当前位置:首页 >英文主页 >中英对照 > 报告详情

Perimeters:2026年 SaaS 安全现状报告:面向首席信息安全官(CISOs)的SaaS生态风险应对指南(英文版)(16页).pdf

上传人: 小*** 编号:1242791 2026-05-20 16页 2.33MB

下载:

1、The State OfSaaS SecurityFor CISOs2026 ReportTable of ContentsKey Attack VectorsSaaS Security StatisticsPerimeters:The All-In-One SaaS Security ToolReal-World BreachesExecutive SummaryThe Rise of Identity ThreatsMisconfigs&ComplianceThe State of SaaS Spendperimeters.io2Giving Back34691011121416Looki

2、ng forward to 2026,SaaS platforms have evolved from auxiliary tools intocentral operational systems-and with that shift comes a rapidly expandingattack surface.While 86%of organizations now list SaaS security as a top priority and 76%haveincreased spending to match,significant gaps remain.Organizati

3、ons continue to struggle with visibility:only 55%report that allemployee-adopted apps are registered with security teams,and a majority lackconsistent controls for non-human identities,API tokens,and third-partyintegrations.At the same time,breaches tied to SaaS platforms and over-privileged accessa

4、re increasing in speed and sophistication.This report drills into three key themes:Surface proliferation:The number of SaaS applications,AI integrations andautomation agents continues to grow,creating unsanctioned entry pointsand unmanaged risk.Identity&access complexity:The distinction between huma

5、n and non-human actors is blurring,and control over OAuth tokens,service accounts,and API keys remains inconsistent.Real Threats:Without proper controls,many organizations are still leftsusceptible to attacks-including some of the biggest names like Salesforce,Microsoft,and Samsung.By combining surv

6、ey data,incident case studies,and usage analytics,the reportprovides actionable insights and benchmarks for security,IT,and procurementleaders tasked with securing SaaS ecosystems.The takeaway is clear:it is no longer sufficient to bolt on tools-organizationsmust adopt a unified,automation-driven ap

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
1. **SaaS安全现状**:86%组织将SaaS安全列为优先级,但仅55%员工使用的应用被安全团队注册,76%增加投入。 2. **核心风险**: - 85%的SaaS应用未被管理,平均每公司106个应用(2024年); - 60%终端账户MFA禁用或失效,99.9%的泄露账户未启用MFA; - 63%的安全事件源于SaaS配置错误,56%组织访问控制薄弱。 3. **AI与身份威胁**: - >50%的AI使用未获IT批准,2025年20%的泄露与“影子AI”相关; - 99%的泄露涉及身份凭证(人类或非人类),55%的权限升级涉及机器身份。 4. **成本与合规**:平均SaaS支出达4830美元/员工,仅47%许可证被使用;42%组织因预算压力优化SaaS支出。 5. **解决方案**:需统一自动化工具,实现OAuth监控、MFA强制执行及影子应用治理。
**SaaS安全盲区?** **AI工具失控?** **身份威胁升级?**
客服
商务合作
小程序
服务号
折叠