Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

CNAPP vs. SaaS security: where cloud visibility still falls short


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Cloud security platforms can map workloads, identities, and attack paths inside the cloud, but Vorlon argues that many real breaches now happen in the SaaS integration layer that sits beyond CNAPP visibility. The boundary problem is structural: OAuth tokens, third-party apps, and non-human identities can move data quietly across tools without cloud-native controls seeing the abuse.

NHIMG editorial — based on content published by Vorlon: Cloud security visibility stops at the SaaS boundary

By the numbers:

Questions worth separating out

Q: Where does CNAPP fail in SaaS environments?

A: CNAPP fails when the important access path is not inside the cloud boundary.

Q: Why do SaaS misconfigurations cause so many breaches?

A: They cause breaches because access and visibility errors often expose data directly, without requiring an exploit chain.

Q: How should security teams govern third-party OAuth access for SaaS integrations?

A: Treat third-party OAuth grants as NHI assets with owners, scopes, and lifecycle rules.

Practitioner guidance

  • Define the SaaS identity boundary List the SaaS applications, OAuth grants, and third-party integrations that sit outside your CNAPP coverage and assign ownership for each one.
  • Review durable delegated access Audit tokens and integrations that were approved once and never revisited, especially where permissions exceed the current business need.
  • Treat AI-driven workflows as a separate identity class Separate conventional service accounts from AI agents that can chain tool calls across SaaS applications.

What's in the full article

Vorlon's full article covers the operational detail this post intentionally leaves for the source:

  • A breakdown of SaaS-to-SaaS visibility gaps and where CNAPP coverage ends.
  • Examples of OAuth and integration abuse patterns that security teams can use for investigation planning.
  • A closer look at how non-human identities and AI agents change the SaaS threat model.
  • The vendor's view of where ecosystem security complements cloud-native controls.

👉 Read Vorlon's analysis of CNAPP limits in SaaS security →

CNAPP vs. SaaS security: where cloud visibility still falls short?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

CNAPP was designed for cloud-origin risk, not ecosystem-origin risk. That assumption fails when the most sensitive business workflows live in SaaS applications that exchange data through OAuth, APIs, and third-party integrations. The implication is that cloud security maturity can coexist with blind spots at the integration layer, so practitioners must stop treating cloud coverage as a proxy for SaaS governance.

A few things that frame the scale:

  • The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.

A question worth separating out:

Q: What is the difference between CNAPP and SaaS security?

A: CNAPP secures cloud infrastructure, workloads, and cloud identities. SaaS security governs the access paths, integrations, and data movement that happen between business applications, often through OAuth tokens and non-human identities. They are complementary, but they answer different risk questions.

👉 Read our full editorial: CNAPP visibility stops at the SaaS boundary



   
ReplyQuote
Share: