Obsidian Security

12 STATS1 REPORTS

All Statistics

The fastest time from initial access to data exfiltration was as little as 9 minutes.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

There was a 300% year-over-year increase in SaaS breaches between September 2023 and 2024.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

SaaS spend is approximately $8,700 per employee.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

85% of SaaS breaches began with a compromised identity.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

Adversary-in-the-middle (AiTM) attacks accounted for 39% of these incidents.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

MFA failed to prevent attacks in 84% of incident responses.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

Organizations typically deploy around 100 AI applications, with 60% lacking proper security controls or federation behind the IdP.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

The average cost of a SaaS breach has risen to $4.88 million.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

Organisations can achieve an 85% reduction in their SaaS attack surface with better security measures.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

The healthcare sector experienced the highest number of SaaS breaches from September 2023-2024, accounting for 14% of the total. This was followed by state and local government at 13% and financial services at 11%.

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

Other credential compromise techniques used to target SaaS applications included self-service password reset (24%), single-factor password guessing (14%), and push fatigue (13%).

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025

99% of SaaS compromises originate at the identity provider (IdP).

Obsidian SecuritySaaS Security Threat Report 2025·Jan 1, 2025