How to secure the modern cyber supply chain and surge in third-party risks amid AI automation

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Anna Sarnek, Director of Strategic Alliances, Valence Security


  • The number of data compromises linked to third-party integrations surged in 2023, significantly impacting organizations due to the interconnected nature of modern SaaS (software as a service) environments.
  • Organizations must adopt comprehensive SaaS security strategies, including asset identification, configuration management and integration auditing, to mitigate vulnerabilities and data breaches.
  • Integration of AI and SaaS application adoption means robust third-party risk management practices have become paramount for securing critical business data and applications.

The year 2023 ended as another record breaker for the number of data compromises organizations face. In the last year, 41% of the organizations that suffered a material incident say a third party caused it. In the United States, over a thousand entities were affected due to a successful attack on just 87 organizations, highlighting the level of cyber risk that third parties create today.

While most organizations are keenly aware of the risk that third parties present, third-party risk management focuses on assessing cyber security postures or cyber hygiene without the additional context of how these third parties are connected to the organization – i.e. what the cyber supply chain looks like.

Modern distributed infrastructure, which relies heavily on software as a service (SaaS) usage, creates endless new opportunities for unmonitored access to corporate data and processes. To exploit cloud environments, adversaries leverage misconfigurations, human error, social engineering, credential theft and other attack methods to compromise critical business data and applications.

SaaS applications have decentralized the procurement of IT as each business unit adopts its own productivity tools, leading to an explosion of application administrators sitting outside of IT and security teams. These SaaS applications come with a unique set of security features that must be independently configured, making them prone to human errors and leading to misconfigurations, creating a massive vulnerability for the organization.

As more and more applications participate in sensitive data workflows and are integrated with critical business applications, the likelihood of a data compromise increases.

Protection amid AI-accelerated automation

In addition to an increase in third-party breaches, 2023 has brought artificial intelligence (AI) into the innovation spotlight. Decades of AI and machine learning innovation have centred on automating processes to increase productivity, a technology that relies on third-party integration in software and technologies.

This year, 2024, will continue to shine the light on the benefit of incorporating AI into the modern workforce, a benefit that will accelerate and increase the third-party vulnerabilities that are already exploited today.

It is of the utmost importance that organizations focus on establishing strong SaaS security to contain third-party risk prior to further incorporating the benefit of AI into the organization.

Recommendation 1: Know your assets

SaaS application adoption has rapidly increased by 41% over the past two years, becoming a top vulnerability concern for chief information and security officers. Breaches and misconfigurations across applications such as Okta, Circle CI, Salesforce and Google Workspace indicate the challenges that organizations face, from core business to security SaaS applications.

For example, the Okta attack impacted 100% of its customer base, indicating that when it comes to SaaS-based third-party breaches, just one can have a ripple effect on thousands of organizations.

Far too often, organizations assume that solutions such as multi-factor authentication, developed to manage cloud-native assets, are fully deployed. Yet, every organization has at least 1% of their SaaS accounts not protected by multi-factor authentication, creating active risks.

While this may seem like a small risk, the Drizly credential stuffing attack highlighted how it just takes one account with weak authentication to lead to a major compromise. Furthermore, SaaS applications have evolved into platforms that store and share company data, increasing their susceptibility to human-error-led data exposure.

The distributed nature of SaaS procurement means that now more than ever, organizations need to have a good grasp of what their SaaS assets are, who manages them, and what information is stored in them to manage their security properly.

Recommendation 2: Manage and monitor the configurations

SaaS applications often come with a multitude of configuration options. Many security configurations are not turned on by default, leaving the application administrators responsible for proper security configurations. With the application administrators residing outside the IT business unit, many administrators inadvertently create risk for data exposure through weak access security.

The decentralized nature of SaaS application procurement means that the IT and the security organizations are not always aware of new application deployment in advance to catch the configuration risks created within the organization.

It is paramount for organizations to have a complete inventory of their SaaS applications and regularly monitor the security configurations to both ensure proper enforcement of security policy and mitigate any changes in the configurations over time that may make applications less secure.

Recommendation 3: Inventory and audit the integrations

One of the benefits of SaaS applications is plug-and-play and low-code or no-code integrations – the same thing that creates frictionless service interoperability also creates new exposure to vulnerabilities.

