Logo webu

Risks related to the use of various web applications and services

15.7 2024 | 10 min read | author: Kateřina Vaňková

It is usual that newly emerging or smaller companies are eagerly using freely available web applications and services known as SaaS – Software as a Service for their operations. This does not apply only to mail services, although these are probably a typical example. Nowadays, the share of web services is increasingly expanding and the Internet is offering services that until recently were the preserve of local devices. The cloud, the provision of infrastructure, but also special and until recently expensive services are becoming more and more prominent. This form has become almost mainstream and is considered secure. But are there situations to watch out for?

Kateřina is a Security Consultant focusing on information security management system, risk management and business continuity. In ensuring compliance with standards and laws, she has experience in conducting maturity assessments and setting corrective measures, especially in the area of ISO 27001 and the Czech Act on Cyber Security.

As with everything, it is good to be cautious when using technology. Just as it is not safe to persist with outdated technologies, too much courage and trust in new emerging services can eventually prove to be a high risk and can endanger the business itself. Decisions to use software as a service are not only based on rational or financial considerations and are often made under time pressure, but also in the euphoria of new possibilities. Let us now look together at the risks in the uncoordinated and decentralized use of these tools.

Information security

It is not possible to generalize and classify freely available software as a service as not secure or risky. The indisputable fact is that we have no control over the information stored in them. If we want to follow the old "trust but verify" rule, we must admit that we have to trust, but we have no way of verifying the facts. We must trust the availability of the online service, now and in the future. We must trust the reliability and trustworthiness of the provider, we have to trust the declared, or at least estimated, level of security. We have to trust in many ways, because the possibilities for verifying the claims of the service provider, the owner of the application, are minimal.

Open source solutions

Open source solutions are a recent trend. Surely no customer wants to be dependent on a particular product or software solution. There are known disadvantages of proprietary solutions such as dependency on technology, vendor lock-in, financial cost. At first glance, open source seems to be a preferable solution. But is it also secure? Can the product always be relied upon to be updated quickly and in the long term? Yes, open source code can be collaborated on by many experts and, in the case of downloads from proven platforms, the history of changes can be tracked. But here, too, there are usually concerns. 

Will there be any interest in the product from the co-creators and their followers? What if the author of the solution and other experts are not interested in further development of the product and we inadvertently build our infrastructure on top of it? What if malicious code gets into the update, even if it is a one-off update? There have been known cases in the past where hackers exploit vulnerabilities in open source code to plant a hidden threat. The questions are many and the answers are not very clear.

Evidence of tools and access to them

Even though these web tools often do not have a direct financial representation in accounting, they represent values for the company, because the functioning of the company is dependent on them and are therefore an asset. Here we encounter a systemic problem, how to manage and administer these assets. First of all, if a company takes the approach that the use of free tools is allowed, it is likely that a situation will quickly arise where a large number of these applications and tools will be tested and subsequently used. We know from experience that a prerequisite for using such tools is registration.

This can get out of control very quickly, because any worker will start to search for such tools and use them on his own initiative and creativity. And almost always with production data. In case the tool is evaluated as unviable, we have no way to verify the deletion of the potentially sensitive data, and the trace of the identity of the worker, the company, remains outside our control. Finally, we must be aware of the poor evidence of these tools. Workers often have no relation to a documentary and systematic record, especially if the tools are used in an uncoordinated way and without central supervision. 

Configurations and modifications

Briefly, we can mention that the configurability of web applications, especially if they are free, is minimal. Basically, we have to live with what the author of the application imagines. The possibility of customization to our organization is almost zero. In case the product does not suit us, we have the possibility to look for another one, but that does not mean that it will be perfect.

Integration of different tools with each other

By its very nature, it follows that different Internet applications have different origins, diversity and different levels and are fully isolated. Many of them are single-purpose and cannot communicate with other applications, but more and more of them use APIs. Even so, their mutual integration and orchestration is not easy and requires a certain amount of time and money. An example could be linking an issue tracking system with CMDB and monitoring, but there are certainly others. The processing of large amounts of data from different sources can also be problematic. All of this needs to be thought about before we rush headlong into a tempting offer.

Availability of the services and exit strategy

A fast internet connection is taken for granted nowadays, but connection stability may not be the rule. Faults can occur on your network equipment itself, internal cabling, but often also with the connection provider. Small and medium-sized enterprises usually do not have the means to build an alternative connection, or it is not even possible for technical reasons. 

Another risk in this category is the guarantee of service availability. This is also conditional on the hosting provider, but in addition to this, the management, patching and update system must also be taken into account. A high risk is the guarantee of long-term uptime and support. The provided service can thus remain either without support or, in a worse case, can be switched off from day to day. In this case, the company not only loses the solution to its needs, but also the data. Therefore is needed also develop and test the exit strategies for all at least core applications and services.

Recommendation in conclusion

At first glance, using freely available internet services and applications seems straightforward and seamless. In our article, we have only touched on some of the risks and mitigating them is often problematic or even impossible. We're not saying that the solution is to use proprietary products and build your own infrastructure, because it's not always worth it. We must be aware that using Software as a Service solutions can pose significant information security risks. These risks can come from a variety of sources, including unauthorized access, data breaches, and loss of sensitive information. To mitigate these risks, it is imperative that a company implements robust security measures, both technical and organizational. Where possible, the IT administrator must ensure that SaaS providers have strong security protocols in place and that they comply with relevant regulations and standards.

If we exclude reputable and proven, but paid solutions (such as the cloud provided by well-known companies), we have to realize that we often entrust our data and information to unknown and perhaps also start-up companies, which may not yet have built a strong background, infrastructure and implemented measures to secure and protect information. Since SaaS solutions involve storing data on third-party servers, there's an inherent risk of data breaches. Additionally, there may be concerns about data privacy, especially if the SaaS provider is in a different jurisdiction with potentially weaker data protection laws. It is therefore important for the company's responsible employees to have a clear understanding of their data and its location, as well as the security measures to protect it.

Especially in the case of SaaS, the company should have a disaster recovery plan in place to ensure business continuity in the event of a disaster or unavailability of the service. This means that it should have a developed and functional backup system for all its data, possibly in such a form that recovery is also possible to another similar tool or service, and a developed concept for restoring functioning in the event of a complete failure of the current solution. In the end, this also entails the need to know other products and services in order to ensure smooth operation. It is therefore very important to set clear rules for the use of these applications and services at the outset, to ensure that they are properly registered and to gain sufficient control over them.

Do you want to maximize cybersecurity in your organization? Contact us!

Right in Your Inbox

Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.

All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.