Insights

Cyber Security Trends in SaaS Companies

The Software and Services industry was the highest growth sector for G3 Cyber in 2025 and remains one of the most active environments for cyber risk, particularly for organisations that operate or invest in SaaS platforms.

We support investors and SaaS operators to strengthen security across product lifecycles, infrastructure, and customer‑facing digital estates. Our approach combines targeted defensive assessments with practical, real-world testing to identify key risks before they become material issues.

The following trends reflect the issues we most frequently observe when supporting SaaS companies.

Customer interaction is the weakest point

SaaS platforms have limited control over customer security practices. Many companies struggle to enforce MFA, retire long‑lived API keys, or set minimum security requirements that are designed to protect both customer and platform interests.

Authorisation is harder than authentication

Identity management is still a challenge, but the greater difficulty often comes from preventing individuals holding excessive or unnecessary access to sensitive information and, in some cases, production environments.

Infrastructure visibility

Many SaaS companies are unclear when new servers or services are deployed without proper controls in their cloud environments. Enforcing those controls and detecting when they are bypassed is a major issue across the sector.

Restoring databases is harder than you think

Most companies have a strategy for database restoration, but this usually covers only one or a small set of customers. When the need arises to restore full databases or entire data centres, the process becomes far more complex, with timelines stretching far beyond original estimates.

Pipeline visibility

Many organisations have separate pipelines with different tools. Incompatibility across vulnerability scanning tools means you lose a single pane of glass view into vulnerabilities which results in poor visibility of real and consolidated risk.

The transition from monoliths to microservices

We see substantial amounts of legacy code, long‑standing technical debt, and situations where companies are caught between monolith and microservice. Newer code and microservices may follow good security practices, but the monolith usually lag and implementing proper security can feel like an overwhelming challenge.

Unclear roles, responsibilities, and accountability

As organisations grow, questions emerge about who is responsible for security in the product and enterprise environments. Development environments typically sit awkwardly between the two. In some cases, the person responsible for securing the product is primarily focused on releasing features, which can create security gaps and misaligned priorities.

Bespoke tools often don’t meet COTS standards

We frequently encounter home‑grown tools that aim to deliver most of the capability of an off‑the‑shelf WAF or API gateway. Issues frequently arise in missing functionality and a lack of consistent security‑driven support. Without the right level of resource, expertise and maintenance, bespoke tools are not a practical solution.​

 

Contact us

If you would like to discuss any of the themes raised in this article, or to hear how we are supporting organisations across sectors and geographies to become more resilient, please do not hesitate to reach out:

Kate O’Loghlen, Head of Cyber  

kateologhlen@g3.co