How to Protect SaaS and IaaS Data From Attackers

TL;DR
Protect SaaS and IaaS data by enforcing access controls inside applications, reducing unnecessary API accounts, managing each service’s changing configuration, and monitoring connections between platforms. Attackers can exploit exposed data, misconfigurations, and machine identities to move laterally from one cloud application to another, so perimeter defenses alone are insufficient.
Transcript
Good morning, everybody. Can you hear me? Yes. Eight thirty in the morning on Wednesday of RSA. All right, my promise to you is at no point in the next fifty minutes am I gonna ask you to raise your hand for any reason. It's my one promise to you. I'm really impressed that this many people showed up. I was out last night, and I made a bet with some... Read More
Key Insights
- Broken access control is the leading SaaS risk highlighted in the presentation because it can undermine other safeguards. Once an attacker passes perimeter, device, firewall, or application defenses, weak internal permissions can provide the final path to the data that the attacker actually wants.
- Data is the primary target of cloud attacks, not merely access to networks or applications. Access control represents the last mile between an intruder and valuable information, so protecting data within SaaS services must remain central to security architecture and operational monitoring.
- SaaS collaboration is enabled by broad accessibility from web browsers, devices, locations, and times. The same design that makes cloud services convenient to administer and use also exposes more paths to stored data, making protection more difficult than within a single controlled data center.
- Cloud configuration risk is fragmented across platforms because Salesforce, Amazon S3, Microsoft 365, Jira, Okta, Slack, and Zoom use different administrative and configuration systems. A specialist who can secure one environment may not possess the expertise required to configure every other service safely.
- SaaS configurations are continuously changing as providers release new features, functionality, portals, and settings. Security teams must therefore maintain current knowledge and repeatedly reassess their posture rather than treating initial hardening as a permanent solution for any cloud application.
- APIs increase both cloud utility and security exposure because applications are intentionally designed to exchange data. If an attacker gains control of an API account, that trusted machine identity may provide access to information without requiring the same path used by an interactive human account.
- Machine accounts constitute one in four identities in SaaS applications, according to the presentation. Although these identities are necessary for integrations, organizations often fail to remove unnecessary default API accounts or adequately restrict the access granted to accounts that remain active.
- Lateral movement in SaaS is movement from one application to another through integrations, shared data, configuration changes, or API identities. This differs from traditional movement between devices, servers, and folder trees, and it requires defenders to examine trust relationships spanning multiple cloud services.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How can organizations protect data stored in SaaS applications?
Organizations can protect SaaS data by applying strong access controls inside each application, not only at the network perimeter. They should identify exposed information, understand what each user and machine identity can access, remove unnecessary API accounts, restrict required integrations, review configurations continuously, and monitor how connected applications can be used to reach sensitive data.
Q: Why is broken access control a major SaaS security risk?
Broken access control is a major risk because perimeter defenses do not determine what an authenticated identity can reach after entering an application. If internal permissions are too broad, an attacker who gets through device, firewall, or application controls may access valuable data directly. Weak access controls can also reduce the effectiveness of several other security safeguards.
Q: Why is SaaS data difficult to secure?
SaaS data is difficult to secure because cloud applications are designed for convenient access and collaboration from browsers, devices, locations, and times around the world. Each platform also has a different configuration stack that changes as new features appear. Connected applications and APIs create additional trust paths through which identities can access or share stored information.
Q: How do APIs create security risks in SaaS environments?
APIs create risk because they intentionally connect applications and allow data to move between them. Attackers who obtain an API account may use its trusted permissions to access information. Risk grows when organizations retain unnecessary default accounts, grant excessive privileges, or fail to control machine identities connecting Salesforce and other business applications to external services.
Q: What are machine accounts in SaaS security?
Machine accounts are identities used by applications and APIs to communicate with other services rather than by people signing in interactively. The presentation states that one in four SaaS identities are machine accounts. These identities are not inherently unsafe, but default, unnecessary, or poorly controlled accounts can give attackers a valuable route to application data.
Q: What does lateral movement mean in a SaaS environment?
Lateral movement in SaaS means moving from one cloud application to another through integrations, APIs, shared information, or configuration weaknesses. Traditional lateral movement often involved traveling between devices, servers, or folder trees within one environment. Cloud services expand that concept because trusted connections can let access obtained in one application lead to data held elsewhere.
Q: Why cannot one security configuration approach protect every SaaS platform?
One approach cannot protect every platform because each SaaS service has its own configuration stack, administrative controls, data model, and changing features. Expertise in Amazon S3 does not automatically provide the knowledge needed to secure Salesforce, Microsoft 365, or Jira. Organizations must evaluate every application separately while also understanding the connections and dependencies between them.
Q: How did remote work increase cloud security challenges?
Remote work accelerated the adoption of SaaS, IaaS, and collaboration platforms while distributing employees and devices beyond traditional data centers. One organization described moving from five data centers for fifteen hundred employees to effectively worrying about fifteen hundred locations. Another compressed a planned three-year Microsoft Teams rollout into three weeks, reducing the time available for deliberate implementation.
Summary & Key Takeaways
-
SaaS applications make data accessible from browsers, devices, and locations around the world, enabling collaboration while complicating protection. Because the objective of an attack is usually valuable data, organizations must extend zero-trust thinking beyond networks and applications to the access controls governing information stored within each cloud service itself.
-
Every SaaS and IaaS environment has its own configuration stack, administrative model, and pace of change. Expertise in securing one platform does not automatically transfer to Salesforce, Microsoft 365, Amazon S3, Jira, or another service. Organizations therefore face multiple, continuously changing configuration risks rather than one consistent security boundary.
-
APIs connect cloud applications and increase their business value, but they also create paths for attackers. Machine identities account for one in four identities in SaaS applications, according to the presentation. Unnecessary or weakly controlled API accounts can expose data and enable lateral movement from one application to another through trusted integrations.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator