100,000 OAuth Grants Later, Security Teams Still Can’t See the Risk

SEP 14, 202653 MIN

Description

Joe and Danielle discuss how AI has accelerated an already messy SaaS security problem, especially as employees connect more tools, more agents, and more data without centralized oversight. The conversation focuses on why traditional block or allow controls are breaking down, and how security teams can use agentic automation to reduce risk without slowing the business 00:00 - Why AI adoption is moving faster than cloud and SaaS ever did 01:20 - The professional pressure to skill up on AI now 03:19 - How cloud security and SaaS security lagged behind adoption 06:13 - Why organizations can’t simply say no to AI tools 08:30 - The difference between cloud-era experimentation and today’s browser-based AI 10:37 - Why AI security and SaaS security are becoming the same problem 12:31 - Why traditional onboarding and vendor review processes don’t scale 14:43 - The Salesforce example that exposed hidden risk in a large enterprise 17:00 - Why most third-party risk programs only cover part of the estate 19:07 - How decentralized tech adoption bypasses security workflows 20:31 - Why OAuth grants and third-party integrations are a major attack path 22:25 - Why attackers usually go after credentials and tokens, not zero days 23:19 - How AI lowers the barrier to entry for attackers 26:55 - Why defenders need agentic capabilities too 28:16 - The scale of unmanaged OAuth grants inside enterprises 30:26 - Why no one can hire enough people to review every grant manually 31:53 - How agents can analyze risk and recommend revocation at scale 33:33 - The reality check from customer conversations about AI visibility 35:24 - How security people think when told they can’t do something 38:16 - Reactance theory and why employees work around controls 40:25 - Incentives matter more than policy slogans 41:48 - Why binary block or allow controls create shadow IT 43:30 - How Nudge Security approaches SaaS and AI as one workforce problem 46:14 - Why a workforce edge model matters more than network or identity alone 48:26 - What just-in-time policy decisions could look like in the browser 50:10 - Why policy experience is as important as policy enforcement 52:08 - Danielle on Nudge Security’s free trial and LinkedIn presence Affiliates ➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh ➡️ OffGrid Coupon Code: JOE ➡️ Unplugged Phone: https://unplugged.com/ Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout *See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions. Tesla Referral Code: https://ts.la/joseph675128 Follow the Podcast on Social Media! Instagram: https://www.instagram.com/secunfpodcast/ Twitter: https://twitter.com/SecUnfPodcast