Risks related to the use of various web applications and services
It is usual that newly emerging or smaller companies are eagerly using freely available web applications and services known as SaaS – Software as a Service for their operations. This does not apply only to mail services, although these are probably a typical example. Nowadays, the share of web services is increasingly expanding and the Internet is offering services that until recently were the preserve of local devices. The cloud, the provision of infrastructure, but also special and until recently expensive services are becoming more and more prominent. This form has become almost mainstream and is considered secure. But are there situations to watch out for?
Kateřina is a Security Consultant focusing on information security management system, risk management and business continuity. In ensuring compliance with standards and laws, she has experience in conducting maturity assessments and setting corrective measures, especially in the area of ISO 27001 and the Czech Act on Cyber Security.
As with everything, it is good to be cautious when using technology. Just as it is not safe to persist with outdated technologies, too much courage and trust in new emerging services can eventually prove to be a high risk and can endanger the business itself. Decisions to use software as a service are not only based on rational or financial considerations and are often made under time pressure, but also in the euphoria of new possibilities. Let us now look together at the risks in the uncoordinated and decentralized use of these tools.
Information security
It is not possible to generalize and classify freely available software as a service as not secure or risky. The indisputable fact is that we have no control over the information stored in them. If we want to follow the old "trust but verify" rule, we must admit that we have to trust, but we have no way of verifying the facts. We must trust the availability of the online service, now and in the future. We must trust the reliability and trustworthiness of the provider, we have to trust the declared, or at least estimated, level of security. We have to trust in many ways, because the possibilities for verifying the claims of the service provider, the owner of the application, are minimal.
Open source solutions
Will there be any interest in the product from the co-creators and their followers? What if the author of the solution and other experts are not interested in further development of the product and we inadvertently build our infrastructure on top of it? What if malicious code gets into the update, even if it is a one-off update? There have been known cases in the past where hackers exploit vulnerabilities in open source code to plant a hidden threat. The questions are many and the answers are not very clear.
Evidence of tools and access to them
Even though these web tools often do not have a direct financial representation in accounting, they represent values for the company, because the functioning of the company is dependent on them and are therefore an asset. Here we encounter a systemic problem, how to manage and administer these assets. First of all, if a company takes the approach that the use of free tools is allowed, it is likely that a situation will quickly arise where a large number of these applications and tools will be tested and subsequently used. We know from experience that a prerequisite for using such tools is registration.
Configurations and modifications
Briefly, we can mention that the configurability of web applications, especially if they are free, is minimal. Basically, we have to live with what the author of the application imagines. The possibility of customization to our organization is almost zero. In case the product does not suit us, we have the possibility to look for another one, but that does not mean that it will be perfect.
Integration of different tools with each other
By its very nature, it follows that different Internet applications have different origins, diversity and different levels and are fully isolated. Many of them are single-purpose and cannot communicate with other applications, but more and more of them use APIs. Even so, their mutual integration and orchestration is not easy and requires a certain amount of time and money. An example could be linking an issue tracking system with CMDB and monitoring, but there are certainly others. The processing of large amounts of data from different sources can also be problematic. All of this needs to be thought about before we rush headlong into a tempting offer.
Availability of the services and exit strategy
A fast internet connection is taken for granted nowadays, but connection stability may not be the rule. Faults can occur on your network equipment itself, internal cabling, but often also with the connection provider. Small and medium-sized enterprises usually do not have the means to build an alternative connection, or it is not even possible for technical reasons.
Recommendation in conclusion
At first glance, using freely available internet services and applications seems straightforward and seamless. In our article, we have only touched on some of the risks and mitigating them is often problematic or even impossible. We're not saying that the solution is to use proprietary products and build your own infrastructure, because it's not always worth it. We must be aware that using Software as a Service solutions can pose significant information security risks. These risks can come from a variety of sources, including unauthorized access, data breaches, and loss of sensitive information. To mitigate these risks, it is imperative that a company implements robust security measures, both technical and organizational. Where possible, the IT administrator must ensure that SaaS providers have strong security protocols in place and that they comply with relevant regulations and standards.
If we exclude reputable and proven, but paid solutions (such as the cloud provided by well-known companies), we have to realize that we often entrust our data and information to unknown and perhaps also start-up companies, which may not yet have built a strong background, infrastructure and implemented measures to secure and protect information. Since SaaS solutions involve storing data on third-party servers, there's an inherent risk of data breaches. Additionally, there may be concerns about data privacy, especially if the SaaS provider is in a different jurisdiction with potentially weaker data protection laws. It is therefore important for the company's responsible employees to have a clear understanding of their data and its location, as well as the security measures to protect it.
Especially in the case of SaaS, the company should have a disaster recovery plan in place to ensure business continuity in the event of a disaster or unavailability of the service. This means that it should have a developed and functional backup system for all its data, possibly in such a form that recovery is also possible to another similar tool or service, and a developed concept for restoring functioning in the event of a complete failure of the current solution. In the end, this also entails the need to know other products and services in order to ensure smooth operation. It is therefore very important to set clear rules for the use of these applications and services at the outset, to ensure that they are properly registered and to gain sufficient control over them.
Do you want to maximize cybersecurity in your organization? Contact us!
Right in Your Inbox
Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.
You Might Also Be Interested
On June 4th, we participated in the ABIT conference in Bratislava, where we presented on the topic External Perimeter Threats. We discussed current challenges and strategies for protecting organizations against external cyber threats. The conference also focused on various aspects of cybersecurity, IT continuity, and third-party management according to the DORA regulation. We thank the organizers for a great event and look forward to the next edition!
Discover the techniques of OSINT and their application in cybersecurity! OSINT (Open Source Intelligence) provides valuable insights from publicly available sources, helping to identify threats, track attacker activities, and respond swiftly to incidents. Learn how to leverage OSINT for monitoring security risks, tracking your supply chain, and increasing security awareness in your organization. Gain practical tips and tools for effective cyber defense.