Estimated reading time: 6 minutes
Nudge Security CEO Russell Spitler says cyber insurance applications miss the question that decides SaaS supply chain risk. He has yet to see an insurer ask for a company’s list of applications.
In August 2025, attackers stole OAuth tokens from Salesloft’s Drift integration. They used them to pull data out of Salesforce instances across many companies. Google’s threat intelligence team tracked the campaign from 8 to 18 August.
Every victim shared two vendors. An insurer trying to size its exposure would have needed to know which policyholders used both.
“An insurer would never be able to see the aggregation of a Salesloft Drift-type event,” Spitler told Cyber Insurance News.
The Question Missing From The Application
Spitler is co-founder and chief executive of Nudge Security. The company launched Adaptive Risk Management on 30 September. It rescores each SaaS and AI application as its use inside a company changes.
Spitler says the underwriting process is looking elsewhere.
“The modern insurance assessment process does next to nothing to understand the use of AI and SaaS in an organization,” he said. “Questionnaires are dominated by endpoint security, backup, and MFA controls.”
He named the two questions he has not seen asked. “We have yet to see an insurer ask the basic question of ‘What SaaS apps does your company use,’ and more importantly, ‘What process do you use to ensure that inventory is complete.'”
The inventory gap is wide, according to Nudge. The company says most organizations actively manage only 30% to 40% of the SaaS and AI tools in use. It says customers typically find two to three times more tools than they expected.
SaaS Supply Chain Risk After Approval
Nudge’s case rests on what happens after a vendor passes review. Employees connect the approved app to other tools and AI agents. They share more sensitive data with it. They invite outside collaborators.
The 2026 Verizon Data Breach Investigations Report puts third-party involvement at 48% of breaches, up 60% from the prior year.
Nudge’s score draws on more than 30 factors. Inputs include access granted, data touched, and stale OAuth grants. Another is whether an AI agent or MCP server connects to the app. That factor relates to the exposure behind the recent findings from the AI Security Institute’s GPT-6 Astra. There, an autonomous agent acted beyond its approved scope in simulation.
The drift can be small. Vercel said its April 2026 incident began with a compromised third-party AI tool used by one employee. The attacker moved from there into the employee’s Google Workspace and Vercel accounts.
Who Carries The Liability
Cyber Insurance News asked who is liable when approved SaaS use drifts into unsanctioned risk. Spitler did not hedge.
“The employee’s company is 100% liable,” he said. “If they approved an app for a particular use, and their own employees start using features or managing data outside that sanctioned use, it’s on the company.”
Vendor contracts often restrict what data a customer may share, he said. That shifts liability onto the customer. “This isn’t regulated in any environment, and it’s a natural part of the day-to-day work for almost every employee these days.”
What The Score Can And Cannot Show Yet
Nudge has not worked with an insurer. Spitler said so plainly. The six-month early access period involved no insurance companies.
He sees an opening in the market’s mood. He pointed to “the recent cynicism” insurers have shown about outside-in risk scores. Their predictive value is in question, he said.
Other scoring firms report early uptake. Andrew Horkan of Cyber Tzar told this week’s podcast that one broker already uses his score before binding.
Get The Podcast
A defense supplier held every certificate on the list, then opened 17,000 ports after a server move nobody had to report. Cyber Tzar CEO Andrew Horkan explains why compliant isn’t the same as secure. Watch the episode →
The release says strong controls such as SSO and MFA can cut an app’s residual risk “by as much as 60%.” That figure comes from Nudge’s model. Asked for evidence against incidents or losses, Spitler described the wider set of factors behind the score. SSO and MFA account for “a substantial portion of the risk removed,” he said. He meant broad attacks on SaaS and AI apps over five years.
The Aggregation View
On a Salesloft Drift-type event, Spitler says Nudge’s position is the one insurers lack. “We can not only enumerate that full set, but also identify the customers that had used the compromised integration,” he said.
He says Nudge helped customers find their exposure within minutes. It also listed which of their other apps had Salesloft in their own supply chain.
For a carrier, that is the accumulation question at the level of a single integration. One compromised connector reaches every company that installed it.
Get The Cyber Insurance New Upload
Subscribe to our weekly newsletter!
How SaaS Supply Chain Risk Builds Quietly
Diego Izquierdo, senior cybersecurity engineer for third-party risk management at Mercado Libre, uses Nudge. He described how the exposure forms in practice. A company can hold strong controls in a tool like Slack. Then users connect less-secure third-party apps to it.
That, he said, “can create a breach path without anyone realizing a new risk was introduced.
FAQ – SaaS Supply Chain Risk
What is SaaS supply chain risk?
The exposure a company inherits from the software-as-a-service apps it uses and the integrations connecting them. A compromised connector can give attackers access to data held in other, trusted applications.
Do cyber insurance applications ask about SaaS apps?
Russell Spitler of Nudge Security says he has yet to see an insurer ask what SaaS apps a company uses, or how it ensures that inventory is complete. He says questionnaires focus on endpoint security, backup and MFA.
What happened in the Salesloft Drift incident?
Between 8 and 18 August 2025, attackers used OAuth tokens stolen from Salesloft’s Drift integration to export data from Salesforce instances at multiple organizations, according to Google’s threat intelligence team.
Who is liable when employees use an approved app in unapproved ways?
Spitler says the employee’s company is fully liable, noting that vendor contracts often restrict what data customers may share. That is his view as a security vendor, not a legal ruling.
Has any insurer used Nudge Security’s risk scores?
No. Spitler says Nudge worked with early access customers for six months before launch and has not yet engaged an insurance company.
How common is third-party involvement in breaches?
The 2026 Verizon Data Breach Investigations Report puts it at 48 percent of breaches, up 60 percent from the prior year.
Related Cyber Insurance Posts
- SMBs Get Easier Access to Cyber Insurance with SaaS Alerts and FifthWall Solutions(Opens in a new browser tab)
- BOXX Insurance Expands Cyber Insurance Coverage with New Tech E&O Product for AI and SaaS Firms(Opens in a new browser tab)
- Hidden OAuth Grants Draw New AI Agents: Nudge Security Targets A Cyber Insurance Blind Spot(Opens in a new browser tab)
- Neon Cyber Launches Workforce Cybersecurity Platform to Protect Modern Teams(Opens in a new browser tab)