Interviews

SaaS Sprawl Moves From IT Headache to Strategic Risk

Jeff Stewart, Group Vice President of Product Management at SolarWinds, explains why organisations need to move beyond simply cutting applications and focus instead on building a simpler, better-governed technology environment.

How serious has SaaS sprawl become for enterprises, and what are its biggest operational challenges?
SaaS sprawl has reached a point where the complexity of managing applications can start to outweigh the benefits they originally delivered. The issue is that SaaS products have matured, and there is now much more overlap between them than there was a few years ago.

A portfolio that once made perfect sense can now contain several tools accomplishing what is essentially the same thing. That creates unnecessary cost, but also more complex workflows, inconsistent processes, and a bigger security and management burden.

For boards, the question is no longer whether an individual application works. It probably does, and may have more functionality than when it was first bought. The real question is whether it still earns its place in the current technology mix. When capabilities overlap, the value of individual investments becomes much harder to justify and measure.

How can organisations identify redundant, overlapping or underutilised SaaS applications?
We are coming off several consecutive years of rapid technology adoption, while the AI race has added another wave of applications. In many cases, business units, rather than IT, have driven that adoption, so organisations first need to understand what they actually have. That means conducting a detailed audit of the technology estate, looking at what applications are being used, by whom and for what purpose. Those reviews often reveal several tools supporting the same workflow across different teams.

The difficult part is then deciding what stays and what goes. Cost should be part of that decision, but it simply cannot be the only factor. The goal is to simplify the environment while preserving the capabilities people genuinely rely on. Consolidation for its own sake rarely sticks.

What are the biggest security and compliance risks created by uncontrolled SaaS adoption?
The biggest risk is losing visibility and control over who has access to what. Unauthorised applications, excessive permissions, OAuth sprawl, public sharing of sensitive data, and insecure integrations, can all create openings that are difficult for IT teams to see.

There is also a very basic problem that organisations still struggle with, which is access that should have been removed but wasn’t. Former employees retaining access can turn a relatively simple offboarding gap into a serious security incident.

Research has found that 21% of organisations had discovered new unsanctioned SaaS or AI tools in the previous year, while 20% identified sensitive data being shared publicly. 18% experienced a breach involving an ex-user whose access had not been removed. Those numbers show that SaaS sprawl is not just a procurement issue. It is a security and governance issue.

How can IT teams balance employee demand for specialised tools with the need for greater application control?
The easiest thing to add to a business is software. It is almost always the hardest thing to remove. That does not mean organisations should respond with blanket bans. People often adopt specialised tools because they solve a genuine business problem. The better approach is to provide approved pathways for adoption, apply controls based on risk, and review exceptions over time rather than letting them become permanent.

There is also a positive shift happening among vendors. Smaller, specialised providers increasingly recognise that customers are looking to simplify their technology environments. They need to demonstrate how they complement broader platforms and integrate effectively with the rest of the ecosystem. That focus on interoperability is important because the future of enterprise IT is not one with fewer capabilities. It is about delivering those capabilities with less complexity.

Is SaaS consolidation becoming a strategic priority for CIOs, and what should enterprises consider before retiring applications?
CIOs today want to optimise costs, improve productivity, ensure seamless workflows and reduce unnecessary operational risk. SaaS consolidation just happens to be one of the most effective ways of achieving those objectives because of how much sprawl organisations have accumulated.

When retiring applications, the mistake is to treat it purely as a cost-cutting exercise. You need to understand which capabilities are essential for compliance, governance and efficiency, while also considering where the business is going next. Without that clarity, organisations can simply replace one form of sprawl with another, where teams make isolated procurement decisions, rather than building a technology environment around shared strategic objectives.

What practical steps can organisations take to reduce SaaS sprawl without affecting employee productivity or business operations?
The starting point is visibility. Build a complete picture of your applications, identities and usage, then understand which tools are genuinely business critical, where the risks sit and where functionality overlaps.

From there, look for the small wins first. Reclaim idle licences, eliminate duplicate accounts and reduce over-provisioned tiers before you start retiring applications. When you do consolidate, start by testing one workflow or business unit, then migrate users and data in phases with proper communication and training.

Finally, make this an ongoing discipline rather than a one-off clean-up. Automate joiner, mover and leaver processes, including permission and OAuth-token reviews, and measure the outcome through cost, adoption, productivity, and user experience. The goal is not simply fewer applications; it’s a simpler environment that works better.

Show More

Chris Fernando

Chris N. Fernando is an experienced media professional with over two decades of journalistic experience. He is the Editor of Arabian Reseller magazine, the authoritative guide to the regional IT industry. Follow him on Twitter (@chris508) and Instagram (@chris2508).

Related Articles

Back to top button