I wrote a document a year,
year and a half ago that talks about how
to create a SaaS resilience strategy.
And one of the first things I do is you have
to find out which SaaS you're already using.
This is not a you can go to the IT guy.
And one of the bullet point recommendations is call your
finance guy and see who put a SaaS tool on their P-card.
Finding that out is not as easy as going through all the workloads
that are running on your infrastructure because you don't know.
So you actually have to go through this investigation
process just to establish what is your risk as a business.
And I think this is why this becomes more and more a risk
management question rather than kind of an IT question.
And the risk management actually extends a little bit if you
want to talk about security and ransomware and cyber threat.
Because that's another thing that's a little
bit different in SaaS than it is on-prem.
You have
some exploits in those environments.
And you have some exploits in those environments that you
don't necessarily have in your data center environment.
You know,
imagine I was actually talking to a friend of mine
who works for a company that investigates this stuff.
And he was saying one of the really pernicious things
that's developing right now is tricking people
into giving them API permissions to the SaaS tenant.
There's nothing that's installed on the client computer.
There's nothing installed in the enterprise.
There's nothing to detect.
Right.
Yeah. And so,
basically, in that long list of permissions,
someone pressed OK and,
you know,
gave someone the ability to manipulate the APIs.
So,
they can do a remote encryption of your files.
They can do a remote exfiltration of your files.
Direct access, basically.
Yeah.
And finding that stuff requires a different set of tools.
Then you start looking at SaaS security posture management.
You're looking at behavior analytics.
You're looking at who has permissions to what.
It's a very different problem than I
think our average enterprise is used to.