How to secure the modern cyber supply chain and surge in third-party risks amid AI automation

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Anna Sarnek, Director of Strategic Alliances, Valence Security


  • The number of data compromises linked to third-party integrations surged in 2023, significantly impacting organizations due to the interconnected nature of modern SaaS (software as a service) environments.
  • Organizations must adopt comprehensive SaaS security strategies, including asset identification, configuration management and integration auditing, to mitigate vulnerabilities and data breaches.
  • Integration of AI and SaaS application adoption means robust third-party risk management practices have become paramount for securing critical business data and applications.

The year 2023 ended as another record breaker for the number of data compromises organizations face. In the last year, 41% of the organizations that suffered a material incident say a third party caused it. In the United States, over a thousand entities were affected due to a successful attack on just 87 organizations, highlighting the level of cyber risk that third parties create today.

While most organizations are keenly aware of the risk that third parties present, third-party risk management focuses on assessing cyber security postures or cyber hygiene without the additional context of how these third parties are connected to the organization – i.e. what the cyber supply chain looks like.

Modern distributed infrastructure, which relies heavily on software as a service (SaaS) usage, creates endless new opportunities for unmonitored access to corporate data and processes. To exploit cloud environments, adversaries leverage misconfigurations, human error, social engineering, credential theft and other attack methods to compromise critical business data and applications.

SaaS applications have decentralized the procurement of IT as each business unit adopts its own productivity tools, leading to an explosion of application administrators sitting outside of IT and security teams. These SaaS applications come with a unique set of security features that must be independently configured, making them prone to human errors and leading to misconfigurations, creating a massive vulnerability for the organization.

As more and more applications participate in sensitive data workflows and are integrated with critical business applications, the likelihood of a data compromise increases.

Protection amid AI-accelerated automation

In addition to an increase in third-party breaches, 2023 has brought artificial intelligence (AI) into the innovation spotlight. Decades of AI and machine learning innovation have centred on automating processes to increase productivity, a technology that relies on third-party integration in software and technologies.

This year, 2024, will continue to shine the light on the benefit of incorporating AI into the modern workforce, a benefit that will accelerate and increase the third-party vulnerabilities that are already exploited today.

It is of the utmost importance that organizations focus on establishing strong SaaS security to contain third-party risk prior to further incorporating the benefit of AI into the organization.

Recommendation 1: Know your assets

SaaS application adoption has rapidly increased by 41% over the past two years, becoming a top vulnerability concern for chief information and security officers. Breaches and misconfigurations across applications such as Okta, Circle CI, Salesforce and Google Workspace indicate the challenges that organizations face, from core business to security SaaS applications.

For example, the Okta attack impacted 100% of its customer base, indicating that when it comes to SaaS-based third-party breaches, just one can have a ripple effect on thousands of organizations.

Far too often, organizations assume that solutions such as multi-factor authentication, developed to manage cloud-native assets, are fully deployed. Yet, every organization has at least 1% of their SaaS accounts not protected by multi-factor authentication, creating active risks.

While this may seem like a small risk, the Drizly credential stuffing attack highlighted how it just takes one account with weak authentication to lead to a major compromise. Furthermore, SaaS applications have evolved into platforms that store and share company data, increasing their susceptibility to human-error-led data exposure.

The distributed nature of SaaS procurement means that now more than ever, organizations need to have a good grasp of what their SaaS assets are, who manages them, and what information is stored in them to manage their security properly.

Recommendation 2: Manage and monitor the configurations

SaaS applications often come with a multitude of configuration options. Many security configurations are not turned on by default, leaving the application administrators responsible for proper security configurations. With the application administrators residing outside the IT business unit, many administrators inadvertently create risk for data exposure through weak access security.

The decentralized nature of SaaS application procurement means that the IT and the security organizations are not always aware of new application deployment in advance to catch the configuration risks created within the organization.

It is paramount for organizations to have a complete inventory of their SaaS applications and regularly monitor the security configurations to both ensure proper enforcement of security policy and mitigate any changes in the configurations over time that may make applications less secure.

Recommendation 3: Inventory and audit the integrations

One of the benefits of SaaS applications is plug-and-play and low-code or no-code integrations – the same thing that creates frictionless service interoperability also creates new exposure to vulnerabilities.

A key benefit of SaaS products is their ability to plug and play with other applications by connecting through integrations to consolidate and simplify data access and application functionality. However, this same functionality that creates interoperability creates vulnerabilities by introducing a spaghetti bowl of entry points into applications that house critical business and customer data.

