Skip to content

The Overlooked Link Between SaaS Visibility, FinOps and Cybersecurity

SaaS visibility stopped being a procurement problem some time ago. It is now the control that finance and security both depend on — and neither can enforce a policy against an application they cannot see.

In the race to modernise IT, many organisations have adopted SaaS as a fast, flexible way to deliver business value. With that agility comes complexity, and with complexity comes risk. SaaS adoption has accelerated; visibility into usage, spend and security posture has not kept pace. The result is a growing blind spot that threatens financial control and cybersecurity at the same time.

CIOs and CISOs are arriving at the same conclusion from different directions. SaaS visibility is not a procurement issue or an IT operations issue. It is a control that several functions depend on, and it either exists or it does not.

What SaaS sprawl actually is

The average organisation now runs 305 SaaS applications. Very few of them can name all 305.

That is the shape of the problem. Employees can onboard a new application with a corporate card and a few clicks, bypassing procurement entirely. The democratisation of technology buying genuinely does drive innovation — it also produces a fragmented landscape of tools, data stores and access points that nobody has an inventory of.

Sprawl is not a failure of discipline. It is the predictable outcome of a purchasing model where the barrier to adopting a new system is lower than the barrier to filing an expense claim.

How sprawl becomes a security problem

Most organisations underestimate how many SaaS applications are in use, and by whom. Shadow IT, duplicate subscriptions and unmanaged licences are normal rather than exceptional. Beyond the financial waste, the absence of an inventory introduces specific security exposures:

  • Unvetted applications may not meet your security standards or your data sovereignty requirements, and nobody assessed them because nobody knew about them.
  • Orphaned accounts stay active long after the person has left. The identity provider licence is usually removed on day one; the twelve applications that were never connected to it are not.
  • Delegated access is the one people miss. An OAuth grant made to a third-party application persists after the person who consented to it has gone, and it can still hold read access to shared drives and mailboxes.
  • Data leakage becomes much harder to detect when sensitive information is distributed across dozens of platforms that appear on no register.

Without a clear inventory of what is in use, you cannot enforce a policy, manage access, or respond credibly to an incident.

Why FinOps is more than an ally to security

FinOps — financial operations for technology spend — is usually read through the lens of cost optimisation. Its principles are increasingly relevant to security.

At its core, FinOps promotes accountability, transparency and collaboration across IT, finance and the business. Those are the same three properties a working security programme needs:

  • Accountability means every application has a named owner who is answerable for its compliance and its security posture.
  • Transparency means IT and security can see usage patterns, access levels and where data actually flows.
  • Collaboration means risk is shared rather than decided in silos and discovered later.

When the FinOps and security functions work from the same inventory, they identify risky applications, remove redundant tools and align SaaS use to both the budget and the policy. They are usually looking at the same list of applications for different reasons, which is exactly why they should not be maintaining two lists.

Visibility is the foundation of control

Security begins with visibility. In a SaaS context, visibility means knowing:

  • what applications are in use
  • who is using them, and how often
  • what data they can reach
  • how they are configured, and whether they sit behind single sign-on
  • where your data goes
  • whether they comply with your internal standards and your external obligations

That level of insight is what makes identity and access management enforceable, anomaly detection meaningful and incident response possible. It is also what GDPR, SOC 2 and ISO 27001 assessments are really asking for when they ask you to demonstrate control over data and systems.

What that looks like when it ships

This used to be the point in the argument where the honest answer was that the tooling had not caught up. It has.

CerteroX SaaS Management converges three independent discovery signals rather than trusting any one of them: identity provider sync from Entra ID and Okta, connector sync that pulls the authoritative user and licence list from the vendor itself, and a browser extension that detects SaaS domains and per-user time-on-application. The first two find what was bought. The third finds what was never bought — which is where shadow IT lives.

47 connectors ship today, resolving against a catalogue of more than 35,000 applications. Discovered applications are classified from their catalogue feature tags rather than a hardcoded list, which is why AI tools surface on the Shadow AI dashboard without anyone maintaining a list of them.

On the security side specifically:

  • OAuth grants are discovered and scored from 0 to 100 on data sensitivity, scope breadth, how consent was given and how long the grant has been dormant. Revocation is a single action, and it is available as a workflow step so it can fire automatically.
  • Offboarding produces evidence. A per-user checklist shows every licence the person held, the connector status behind each one, and whether revocation is pending, in progress or complete — alongside the monthly cost of whatever is still open. “The account was disabled” is not the same claim as “every grant and seat was revoked and here is the record”.
  • SSO coverage is measured, with a ranked list of the high-value applications sitting outside it.

The cost of ignoring sprawl

The consequences are not hypothetical. Breaches have been traced to misconfigured SaaS applications, forgotten accounts and unauthorised sharing. In many of those cases the root cause was not an absence of security tooling. It was an absence of knowledge about what needed protecting.

The financial side is easier to quantify: 46% of SaaS licences go entirely unused, and the average organisation uses 54% of what it pays for. Organisations overspend on duplicate subscriptions while missing the consolidation and renegotiation opportunities that a complete inventory would hand them. Without FinOps discipline the costs compound, and so does the exposure.

A strategic opportunity for IT leaders

The convergence of SaaS visibility, FinOps and cybersecurity is an opportunity rather than a burden, because one piece of work serves three functions. Treating SaaS governance as a cross-functional priority lets leaders:

  • reduce risk and evidence compliance
  • optimise spend and remove waste
  • strengthen the working relationship between IT, finance and security
  • build a technology base that can absorb change rather than react to it

This is not really about tools, though the tools now exist. It is about accepting that visibility is not a feature to be added later. It is the capability everything else rests on.

Related reading

Other posts covering the same ground.

  • Changing ITAM from a tick-box job to business enabler

    IT asset management stopped being an audit chore some time ago. Here is what it now does for finance, security, procurement and the service desk — and what changes the moment the data becomes trustworthy.

    • ITAM
    • Security
    • FinOps
    6 min
  • Certero unveils CerteroX at FinOps X 2025

    CerteroX was announced in San Diego as one platform bringing cloud cost management and SaaS optimisation together. Here is what was said at the show, and what the platform actually ships today.

    • SaaS
    • Cloud
    • FinOps
    4 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.