Engineers the AI Chassis to Conquer the Inference Power Paradox
July 24, 2026

WEKA Engineers the AI Chassis to Conquer the Inference Power Paradox

Brad Shimmin, VP and Practice Lead at Futurum, shares his insights on WEKA’s launch of the WEKApod 3 appliances and NeuralMesh 6 software. By taking total control of its hardware...
Solving the Distributed AI Dilemma: Oracle Base Database Cloud@Customer Brings OCI Automation to Local Workloads
July 24, 2026

Solving the Distributed AI Dilemma: Oracle Base Database Cloud@Customer Brings OCI Automation to Local Workloads

Brad Shimmin at Futurum analyzes Oracle's launch of Base Database Cloud@Customer X11, exploring how converged application VMs and local AI Database 26ai deployments solve data gravity and latency issues....
Conduent's AI-Powered CX Platform: A Major shift for Customer Engagement?
July 24, 2026

Conduent’s AI-Powered CX Platform: A Major shift for Customer Engagement?

Conduent sells its tolling business to Quarterhill for $70M to redirect resources toward AI platform services, capitalizing on surging demand as the AI market projects to reach $25.7B by 2026....
ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth
July 23, 2026

ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth

Futurum Research analyzes ServiceNow Q2 FY 2026 earnings, focusing on AI Control Tower adoption, security expansion, and workflow demand....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.