As SaaS Adoption Surges, Enterprises Face a Growing Visibility Gap

As organisations rapidly expand their use of cloud applications, SaaS sprawl is creating a new layer of complexity for IT and security teams. Tony Zabaneh, Director, Systems Engineering – South Middle East, Fortinet, explains why enterprises need greater visibility across their SaaS ecosystems, how they can identify redundant and risky applications, and why consolidation should focus on business value, dependencies and security exposure rather than simply reducing the number of applications.
How serious has SaaS sprawl become for enterprises, and what are its biggest operational challenges?
SaaS sprawl is becoming part of a much larger cloud complexity problem. Organisations are adding applications, services and data stores continuously, often across environments that were never designed to operate as one. Security tooling proliferates alongside that expansion, frequently without coordination, creating disconnected tools, inconsistent controls and siloed telemetry.
Fortinet’s 2026 Cloud Security Report found that 69% of organisations cite tool sprawl and visibility gaps as their top barrier to effective cloud security. This creates a significant operational burden because teams are forced to manually correlate information across systems that were never designed to work together. The challenge is therefore not simply having too many applications, but managing an environment that is becoming increasingly fragmented as quickly as the business itself changes.
How can organisations identify redundant, overlapping or underutilised SaaS applications?
The starting point is to understand the SaaS environment as an interconnected ecosystem rather than a list of applications. That means looking at core applications alongside third-party applications and shadow SaaS, then examining how they relate to one another.
For unmanaged applications, useful indicators include the application type, vendor compliance level, number of users, frequency of interactions and the nature of those interactions. User activity can also reveal applications that have become inactive or are no longer delivering meaningful value.
This analysis can distinguish between an application that is genuinely redundant and one that has a smaller but important user base. It can also reveal duplication that a conventional software inventory may miss, giving organisations a more informed basis for rationalisation rather than simply removing applications based on licence counts.
What are the biggest security and compliance risks created by uncontrolled SaaS adoption?
Some of the most significant risks sit in the access surrounding SaaS rather than in the applications themselves. Third-party applications can retain permissions to corporate data long after the original business need has changed, while tokens can create persistent access that is easy to overlook.
The risk increases when applications have access to sensitive information or hold permissions that are broader than necessary. Third-party applications can be examined through factors such as their permissions, vendor risk, access to sensitive data, marketplace verification and user activity.
Identity is another important consideration because a single human or non-human identity may have access across multiple SaaS applications, creating combinations of privileges that are difficult to spot individually. Inadequate permissions can ultimately expose data to unauthorised access, modification or deletion.
How can IT teams balance employee demand for specialised tools with the need for greater application control?
The growth of shadow SaaS is partly a consequence of how quickly employees can find tools that solve immediate business problems. That flexibility should not automatically be treated as a security failure. The more useful question is why an application was adopted and whether it continues to serve a legitimate business need. Business users can provide that context because they understand the workflow the application supports and the value it provides.
From there, applications can be evaluated according to their actual use and risk rather than simply whether they appear on an approved list. That creates room for useful innovation while giving IT and security teams a basis for intervention where an application presents unacceptable risk. It also avoids a situation where overly restrictive controls push employees towards even less visible ways of getting their work done.
Is SaaS consolidation becoming a strategic priority for CIOs, and what should enterprises consider before retiring applications?
SaaS consolidation is becoming a strategic consideration as organisations look to reduce unnecessary complexity and make better use of the applications they already have. But reducing the application count should not become the objective in itself. Before retiring an application, CIOs need to establish whether it supports a critical business process, who depends on it, what data it contains and what other services rely on it.
Dependencies are particularly important because an application that appears isolated may be connected to other business systems or used by another team in a way that is not immediately obvious. Consolidation should therefore be based on business purpose and dependencies, not simply usage statistics or licence costs. The strongest outcome is an environment where applications have a clear purpose, ownership and place in the wider technology landscape.
What practical steps can organisations take to reduce SaaS sprawl without affecting employee productivity or business operations?
SaaS rationalisation should be an ongoing exercise in prioritisation rather than a one-time clean-up. Organisations should first establish which applications are genuinely business-critical and which create unnecessary exposure, duplication or cost. From there, the focus should be on the risks that could have the greatest impact rather than trying to address every finding at once.
Security teams need to see through the attacker’s eyes: what could an attacker actually do through a particular SaaS environment, how could they move internally, what could they modify or steal and what could cause meaningful damage? That perspective helps organisations focus limited resources on the applications and access paths that matter most, while allowing lower-risk tools to continue supporting employ



