• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Are SaaS Apps the Achilles’ Heel for Supply Chain Attacks?

Think Tank
Think Tank RSS FeedRSS

Are SaaS Apps the Achilles’ Heel for Supply Chain Attacks?

A PAIR OF HANDS WORK ON A LAPTOP IN A DARK ROOM. COMPUTER TEXT HOVERS ABOVE THE PERSON'S HANDS.

Photo: iStock / Sergey Shulgin

November 16, 2023
Alexander Adamov, SCB Contributor

The shift toward an increasingly digital workforce has led to a massive increase in software-as-a-service (SaaS) applications. These promise everything from simplified communications to improved efficiency, and users have literally thousands of options from reputable companies and private developers from which to choose. Yet many apps come with serious vulnerabilities, turning them from an asset into a liability. 

With varying access and threat levels, these apps can have a catastrophic impact on the security of supply chains. Case in point is the recent space of supply chain attacks on established software providers such as SolarWinds’ Orion Platform, Kaseya VSA, GitHub and Viasat KA-SAT. In April, 2022, GitHub identified an attack on two third-party vendors critical to its supply chain, Travis CI and Heroku. Despite acting quickly, the company acknowledged that this type of breach could have led to a more extensive supply chain attack and compromised mission-critical infrastructure.

Time is critical when dealing with SaaS attacks. The more information that’s compromised, the greater the potential for damage. Attacks are swift, taking advantage of the time gap to infiltrate systems before victims become aware and can take action. Though GitHub took the proper reactionary measures, the lack of an accurate inventory of third-party vendors’ access privileges cost it valuable response time.

Managing and reducing SaaS app risks is a time-consuming and complex process. Following are five proactive measures that companies can take to minimize the impact.

Understand the scope of access and permissions requests from SaaS apps. When a company’s IT team installs SaaS applications, they must be aware of every access token used, and which permissions are required. IT security teams need an accurate picture of their SaaS app inventory to verify credibility authorship and identify risks. Failure to do so can delay a company’s ability to find security compromises, address those weaknesses and prevent further damage.

Build a software bill of materials to manage risks. SBOMs, both "Deployed" and "Runtime," are vital tools for managing risk associated with SaaS applications. A Deployed SBOM identifies software that's active on a system and analyzes its execution behavior in a possible simulated development setting. Runtime SBOMs, sourced from the system operating the software, document current system components and any external interactions or dynamically loaded elements. These might also be termed "Instrumented" or "Dynamic" SBOMs.

Regardless of which SBOM you use, it should provide a comprehensive list of software details such as license type, patch status and component version. Software that’s outdated or poses high-security risks becomes much easier to observe and address.

Enforce least privilege when granting SaaS app permissions. Supply chain vendors, internal vendors and other entities should only be granted the minimum level of access needed to perform their duties. Limiting access prevents attackers from moving laterally through the organization and doing even more extensive damage. Enforcing least privilege provides a simplified way to manage potential SaaS risks across supply chain segments.

Continuously monitor cloud environments. SaaS defense requires continuous defense. Admins have a bevy of tools for ensuring the performance, security and availability of resources. One important option is monitoring services provided by cloud service providers. Real-time insights into performance and health metrics ensure early detection and faster response times. In addition, there are a host of third-party monitoring tools on the market that act as a second safety net.

Conduct an inventory of SaaS apps. At-home environments — the software and networks employed by remote workers — are riskier than private environments, thanks to non-existent or weak security policies. LastPass experienced this firsthand in December, 2022 when an engineer’s home computer was compromised. Threat actors were able to successfully run remote code execution capabilities and plant keylogger malware, allowing for capture of the engineer’s master password and access to the LastPass corporate vault. Following the initial attack, they could steal encrypted data and secure notes until they got to the company’s AWS S3 LastPass production backups, cloud-based storage, and mission-critical database backups.

Cybersecurity is essential for every aspect of business, including supply chains. IT teams need policies and procedures that identify access levels of their personnel and software, cloud and third-party monitoring, and an accurate inventory of SaaS apps. Revealing and mitigating supply chain security should be a top priority for organizations.

Alexander Adamov is chief security researcher for Spin.AI, and a professor at NURE and BTH universities.

HR & Labor Management Regulation & Compliance Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • On Demand - Webinar Descartes Tue Jun 23 2026 11a ET.png

    Descartes AI Exchange: AI Agents for Fleet Performance Management

    General SCM
  • A UNIFORMED OFFICER STANDS NEAR A HIGHWAY WITH TRUCKS ON IT

    U.S. Customs Ramps Up AI Investment in Push to Sharpen Enforcement

    Artificial Intelligence
  • On Demand Webinar - Arkieva - Wed Jun 24 2026 2p ET.png

    Shift Left Planning: Why Many Plans Fail to Execute—and How to Fix It

    Webinars
  • A MAP OF THE STRAIT OF HORMUZ SHOWING DOZENS OF BLUE DOTS DISTRIBUTED THROUGHOUT THE WATERWAY

    Traffic Flows Through Hormuz Despite Shock Ship Attack

    Global Gateways
  • On Demand Webinar 4flow Thu Jun 25 2026.png

    How Mars uses 4flow's AI platform for Logistics optimization

    Webinars

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing