the top 8 security blind spots in your saas environment€¦ · the top 8 security blind spots in...

30
D A V I D P O L I T I S CEO, BetterCloud The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel! To join, visit betterit.cloud

Upload: others

Post on 13-Jun-2020

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

D A V I D P O L I T I SCEO, BetterCloud

The Top 8 Security Blind Spots in Your SaaS Environment

JOIN THE CONVERSATION on BetterIT in the #webinars channel! To join, visit betterit.cloud

Page 2: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

What is a blind spot?

Page 3: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

The New York Times, 1999

Intel, 2003Computer Weekly, 1999

The Economist, 2001

Remember when employees started accessing corporate data on mobile devices?

Page 4: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Computer World, 2001

Then this happened...

Computer World, 2003

TechTarget, 2005

Washington Post, 2005

IEEE, 2005

Page 5: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

The same thing is happening with SaaS now.

Fast Company, 2010

strategy+business, 2010

Lifehacker, 2011

TIME, 2015

Wired, 2012

Page 6: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

SaaS is creating unforeseen security challenges.

Fast Company, 2017

ZDNet, 2017

Dark Reading, 2014

The Hill, 2016

CSO, 2013

Page 7: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Source: BetterCloud Monitor, https://www.bettercloud.com/monitor/6-guiding-principles-for-it-success/

of IT professionals are just getting started managing SaaS apps, or teaching themselves

78%

Page 8: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

And it’s not your fault.

You don’t know what you don’t know.

Page 9: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

5 Stages of Learning

MASTERY ACHIEVED

BLISSFULLY UNAWARE

NAIVELY CONFIDENT

DISCOURAGINGLY REALISTIC

TEACHING OTHERS

Kruger, Justin, and Dunning, David (1999). Unskilled and Unaware Of It: How Difficulties in Recognizing One’s Own Incompetence Lead to Inflated Self-Assessments. Journal of Personality and Social Psychology. American Psychological Association. 77(6): 1121–1134.

Page 10: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

5 Stages of Learning How to Manage SaaS Applications

MASTERY ACHIEVED

BLISSFULLY UNAWARE

NAIVELY CONFIDENT

DISCOURAGINGLY REALISTIC

TEACHING OTHERS

BLIND SPOTSARE HERE

FEW HAVE ACHIEVED

THIS

You think you know, but still don’t know what you don’t know

You know it

You know it fully, and you’re helping others learn it

You know what you don’t know

You don’t know what you don’t know

Page 11: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

The 3 Most Dangerous Blind Spots

Page 12: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

POLL QUESTION #1

Page 13: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

13-191-3The # of super admins in your org is higher than you think, which is a security risk.

B L I N D S P O T # 1 Admin Permissions

Page 14: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Super admins can make changes that are disastrous.

Regulations like GDPR require you to limit admin permissions as much as possible.

B L I N D S P O T # 1 | Admin Permissions

Why should I care?

Page 15: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

SaaS apps lack granular admin roles, so you end up giving everybody super admin access.

You don’t think about admin permissions when you first deploy SaaS.

B L I N D S P O T # 1 | Admin Permissions

Why does this happen?

Page 16: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

CUSTOMER STORY

Page 17: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

POLL QUESTION #2

Page 18: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

The percentage of ex-employees who still have access to your data is higher than you think.

B L I N D S P O T # 2 Offboarding

Page 19: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Ex-employees who retain access can steal, tamper with, or destroy confidential data.

B L I N D S P O T # 2 | Offboarding

Why should I care?

Page 20: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Offboarding is a very manual, time-consuming process that nobody wants to do.

B L I N D S P O T # 2 | Offboarding

Why does this happen?

Page 21: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

CUSTOMER STORY

Page 22: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

POLL QUESTION #3

Page 23: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Whether it’s done accidentally or maliciously, your data is more exposed than you think.

B L I N D S P O T # 3 Data Exposure

Page 24: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Sensitive or confidential information can be exposed to the entire org, or worse — the public. Hackers are mining information for phishing attacks.

B L I N D S P O T # 3 | Data Exposure

Why should I care?

Page 25: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

SaaS apps are prone to very simple misconfiguration errors, making it easy to accidentally expose data.

B L I N D S P O T # 3 | Data Exposure

Why does this happen?

Page 26: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

CUSTOMER STORY

Page 27: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

MASTERY ACHIEVED

TEACHING OTHERSAVOID BLINDSPOTS

SAAS MANAGEMENT

EXPERT

5 Stages of Learning How to Manage SaaS Applications

NAIVELY CONFIDENT

DISCOURAGINGLY REALISTIC

BLISSFULLY UNAWARE

Page 28: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

The 8 critical blind spots1. Admin Permissions

2. Offboarding (User Lifecycle Management)

3. Data Exposure

To learn more about all 8 blind spots, download our whitepaper athttps://bettercloud.com/blindspots

4. Insider Threats

5. External Access

6. Groups Management

7. Licenses

8. Maintenance

Page 29: The Top 8 Security Blind Spots in Your SaaS Environment€¦ · The Top 8 Security Blind Spots in Your SaaS Environment JOIN THE CONVERSATION on BetterIT in the #webinars channel!

Q & A