September 30, 2026

Nudge Security Unveils Adaptive Risk Management to Track How SaaS and AI Risk Changes as Usage Evolves After Approval

New capability continuously reassesses risk as employees connect integrations, expand access, and adopt AI tools, closing a gap left by one-time vendor reviews.

Nudge Security

AUSTIN, Texas, Sept. 30, 2026 – Nudge Security, a leader in SaaS and AI security governance, today announced Adaptive Risk Management, new functionalities that respond to changes in SaaS and AI vendor risk as well as internal usage, helping security teams to more effectively manage risk across a sprawling SaaS and AI attack surface.

‍

Most organizations evaluate a vendor once, during procurement, and treat that assessment as settled. But an application’s criticality and risk to a specific business isn’t static. After the vendor review and approval is complete, employees often connect it to other business apps and AI agents, share more sensitive data, or invite more internal and external collaborators – often without security’s knowledge or review. Traditional third-party risk tools are built to monitor a vendor’s external security posture and internal security controls applied once. They are not built to reassess or apply additional security controls as enterprise usage changes.

‍

Nudge Security does both, continually monitoring vendors’ external risk posture and recalculating an application’s risk score as internal usage changes. As risk scores change, Nudge Security applies and recommends appropriate mitigating and compensating controls, natively and through third-party security integrations, creating a truly adaptive risk management program.

‍

“Nudge provides a relational view across applications, users, integrations, browser extensions, and authentication that surfaces where security actually needs improvement,” said Diego Izquierdo, Senior Cybersecurity Engineer, Third Party Risk Management at Mercado Libre. “For example, an organization can have very strong controls in a tool like Slack, but if users connect less-secure third-party apps into it, that can create a breach path without anyone realizing a new risk was introduced. That integrated perspective on risk is what makes Nudge unique.”

‍

Third-party involvement in breaches has risen 60% year over year to account for 48% of all breaches, according to the 2026 Verizon Data Breach Investigations Report. Compressed vulnerability cycles in the post-Mythos era stand to accelerate that trend further, and recent supply chain incidents (including those at Vercel, Salesloft Drift, and LastPass) have already shown how quickly access granted to one application can expose an entire environment. Security teams are increasingly asked not just whether a vendor is secure, but what that vendor's access can actually reach inside their environment right now – a question a point-in-time review can’t answer on its own. Compounding this challenge, most organizations actively manage only 30–40% of the SaaS and AI tools actually in use, and typically discover two to three times more tools than they expected with Nudge Security.

‍

‍Adaptive Risk Management is built to close that gap by continuously combining what’s known about a vendor’s security, supply chain risk, and compliance program with what’s actually happening inside a customer’s own environment. 

  • Automatic app criticality tiering: Every application is automatically classified by the breadth of use across the organization along with the sensitivity of the data it typically handles, using a proprietary AI model that identifies up to 29 distinct data types, so security teams know which applications matter most without reviewing each one manually.
  • Continuous risk scoring: Each application gets a dynamic risk score built from more than 30 factors, combining a vendor’s external security posture with how that specific application is being used inside a customer’s environment: approval status, access granted, data touched, MCP connections, who or what is using it, what security controls in place, and what security findings are failing. Scores update automatically as those factors change, rather than waiting for the next scheduled review. That includes signals like whether a vendor's OAuth grants are stale or unused, whether an AI agent or integration is connected to the app, and whether employees are authenticating through single sign-on or with standalone credentials.
  • A direct line from risk to action: Nudge Security ranks the specific control gaps driving an app's risk score — such as enabling SSO or closing a stale OAuth grant — by how much closing each one would reduce that risk, and in many cases security teams can act on it directly from the risk panel. The platform also adapts its own monitoring as an app's importance changes: mark an app business-critical, and Nudge automatically begins surfacing additional findings for it — like password reuse or weak authentication — that weren't being tracked before.

‍

Nudge Security's risk dashboard, showing residual risk trends and a heatmap of business criticality versus risk severity across an organization's SaaS and AI portfolio.

‍

Risk scores update automatically as those factors change — and Nudge Security customers using strong compensating controls like SSO and MFA can reduce an app's residual risk by as much as 60%.

‍

“Too many organizations still treat third-party risk as an annual exercise, while in reality, the conditions that impact risk change every single day,” said Jaime Blasco, co-founder and CTO of Nudge Security. “An application approved for a handful of employees becomes entrenched across the business. Someone connects an AI tool to sensitive data or grants an integration broader access. A breach at one of your vendors suddenly turns that access into a potential path into your environment. Your last vendor assessment won’t tell you what’s at risk now. We built Adaptive Risk Management to connect changes in usage, access, and a vendor’s security posture so security teams can continuously reassess their exposure and act as it changes.

‍

Nudge Security built its risk model on its own data rather than third-party scoring services, drawing on a self-populating database of more than 250,000 SaaS and AI vendor security profiles. That means Adaptive Risk Management can assess an application from the moment it enters an environment, without requiring vendor cooperation, manual data entry, or even prior knowledge that the application was in use.”

‍

Availability
Adaptive Risk Management is available now to all Nudge Security customers.

‍

About Nudge Security
Nudge Security delivers SaaS and AI security governance at the Workforce Edge, where employees make thousands of technology decisions daily. Our automated, policy-driven guardrails reach employees when and where they work, enabling rapid technology adoption while minimizing risk and sprawl. Through unrivaled discovery capabilities, AI-driven risk insights, and behavioral science-based engagement, we make security a natural part of how modern work gets done rather than an obstacle to innovation. Nudge Security was founded in 2021 by Russell Spitler and Jaime Blasco and is backed by Cerberus Ventures, Ballistic Ventures, Forgepoint Capital, and Squadra Ventures.

‍

Media Contact:

Danielle Ostrovsky
Hi-Touch PR

[email protected]