Summary is AI-generated, newsdesk-reviewed
  • SaaS Alerts SASI Report analyses 136 million security events, highlights Russia, China-originated attacks.
  • Report reveals 10,000 daily brute force attacks, identifies top cyber threat vectors.
  • SMBs face risks from guest accounts, third-party apps, and risky file-sharing behaviours.

SaaS Alerts, a cybersecurity firm tailored for MSPs to safeguard and capitalise on their clients' SaaS applications, has released the latest findings from its SaaS Application Security Insights (SASI) Report.

This report, published every six months and freely available for download, is unique in its analysis of around 136 million SaaS security events across 2,100 small and medium businesses worldwide, uncovering cyber trends posing risks to these enterprises.

SASI Report Findings

The recent SASI report offers a comprehensive examination of security events from over 120,000 user accounts spanning January 1st to December 31st, 2021. A significant majority of attacks on top SaaS platforms—such as Microsoft 365, Google Workspace, Slack, and Dropbox—were found to originate from Russia and China. This considerable dataset assists solution providers in managing SaaS application portfolios, aligning defensive IT security measures as necessary.

Analysis indicates that these countries may be coordinating their attack efforts

Analysis indicates that these countries may be coordinating their attack efforts. SaaS Alerts reports significant activity increase from these nations, with consistent levels of both attempted and successful cyberattacks. Comparisons between attack trends from Russia and China reveal near-identical patterns, while deviations from patterns in countries like Germany support this hypothesis of coordinated efforts.

Cyber Threat Landscape

The Brookings Institute notes that the US National Security Strategy classifies Russia and China as the two primary threats to its national security.

It states, "Russia’s increasingly close relationship with China represents an ongoing challenge for the United States." SaaS Alerts monitored over 136 million security events within the same timeframe to discern cyberattack patterns targeting popular SaaS applications used by SMBs.

Key Findings of the Report

1) The analysis revealed an average of about 10,000 Brute Force Attacks per day on monitored user accounts.
2) Potential attack origins include China, Vietnam, Russia, Korea, and Brazil, with unauthorised login attempts originating from these regions.
3) Successful logins using legitimate user credentials were traced back to actors in the same countries.
4) Common critical security alerts stem from:

  • Successful logins from unapproved locations trigger alerts for user accounts accessible from outside approved areas.
  • SaaS Integration alerts highlight risk from third-party application connections sharing data between SaaS Apps.
  • Multiple Account Lockouts are recorded when accounts face repeated lock attempts, suggesting programmatic password testing by malicious actors.

5) The report also highlights significant threat vectors, including the use of Guest User Accounts by SMBs, with 42% of monitored accounts being guest users. It emphasises the risk associated with third-party OAuth app integrations and risky file-sharing behaviour, noting that 19% of cloud-based file sharing occurs externally rather than internally, potentially facilitating malicious access if unmanaged.

Managing Security in an Uncertain Cyber-Environment

"In the uncertain cyber-climate we all reside in today, detailed SaaS security oversight and robust defences are a requirement for ensuring high resiliency and business continuity," said Jim Lippie, CEO of SaaS Alerts. He added that data loss, theft, or corruption could severely impact SMBs reliant on uninterrupted operations, a target for threat actors for years. The report serves to offer businesses and the MSPs supporting them, valuable insights into their security environment.

Focus on Security Management and Compliance

For MSPs, the security management and compliance of SaaS applications used by SMBs have become increasingly crucial. Emphasising the importance of SaaS-optimised security controls, building a security-oriented employee culture focusing on these controls, as well as procedural compliance, can significantly mitigate the risk of successful attacks.

In case you missed it

What are emerging applications for physical security in transportation?
What are emerging applications for physical security in transportation?

Transportation systems need robust physical security to protect human life, to ensure economic stability, and to maintain national security. Because transportation involves moving...

Gallagher & Fortified enhance perimeter security solutions
Gallagher & Fortified enhance perimeter security solutions

Global security manufacturer - Gallagher Security is proud to announce a strategic partnership with Fortified Security, a pioneering perimeter systems integrator with over 30 years...

Genetec: Data sovereignty in physical security
Genetec: Data sovereignty in physical security

Genetec Inc., the global pioneer in enterprise physical security software, highlights why data sovereignty has become a central concern for physical security leaders as more survei...