On average, SaaS platforms have hundreds of integrations available that create an authorized handshake between multiple platforms. A typical organization has over 50% inactive integrations. These integrations create an authorized path for attackers to silently access critical SaaS applications that can lead to a wider compromise. Moreover, organizations have an average of 21 integrations with organization-wide access, paving a global path for systemic compromise.

Many of the inactive integrations within organizations stem from remnants of old vendors and no longer used proofs of concept, creating a shadow risk. To minimize such risk, organizations must actively monitor where the third-party integrations are created between applications and the level of access the integrations have. Periodic audits of SaaS applications should also enforce the rotation of secrets and authentication tokens to minimize the risk of credential theft over time.

By proactively understanding, managing and auditing SaaS assets, their configurations and integrations, organizations can fortify their defences against third-party risks and safeguard critical data in the modern digital ecosystem.


Trending now:


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

This article was exclusively written for The European Sting by Mr. Frank Shao is a Tanzanian medical student. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Access to Healthcare: is it too much to ask?

This article was exclusively written for The European Sting by Mr. Khalil Al Bilani is a 5th-year medical student at Saint George’s University of Beirut. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect […]

UN Photo/Manuel Elías Ramiz Alakbarov (on screen), Deputy Special Coordinator for the Middle East Peace Process, briefs the Security Council meeting on the situation in the Middle East.

Potential turning point for Gaza as peace plan enters second phase: UN envoy

This article is published in association with United Nations. The start of a second phase of a stabilisation plan for Gaza offers a potential turning point for the war-ravaged enclave, a senior UN official told the Security Council on Wednesday. Ramiz Alakbarov warned that risks of violence escalating again remain high, while the situation in the […]

This article is published in association with United Nations.

Gaza ceasefire improves aid access, but children still face deadly conditions

The fragile ceasefire in the Gaza Strip is making a difference to the lives of over a million children, and improving overall access to food – but more aid still needs to enter.  That’s the assessment of two senior officials from the UN Children’s Fund (UNICEF) and the World Food Programme (WFP), speaking on Monday to journalists in New York following a […]

A new blow for UNRWA as headquarters in East Jerusalem ‘set on fire’

© UNRWA Destruction at UNRWA headquarters in East Jerusalem after Israeli authorities sent in bulldozers on 20 January. This article is published in association with United Nations. The head of embattled UN relief agency for Palestinians, UNRWA, has condemned reports that its headquarters in East Jerusalem have been set alight deliberately. It comes after Israeli authorities […]

© UNHCR/Yevheniia Kozun This cinema in Saltivka, Kharkiv, was hit during an earlier strike (file Jan 2026).

‘Cycle of attacks must end’: Lead UN official in Ukraine

This article is published in association with United Nations. The senior UN official in Ukraine, Matthias Schmale, has issued a condemnation of the massive overnight Russian drone and missile strike on several major Ukrainian cities, killing and injuring civilians, and knocking out energy infrastructure amid sub-zero temperatures. The attacks on some of Ukraine’s most important population […]

WHO/P. Virot The flag of the UN World Health Organization (WHO) flies at its headquarters in Geneva, Switzerland.

US withdrawal from WHO ‘risks global safety’, agency says in detailed rebuttal

This article is published in association with United Nations. The World Health Organization (WHO) has issued a detailed statement regretting the United States decision to leave the UN agency, and declaring that it will leave both the US and the world less safe as a result. The statement, released on Saturday, also includes a rebuttal of […]

© UNOCHA/Ximena Borrazas Kateryna and her two children warm up at a heating point and use rhe available electricity to charge their devices.

Keeping people warm amid hostilities and harsh winter weather in Ukraine

This article is published in association with United Nations. As people in war-torn Ukraine face the coldest winter in more than a decade, authorities and humanitarians are working to help them stay warm, particularly the most vulnerable residents.  Russian forces continue to attack Ukraine’s energy grid, leaving families without electricity and heating as temperatures plummet to -20° Celsius.  Since 2022, the Government has established so-called “Invincibility Points” – located in tents or public […]

UN News A UN emergency shelter set up amid the ruins of Gaza.

Gaza: War crimes probe pledges to continue work for justice and accountability

This article is published in association with United Nations. As President Trump launched the international Board of Peace plan for Gaza on Thursday, top independent rights experts tasked by the UN Human Rights Council with investigating grave abuses linked to the Hamas-Israel war pledged to continue their work seeking justice and accountability for all. “The Board […]

© WFP/Maxime Le Lijour Children wait for a hot meal at a kitchen in Khan Younis, Gaza, supported by the World Food Programme.

Cold kills another infant in Gaza as West Bank displacement intensifies

This article is published in association with United Nations. Another child in the Gaza Strip has died from hypothermia as winter weather continues to whip the enclave, the UN said on Wednesday, citing information from the health authorities.  The baby girl – just three months old – was found frozen to death on Tuesday morning at her home in […]

Critical medicines: EU measures to boost competitiveness and tackle shortages 

Critical medicines: EU measures to boost competitiveness and tackle shortages 

This article is brought to you in association with the European Parliament. On Tuesday, Parliament adopted proposals to enhance the availability and supply of essential medicines in the EU. The report, adopted with 503 votes in favour, 57 against and 108 abstentions, aims to ensure a high level of public health protection for EU citizens by […]

Europe Was Warned: Why the Next Pandemic Could Be  Worse 

This article was exclusively written for The European Sting by one of our passionate readers, Dr Taimoor Ahmed Shumail , MD | Dr Ahmed Bilal , MD , Vice  President Global Health and Diplomacy Wing – Pakistan International Medical Students  Association. The opinions expressed within reflect only the writer’s views and not necessarily The European Sting’s position […]

UN News Many Palestinian families are living in poorly equipped shelters that are highly vulnerable to flooding, leaving people inevitably exposed to harsh, stormy weather..

Gaza humanitarian crisis ‘far from being over,’ UN aid coordination office warns

This article is published in association with United Nations. Three months into the ceasefire in the Gaza Strip, the UN and partners have delivered tonnes of assistance items and carried out critical repairs, but this is only a temporary “Band-Aid” solution, a veteran aid worker has warned. “The humanitarian situation and crisis in Gaza is far […]

This article is published in association with European Investment Bank.

Will AI kickstart a new age of nuclear power?

This article is published in association with United Nations. The rapidly expanding use of artificial intelligence worldwide is putting electrical grids under huge pressure and many believe that, to meet that need without contributing to the climate crisis, a full-scale expansion of nuclear energy is essential. The global demand for electricity is growing at a vertiginous […]

UN Photo/Loey Felipe Martha Ama Akyaa Pobee, Assistant Secretary-General for Political Affairs briefs the Security Council meeting on the situation in Iran.

Iran: UN urges ‘maximum restraint’ to avert more death, wider escalation

This article is published in association with United Nations. As nationwide protests in Iran appear to ease after nearly three weeks of unrest and bloodshed, a senior UN official called on Thursday for action to prevent further escalation.  Assistant Secretary-General Martha Pobee briefed an emergency meeting of the Security Council in New York called by the […]

UNRWA UNRWA Headquarters in East Jerusalem

East Jerusalem: Forced shutdown of UN clinic signals escalating disregard for international law

This article is published in association with United Nations. The temporary closure of a UN-run health centre in East Jerusalem is the latest phase in “a pattern of deliberate disregard” for international law, the head of the UN agency that assists Palestine refugees, UNRWA, said on Wednesday.  Israeli forces stormed the UNRWA-operated health centre on Monday and ordered it […]

Unsplash

Iran: ‘The killing of peaceful demonstrators must stop,’ UN rights chief says

This article is published in association with United Nations.  As anti-government demonstrations continue across Iran, the UN human rights chief said on Tuesday that he was horrified at the mounting violence directed by security forces against protestors, with reports of hundreds killed and thousands arrested.  Volker Türk urged the authorities to immediately halt all forms of violence and repression against peaceful […]

© UNHCR/Yevheniia Kozun The bombing of residential buildings in Saltivka, Kharkiv, has left many Ukrainians without power.

Ukraine: Deadly Russian strikes push civilians deeper into winter crisis

This article is published in association with United Nations. Ukraine has entered the new year under intensifying and deadly Russian attacks which have crippled energy systems and left millions without heating, electricity or water amid freezing temperatures, senior UN officials told the Security Council on Monday. Under-Secretary-General for Political Affairs Rosemary DiCarlo told ambassadors the start […]

UN Photo/Eskinder Debebe UN Secretary-General António Guterres. (file photo)

UN chief ‘shocked’ by reports of excessive force against protesters in Iran

This article is published in association with United Nations. The UN Secretary-General is shocked by reports of violence and excessive use of force by Iranian authorities against protesters across the country, urging restraint and the immediate restoration of communications as unrest enters its third week. “All Iranians must be able to express their grievances peacefully and […]

Ukraine: New strikes disrupt basic services for millions

Ukraine: New strikes disrupt basic services for millions

This article is published in association with United Nations. Several parts of Ukraine were hit by a new wave of Russian strikes between Wednesday and Thursday morning. The attacks over the last 24 hours left civilians reportedly killed and injured in the port city of Odesa, interrupting power and water supplies there, as well as in […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading