Sample domain · public signals only · no internal access
SaaS security is the discipline of controlling identity, application access, data sharing, and activity across cloud software so trust does not become an unmanaged path into business data.
Identity and trust are the recurring SaaS weak points.

Short answer: SaaS security is the practice of controlling who and what can reach a business's data inside cloud applications like email, file storage and collaboration tools. Kaseya's 2026 SaaS Security Report, drawn from 27.6 billion security events across 50,723 small businesses managed by 5,401 MSPs in 2025, shows the weak points are identity and trust rather than malware: guest accounts outnumber licensed users more than two to one, most accounts lack active MFA, and more than a third of shared files leave the organization.
The report's framing is that trust has become the crack in small-business environments: trust extended to guests, to connected apps, to unapproved tools, and to sessions that are never re-checked. I agree with that read, and I think it changes what an MSP should bring to a sales conversation. The attacker's view of a small business is one environment. Most small businesses defend it in disconnected pieces, and nobody is looking at the whole picture until an MSP does.
The numbers worth knowing by heart
These are the figures I would expect an MSP owner to be able to say without looking, all from Kaseya's 2026 SaaS Security Report covering calendar year 2025:
- 69 percent of the 6.26 million accounts monitored were guest accounts, not licensed users, an increase of more than 1.9 million guests over the prior year.
- 56 percent of end-user accounts had MFA disabled or inactive, and only 27 percent of the small businesses monitored were actively enforcing MFA policies.
- More than 277 million files were shared, double the 2024 volume, and 34.75 percent of them were shared outside the organization.
- In Microsoft 365 tenants, nearly half of shared files went external, compared with about a quarter in Google Workspace.
- Of 27.6 billion events, 98.9 percent were low severity, which still left more than 278.9 million medium and critical alerts.
Each one of those is a conversation opener, and each one is a question the prospect probably cannot answer about their own business.
Identity is the perimeter now
Two of the findings are about who can sign in. Guest accounts get created for a contractor, a supplier or a one-time project and then outlive the relationship by months or years. The report notes many are given the same permissions as staff. MFA gaps mean a stolen or guessed password is enough to walk in and operate as a legitimate user.
Put those together and the typical small tenant has more outsiders than employees on its account list, and most of the accounts on that list can be opened with a password alone. That is the sentence that gets an owner's attention.
The data leaves by invitation
External sharing is the finding owners feel most personally, because it is their files. The report calls out orphaned sharing links: links made for a short collaboration and never revoked, which leave documents open to former contractors or anyone who still holds the URL. Many of those links skip login entirely.
For regulated clients, that is a compliance issue as well as a security one. For the MSP, it is a scoping question: sharing policy, link expiration and a periodic review of what is exposed.
Attackers blend in
The report's fifth and sixth findings explain why none of this shows up on its own. Attackers route through ordinary cloud infrastructure and VPNs, so location-based rules miss them. Once inside, their activity looks like normal file access, app sign-ins and automated logins. Service principal sign-ins, the non-human identities apps use, made up 20 percent of critical alerts in 2025.
The practical lesson for MSPs selling into small businesses: the risk is sitting in configuration and identity, visible to anyone who looks at the tenant's accounts, grants and policies, and invisible to a client who only looks at whether the antivirus is green.
Where this meets the sales process
Kaseya's own State of the MSP Report says the share of MSPs struggling to quickly demonstrate value to prospects nearly doubled in a year, from 10 to 19 percent. The SaaS findings are the answer to that problem. Guest sprawl, MFA gaps and connected apps are measurable in a prospect's own tenant with read-only access, they are specific, and the prospect can verify every one of them.
Frequently asked questions
What is SaaS security?
SaaS security covers the controls that govern access to business data in cloud applications: identity and MFA, guest and external users, connected third-party apps, sharing settings and monitoring of sign-in and file activity.
What are the biggest SaaS security risks for small businesses in 2026?
Kaseya's 2026 SaaS Security Report identifies guest account sprawl, OAuth-connected apps, incomplete MFA, external file sharing, attackers hiding in trusted infrastructure, and high-risk alerts buried in event noise.
How many small businesses enforce MFA?
Only 27 percent of the more than 50,000 small businesses monitored in Kaseya's 2026 SaaS Security Report were actively enforcing MFA policies, and 56 percent of end-user accounts had MFA disabled or inactive.
How much file sharing in Microsoft 365 goes external?
Nearly half. Kaseya found about 45 percent of shared files in Microsoft 365 went outside the organization in 2025, compared with about 24 percent in Google Workspace, and 34.75 percent across all platforms monitored.
How should MSPs use SaaS security data in sales?
Measure the same risks in the prospect's own tenant, with their read-only consent, and present the results as specific findings rather than industry averages. Kaseya's data tells the owner the risk is common; their own tenant tells them it is theirs.
How SCOUTz gets you there
SCOUTz is prospect intelligence for MSPs. It turns the industry numbers above into facts about one specific prospect. From the domain alone, before any access, SCOUTz shows the prospect's public footprint. With a read-only Microsoft 365 connection the prospect approves, it adds the tenant picture: identity and MFA posture, connected and AI applications and the permissions they hold, and license use, all from configuration and never from mailbox or file content. Every finding names its evidence and lands in a branded report in your MSP's name with a work plan the owner can act on. Point it at any client and walk out with a deal. The open beta is free for thirty days at scoutzsecurity.io.
