No Insurer Has Asked Which SaaS Apps You Use

Estimated reading time: 6 minutes

Nudge Security CEO Russell Spitler says cyber insurance applications miss the question that decides SaaS supply chain risk. He has yet to see an insurer ask for a company’s list of applications.

In August 2025, attackers stole OAuth tokens from Salesloft’s Drift integration. They used them to pull data out of Salesforce instances across many companies. Google’s threat intelligence team tracked the campaign from 8 to 18 August.

Every victim shared two vendors. An insurer trying to size its exposure would have needed to know which policyholders used both.

“An insurer would never be able to see the aggregation of a Salesloft Drift-type event,” Spitler told Cyber Insurance News.

The Question Missing From The Application

Spitler is co-founder and chief executive of Nudge Security. The company launched Adaptive Risk Management on 30 September. It rescores each SaaS and AI application as its use inside a company changes.

Spitler says the underwriting process is looking elsewhere.

Russell Spitler, co-founder and CEO of Nudge Security, discussing SaaS supply chain risk with Cyber Insurance News.
Nudge Security CEO, Russell Spitler

“The modern insurance assessment process does next to nothing to understand the use of AI and SaaS in an organization,” he said. “Questionnaires are dominated by endpoint security, backup, and MFA controls.”

He named the two questions he has not seen asked. “We have yet to see an insurer ask the basic question of ‘What SaaS apps does your company use,’ and more importantly, ‘What process do you use to ensure that inventory is complete.'”

The inventory gap is wide, according to Nudge. The company says most organizations actively manage only 30% to 40% of the SaaS and AI tools in use. It says customers typically find two to three times more tools than they expected.

SaaS Supply Chain Risk After Approval

Nudge’s case rests on what happens after a vendor passes review. Employees connect the approved app to other tools and AI agents. They share more sensitive data with it. They invite outside collaborators.

See also  Got an Opinion on Whether the Feds Should Take a Major Role in Cyber Insurance? You've Still Got Time to Weigh In with the Government

The 2026 Verizon Data Breach Investigations Report puts third-party involvement at 48% of breaches, up 60% from the prior year.

Nudge’s score draws on more than 30 factors. Inputs include access granted, data touched, and stale OAuth grants. Another is whether an AI agent or MCP server connects to the app. That factor relates to the exposure behind the recent findings from the AI Security Institute’s GPT-6 Astra. There, an autonomous agent acted beyond its approved scope in simulation.

The drift can be small. Vercel said its April 2026 incident began with a compromised third-party AI tool used by one employee. The attacker moved from there into the employee’s Google Workspace and Vercel accounts.

Who Carries The Liability

Cyber Insurance News asked who is liable when approved SaaS use drifts into unsanctioned risk. Spitler did not hedge.

“The employee’s company is 100% liable,” he said. “If they approved an app for a particular use, and their own employees start using features or managing data outside that sanctioned use, it’s on the company.”

Vendor contracts often restrict what data a customer may share, he said. That shifts liability onto the customer. “This isn’t regulated in any environment, and it’s a natural part of the day-to-day work for almost every employee these days.”

What The Score Can And Cannot Show Yet

Nudge has not worked with an insurer. Spitler said so plainly. The six-month early access period involved no insurance companies.

He sees an opening in the market’s mood. He pointed to “the recent cynicism” insurers have shown about outside-in risk scores. Their predictive value is in question, he said.

Other scoring firms report early uptake. Andrew Horkan of Cyber Tzar told this week’s podcast that one broker already uses his score before binding.

The release says strong controls such as SSO and MFA can cut an app’s residual risk “by as much as 60%.” That figure comes from Nudge’s model. Asked for evidence against incidents or losses, Spitler described the wider set of factors behind the score. SSO and MFA account for “a substantial portion of the risk removed,” he said. He meant broad attacks on SaaS and AI apps over five years.

The Aggregation View

On a Salesloft Drift-type event, Spitler says Nudge’s position is the one insurers lack. “We can not only enumerate that full set, but also identify the customers that had used the compromised integration,” he said.

He says Nudge helped customers find their exposure within minutes. It also listed which of their other apps had Salesloft in their own supply chain.

For a carrier, that is the accumulation question at the level of a single integration. One compromised connector reaches every company that installed it.

Get The Cyber Insurance New Upload
Subscribe to our weekly newsletter!

How SaaS Supply Chain Risk Builds Quietly

Diego Izquierdo, senior cybersecurity engineer for third-party risk management at Mercado Libre, uses Nudge. He described how the exposure forms in practice. A company can hold strong controls in a tool like Slack. Then users connect less-secure third-party apps to it.

That, he said, “can create a breach path without anyone realizing a new risk was introduced.

FAQ – SaaS Supply Chain Risk

What is SaaS supply chain risk?

The exposure a company inherits from the software-as-a-service apps it uses and the integrations connecting them. A compromised connector can give attackers access to data held in other, trusted applications.

Do cyber insurance applications ask about SaaS apps?

Russell Spitler of Nudge Security says he has yet to see an insurer ask what SaaS apps a company uses, or how it ensures that inventory is complete. He says questionnaires focus on endpoint security, backup and MFA.

See also  Cyber Risk Underestimation: Why Business Confidence Is Outpacing Cyber Reality

What happened in the Salesloft Drift incident?

Between 8 and 18 August 2025, attackers used OAuth tokens stolen from Salesloft’s Drift integration to export data from Salesforce instances at multiple organizations, according to Google’s threat intelligence team.

Who is liable when employees use an approved app in unapproved ways?

Spitler says the employee’s company is fully liable, noting that vendor contracts often restrict what data customers may share. That is his view as a security vendor, not a legal ruling.

Has any insurer used Nudge Security’s risk scores?

No. Spitler says Nudge worked with early access customers for six months before launch and has not yet engaged an insurance company.

How common is third-party involvement in breaches?

The 2026 Verizon Data Breach Investigations Report puts it at 48 percent of breaches, up 60 percent from the prior year.

Leave a Comment

×