The Shadow SaaS Blind Spot: A CISO's Story from @BlackHatOfficialYT
Unixi
0:00 / 0:00
The Shadow SaaS Blind Spot: A CISO's Story from @BlackHatOfficialYT
44 просмотра · 12 дней назад
Unixi
19 подписчиков
44 просмотра · 12 дней назад
Recorded live at Black Hat USA 2026: A routine offboarding audit uncovered 20% of employees using shared, unmanaged accounts on apps invisible to the IDP. Here's what a former CISO learned about the shadow SaaS blind spot, and why it changed his career.
Even mature identity programs (Entra ID, SAML, conditional access, SOC 2-certified) can be blind to a massive category of applications. In this talk, a former enterprise CISO shares the real story behind a simple spot audit that exposed a fundamental flaw in IDP-based identity governance, and why the real perimeter has shifted to the browser layer.
You'll learn:
-Why 1 in 5 apps in most orgs exist completely outside the IDP
-How shared, password-only accounts create invisible offboarding risk
3 root causes of the IDP visibility gap, including the "SSO tax" that makes secure login economically irrational for many vendors
-Why browser-layer visibility is the new identity perimeter
4 steps to audit your own environment for shadow SaaS - starting this week
📌 Quick audit checklist:
Pull login data from your browser security portal
Ask a team what apps they actually log into
Audit your last 5 offboardings for real app access, not just IDP records
Review 30 days of actual login activity org-wide
Unixi's universal SSO platform delivers a new reality over SaaS apps — no integrations, no SSO tax, just passwordless access with 100% SaaS app coverage.
Learn more at www.unixi.io
#IAM #ShadowIT #ShadowSaaS #CISO #IdentitySecurity #CyberSecurity #ZeroTrust