Report by Cloud Security Alliance

State of SaaS Security Report: Trends and Insights for 2025-2026

10 FINDINGSPublished Apr 22, 2025
View Original Report →

Key Findings

SaaS security is a top priority for 86% of organisations, with 76% increasing their budgets this year.

SaaSBudget

46% of organisations are struggling to monitor non-human identities (NHIs).

SaaSNon-human identities

55% of respondents shared that employees are adopting SaaS tools without security's involvement.

SaaS

79% of organisations expressed confidence in their security programs.

SaaSSecurity program

54% of organisations lacked automation for lifecycle management.

SaaSAutomationLifecycle management

63% of organizations report external data oversharing and 56% say employees upload sensitive data to unauthorized SaaS apps.

SaaSData exposure

56% of organisations concerned with over-privileged API access.

SaaSAPI

Too many organisations are relying on fragmented strategies, such as vendor-native tools (69%), general-purpose solutions like Cloud Access Security Brokers (CASBs) (43%), and manual audits (46%)

SaaSFragmentation

58% of respondents said enforcing proper privilege levels was difficult.

SaaSPrivileges

57% of organisations reported they are grappling with fragmented SaaS security administration.

SaaSFragmentation