For security professionals seeking insight into emerging threats, Mandiant's annual M-Trends report has long served as an essential compass. Drawing from countless hours of incident response work, this year's findings cast a particularly stark light on a challenge that's been lurking in the shadows for years: the rapidly expanding—and increasingly vulnerable—SaaS attack surface.
Here's a reality check that might sting a bit: while organizations have enthusiastically embraced cloud and SaaS solutions for their undeniable benefits (who doesn't love scalability and flexibility?), they've stumbled into a security twilight zone. The shared responsibility model between providers and customers leaves IT and security teams trying to secure identities and manage configurations across 10’s if not 100’s of disparate SaaS tools, all with unique options and business requirements. That is, if they even know the tool is being used in the first place.
These findings from the report underscore this risk:
The 2025 M-Trends report confirms what many defenders feel: SaaS is where business happens, and where attackers follow. The organizations that fare best are those that:
The writing on the wall couldn't be clearer: understanding and securing your SaaS attack surface isn't just another checkbox on your security to-do list—it's becoming as fundamental as having a disaster recovery plan.
Nudge Security discovers every SaaS and GenAI account ever created by anyone in your org within minutes of starting a free trial and provides security posture checks to help you prioritize and resolve SaaS security risks. Learn more about Nudge Security's approach to SaaS security and governance.