Two Steps Forward for SaaS Adoption, One Step Back for SaaS Security
Download resourcesAbout this session
Anna Sarnek, who leads strategic alliances at Valence Security, argues that SaaS adoption has outpaced SaaS security because procurement decentralized to individual business units while security tooling stayed focused on identity providers, CASBs and endpoint controls that cannot see application-to-application integrations. She walks through concrete failure patterns: OAuth tokens and integrations left active after a tool is decommissioned, local accounts created through 'sign in with Google' that identity providers never see and so never terminate, a single third-party integration with tenant-wide access becoming a full breach path (illustrated with the GitHub/Heroku/Travis CI and Drizzly incidents), files shared to personal Gmail accounts out of convenience, and gaps in MFA enforcement across unmanaged SaaS tools. Her six recommendations center on regularly auditing and off-boarding unused integrations and accounts, centralizing identity, applying data labels to prioritize audit effort, enabling native SaaS security controls rather than assuming defaults are safe, and studying emerging SaaS-to-cloud attack patterns. A Q&A clarifies what Valence Security's platform automates versus CSPM and CASB tools.
Key takeaways
- Audit and off-board unused SaaS integrations and OAuth tokens whenever a tool is decommissioned or a proof of concept ends; over half of integrations found in the wild are unused.
- Do not assume identity-provider offboarding terminates access everywhere; 'sign in with Google/Microsoft' creates local accounts your IdP never sees and never kills.
- Regularly inventory and minimize third-party integrations with tenant-wide access, since a single stolen authorization token there can expose the whole organization.
- Enforce MFA for both human and machine-to-machine identities across every SaaS application, not just the ones provisioned through central IT.
- Use data labeling to prioritize which files and shares to audit for external or personal-account exposure, rather than trying to review everything at once.
Speakers

Anna Sarnek is a highly experienced strategic business development professional, launching innovative product lines and driving growth through strategic partnerships. With over 10 years of experience in the field, Anna has a technical background and… Read moreRead less
Anna Sarnek is a highly experienced strategic business development professional, launching innovative product lines and driving growth through strategic partnerships. With over 10 years of experience in the field, Anna has a technical background and a macro-level perspective on technology problems, allowing her to identify unique joint development and go-to-market opportunities. She's currently the Head of Strategic Alliances at Valence Security, helping to reduce SaaS Misconfiguration driven cybersecurity risks and to reduce Third Party Risk exposures created by SaaS integraitons.
