Trust is the primary source of risk within modern IT environments, according to Kaseya’s 2026 SaaS Security Report. Threat actors have abandoned perimeter attacks in favour of softer targets like identities, OAuth integrations and collaboration workflows, leaving a trust gap most small and mid-sized businesses can’t see, let alone close.
The report analysed more than 27.6 billion SaaS security events across over 50,000 SMB environments, including 5,400 MSP partners and 6.2 million end-user accounts. The data highlights a critical reality: as SaaS ecosystems expand, everyday operational conveniences like unmanaged guest accounts – which now make up 69% of all monitored accounts – persistent third-party access and externally shared data are creating massive security liabilities for small and mid-sized businesses.
The rush to adopt AI has triggered a sprawl of third-party OAuth integrations that use persistent tokens instead of credentials, granting attackers permanent data access even after password resets. Consequently, non-human service principal logins now account for 20% of critical security alerts. Simultaneously, attackers use AI-driven automation to instantly locate and exploit dormant guest accounts, weaponising these forgotten entry points faster than manual defences can react.
Legacy controls like geolocation blocks are also failing as attackers route traffic through trusted cloud hosts and VPNs. Outside North America, 44% of unauthorised logins originated from trusted infrastructure and outsourced hubs – including 7% in the UK – allowing intruders to blend into normal business traffic. Once inside, they exploit massive identity gaps: 56% of accounts lacked active MFA, and only 27% of SMBs enforced organisation-wide MFA. This exposure, combined with a rise of file sharing, allows attackers to silently exfiltrate data from within the network.
To counter these evolving threats, organisations must transition from rigid perimeter defences to active, identity-first governance frameworks. Bridging the modern trust gap requires businesses to move away from static event tracking and instead prioritise automated behavioural monitoring that can flag anomalous activity inside trusted accounts.






