wonderfully unique software solutions

SaaS monitoring from LastPass tackles shadow IT fears and AI risk

LastPass has added SaaS monitoring to its secure-access and password-management portfolio in a bid to help organisations reduce shadow IT and shadow AI risks.

At the Black Hat 2025 cybersecurity expo this month, LastPass unveiled SaaS Protect. The feature is aimed at enabling SMBs to shore up defences against unauthorised IT use, including AI apps.

Don MacLennan, LastPass chief product officer, said SaaS Protect targets businesses with resource constraints that need more visibility as well as policy enforcement and credential protection.

“SMBs face a perfect storm of complexity — unknown risks living within unknown apps and AI services,” MacLennan said.

“We built SaaS Protect to turn that chaos into clarity.”

Accordingly, LastPass had bulked up its SaaS monitoring capabilities with customisable SaaS app policies, credential risk detection, and real-time enforcement reporting.

Shadow IT or AI is when staff introduce technology tools or applications to the network without their employer’s authorisation.

Because new or unneeded software can introduce risks and cost to the IT estate, shadow tech adoption is a common concern.

How improving SaaS monitoring helps

For example, IT managers can use the product to restrict access to unsanctioned or high-risk SaaS apps. At the same time, they can issue customised warnings to workers involved, the vendor said.

Managers can also use SaaS Protect to generate governance reports with SOC 2 and other compliance frameworks in mind. In addition, it can identify duplicate apps or excessive licensing, LastPass said.

SaaS Protect works via browser extension, with activity data and policy enforcement results populated to the admin console, it said.

Organisations can have many more applications installed than they really need. “This mix of sanctioned and unsanctioned tools creates a sprawling, fragmented attack surface,” LastPass said.

At the same time, around 78% of users reuse the same password across multiple accounts, it said.

The vendor expects SaaS Protect to be generally available in early autumn.

( Photo by Markus Winkler on Unsplash )

Recent Articles

spot_img

Related Stories

Leave A Reply

Please enter your comment!
Please enter your name here

Weirdware monthly - Get the latest news in your inbox