A key benefit of SaaS products is their ability to plug and play with other applications by connecting through integrations to consolidate and simplify data access and application functionality. However, this same functionality that creates interoperability creates vulnerabilities by introducing a spaghetti bowl of entry points into applications that house critical business and customer data.

On average, SaaS platforms have hundreds of integrations available that create an authorized handshake between multiple platforms. A typical organization has over 50% inactive integrations. These integrations create an authorized path for attackers to silently access critical SaaS applications that can lead to a wider compromise. Moreover, organizations have an average of 21 integrations with organization-wide access, paving a global path for systemic compromise.

Many of the inactive integrations within organizations stem from remnants of old vendors and no longer used proofs of concept, creating a shadow risk. To minimize such risk, organizations must actively monitor where the third-party integrations are created between applications and the level of access the integrations have. Periodic audits of SaaS applications should also enforce the rotation of secrets and authentication tokens to minimize the risk of credential theft over time.

By proactively understanding, managing and auditing SaaS assets, their configurations and integrations, organizations can fortify their defences against third-party risks and safeguard critical data in the modern digital ecosystem.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]
UN Photo/Eskinder Debebe UN Relief Chief Tom Fletcher (centre) along with Ambassador Mike Waltz (right) and Jeremy P. Lewin of the United States hold a joint press briefing on funding to the humanitarian system.

UN welcomes $1.8 billion US boost for humanitarian operations

This article is published in association with United Nations. An additional $1.8 billion in US humanitarian funding will allow the United Nations and its partners to expand emergency relief operations reaching millions of people worldwide, as rising global needs and funding shortfalls force aid agencies to scale back assistance. The funding announcement, made on Wednesday by […]
© WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]
This article was exclusively written for The European Sting by Mr. Franco Miguel Nodado, a 4th-year medical student from the Philippines. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Autism Spectrum Disorders in Global Health: Bridging the Gap in  Awareness, Early Diagnosis, and Inclusive Care 

This article was exclusively written for The European Sting by Ms. Georgia Maria Vardalachaki, a medical student from the Medical University of Crete, Greece. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s […]
© WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

Hantavirus-hit ship evacuation completed as quarantines begin

This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Strait of Hormuz de-escalation is urgent, says UN chief

This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
This article is published in association with United Nations.

Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
Nuclear energy in the Middle East: A realistic choice or a risk?

Nuclear energy in the Middle East: A realistic choice or a risk?

This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Bahrain and US float Security Council resolution on the Strait of Hormuz

This article is published in association with United Nations. Bahrain and the United States have circulated a draft Security Council resolution calling for Iran to cease attacks in the Strait of Hormuz, their ambassadors outlined to journalists at UN Headquarters in New York on Thursday. The text is supported by Kuwait, Qatar, Saudi Arabia and the […]
© CDC An enhanced microscopic image shows the Hantavirus.

Hantavirus outbreak: Another passenger contracts disease

This article is published in association with United Nations. It’s been confirmed that another passenger from the cruise liner linked to the outbreak of hantavirus has contracted the disease, which has claimed the lives of three people on board and sparked an international alert coordinated by the UN World Health Organization (WHO). The individual, who is […]
This article is published in association with United Nations.

UN warns of worsening human rights crisis in Mali after deadly attacks

This article is published in association with United Nations. The human rights situation in Mali is rapidly deteriorating following coordinated attacks by armed groups across the country, with civilians killed, displaced and cut off from food and aid, UN rights office OHCHR said on Tuesday. The violence, which erupted on 25 and 26 April, saw large-scale […]
© UNICEF A damaged ambulance in Tebnine in southern Lebanon.

In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
© Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

Uncertainty continues over safety in the Strait of Hormuz

This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]
© ADB/Ariel Javellana Women farmers in India sell wheat grain and buy fertilizer with the proceeds.

Middle East crisis puts aid, food, fuel further out of reach for millions already struggling – UN agencies

This article is published in association with United Nations. As the Middle East crisis continues the humanitarian fallout is worsening, with aid route disruptions and food and fuel price hikes wrecking the lives and the rights of the most vulnerable people worldwide, UN agencies warned on Friday. Heightened insecurity and instability around key Gulf routes, including […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com