Closing the Forgotten SaaS Account Security Gap With Kaseya
The Business of CybersecuritySeptember 23, 2026
47
00:21:4819.97 MB

Closing the Forgotten SaaS Account Security Gap With Kaseya

Could your security team produce an accurate list of every employee, contractor, guest account, application, and AI agent with access to your SaaS environment today?

In this episode of The Business of Cybersecurity, I speak with Jim Lippie, Chief Product Officer at Kaseya, about findings from the company’s latest SaaS security research. The report draws on anonymized activity from the SaaS Alerts platform, covering 27 billion security events across 50,000 organizations.

One finding immediately stands out. Only 44% of monitored organizations were using multifactor authentication. When the research began in 2022, the figure was 32%. Four years of heightened cyber awareness have therefore produced an increase of only 12 percentage points.

The report also found that guest accounts represented 69% of monitored accounts. This means guest users outnumbered licensed users by over two to one.

Jim explains how these accounts accumulate. A consultant, contractor, or temporary employee receives access to company systems, completes the work, and leaves. The account remains because nobody owns the process of removing it. Over time, these forgotten identities create unattended routes into business data and applications.

Our conversation examines how SaaS has changed the security perimeter. Employees no longer need to be inside an office or connected through a corporate network. A browser, valid credentials, and access to a cloud application may be enough. Security teams must therefore monitor user behavior, permissions, locations, and unusual patterns rather than relying on controls designed around the office firewall.

AI agents add another category of identity. An autonomous system performing workflow tasks may require access to files, email, customer data, financial systems, or internal applications. Jim argues that these agents should be treated like users, with defined permissions and continuous behavior monitoring.

We also discuss the tension created by easy collaboration. The report found that 34% of monitored file sharing traveled outside the organization. That sharing may be legitimate, but businesses need to understand which information has left, who received it, and whether access remains appropriate.

Jim’s advice is deliberately practical. Begin with a complete assessment of the environment. Identify every account and application, require MFA, give guest access an expiration date, monitor behavior, and use overlapping security controls where a second source of evidence can expose missed activity.

Does your organization have genuine visibility across its SaaS environment, or are forgotten accounts and unmonitored identities creating doors nobody remembers opening? Listen to the episode and share your thoughts with me.

Useful Links