Demo Request
Take a personalized product tour with a member of our team to see how we can help make your existing security teams and tools more effective within minutes.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Home
Blog

Reco Launches The State of SaaS Security Report

Kate Turchin
Updated
November 19, 2024
February 4, 2025
5 min read
Ready to Close the SaaS Security Gap?
Chat with us

Analyzing over 6,600 SaaS environments, this inaugural report uncovers the risks, trends and countermeasures for SaaS security

New York – November 12, 2024 – Reco, a leading provider of SaaS security, announced today that it has published The State of SaaS Security 2024, an inaugural cybersecurity research report that uncovers the biggest risks and trends in SaaS security. By analyzing over 50 organizations and 6,600 SaaS environments, Reco identified the most common misconfigurations, risks, and threats to SaaS data security across all industries today that organizations can use to secure their expanding SaaS footprint.

The report reveals critical trends and strategic opportunities that will help shape the future of SaaS security:

  • Generative AI surge in enterprises – On average, companies are using 17 Generative AI applications, which represents a year over year increase.
  • The shadow SaaS blindspot  –  Apps are flying under the radar, increasing the chance of a data breach.
  • MFA oversight – 1 in 10 accounts are still vulnerable. 
  • The continued explosion of SaaS and unauthorized apps – Many apps are outside of the purview of security teams.
  • Data leak dangers – Misconfigurations are common in SaaS platforms; one particular critical misconfiguration was seen in over 90% of Salesforce implementations.

“We’re excited to provide these findings to the industry in order to highlight critical security gaps that may pose risks to many organizations’ sensitive data. By bringing these issues to the forefront, organizations can consciously work toward safer, more secure collaboration via SaaS applications,” said Ofer Klein, CEO and Co-Founder of Reco.

The report also touches on remediation recommendations that organizations can put into action in order to more effectively secure their SaaS ecosystems. By implementing the right SaaS Security solution, along with the right controls and governance programs, organizations can reduce the risk of damaging breaches while empowering workforces with the latest and greatest SaaS applications that improve efficiency, communication, and revenue generation.

About Reco 

Reco is a full lifecycle SaaS security solution. It empowers organizations with full visibility into every app, identity, and their actions to seamlessly prioritize and control risks in the SaaS ecosystem. Their AI-based graph technology connects in minutes and provides immediate value to security teams to continuously discover all SaaS applications including sanctioned and unsanctioned apps, shadow apps, associated identities from both humans and machines, their permission level, and actions. Reco uses advanced analytics around persona, actions, interactions and relationships to other users, and then alerts on exposure from misconfigurations, over-permission users, compromised accounts, and risky user behavior. This comprehensive picture is generated continuously using the Reco Identities Interaction Graph and empowers security teams to take swift action to effectively prioritize their most critical points of risk. Reco uses a low-code/no-code approach to add a new SaaS integration in 3-5 days. The company’s leadership team brings expertise and innovation from leading technology, cybersecurity and counterintelligence organizations. Reco is backed by top-tier investors including Insight Partners, Zeev Ventures, BoldStart Ventures, and Angular Ventures and has established partnerships with leading technology companies including Wiz, Palo Alto Networks, SecurityScorecard, BlinkOps, Tines and Torq. Reco was named a Global Infosec Awards winner in 2024 for “Hot Company, SaaS Security” and a CRN® 2024 Stellar Startup. You can learn more or book a demo at www.reco.ai.

Media Contact

Kate Turchin

Director of Demand Generation, Reco

katet@reco.ai

No items found.

Kate Turchin

ABOUT THE AUTHOR

Kate Turchin is the Director of Demand Generation at Reco.

Technical Review by:
Gal Nakash
Technical Review by:
Kate Turchin

Kate Turchin is the Director of Demand Generation at Reco.

Ready to Close the SaaS Security Gap?
Chat with us
Table of Contents
Get the Latest SaaS Security Insights
Subscribe to receive updates on the latest cyber security attacks and trends in SaaS Security.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Explore Related Posts

OpenClaw: The AI Agent Security Crisis Unfolding Right Now
Alon Klayman
OpenClaw, the viral open-source AI agent with over 135,000 GitHub stars, has triggered the first major AI agent security crisis of 2026 with multiple critical vulnerabilities, malicious marketplace exploits, and over 21,000 exposed instances. When employees connect these autonomous agents to corporate systems like Slack and Google Workspace, they create shadow AI with elevated privileges that traditional security tools can't detect. Reco's platform provides the visibility security teams need to identify OpenClaw integrations, audit permissions, and assess risk before incidents occur.
SaaS and AI Security Is Here: Reco Raises Series B to Dominate the Future of AI Usage in SaaS
Ofer Klein
After 400% growth, Reco raises $30M Series B to address the AI SaaS security gap, where traditional tools can't see the thousands of AI apps, agents, and integrations that now power modern enterprises. This round was led by Zeev Ventures, with participation from all our existing investors—Insight Partners, boldstart ventures, and Angular Ventures—and new corporate investors including Workday Ventures, TIAA Ventures, S Ventures, and Quadrille Capital.
When AI Becomes the Insider Threat: Understanding Risks in Modern SaaS Environments
Tal Shapira
As AI becomes deeply embedded across SaaS platforms, it is increasingly operating with trusted internal access once reserved for employees and service accounts. This article examines how AI can function as an insider threat, why these risks are harder to detect than traditional insider activity, and what signals security teams should watch for. It also explores common governance gaps, real-world scenarios, and practical approaches organizations can take to reduce AI-driven insider risk without limiting legitimate AI use.
See more featured resources

Ready for SaaS Security that can keep up?

Request a demo