Monitoring Third-Party SaaS Risk Signals and Breach Notifications
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.
External risk signals
- Public breach disclosures or reports involving the vendor.
- Threat intelligence mentions of the vendor's data on criminal forums.
- Changes in the vendor's security attestations (expired SOC 2, missing renewal).
- Acquisitions or major leadership changes at the vendor.
- Security rating services showing deteriorating external posture.
Internal signals
- The vendor's integration accessing more data than usual (Defender for Cloud Apps app governance, audit logs).
- New OAuth permissions requested by the vendor's app.
- Sign-ins to your tenant from the vendor's support accounts or IP ranges outside agreed windows.
- Unexpected API usage from vendor integrations in AWS or Azure.
Process
- Maintain a list of high-tier vendors with business owners.
- Subscribe to vendor security notification channels and status pages.
- Set up news and threat intelligence alerts for vendor names.
- Review app governance alerts for vendor integrations weekly.
- When a vendor reports an incident, use a vendor-breach playbook: assess data exposure, rotate shared credentials and tokens, review access logs, and prepare notification decisions.
Breach notification readiness
Keep templates ready for notifying customers or donors about a vendor incident, and know your regulatory timelines.
- Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom Incident Teardowns
- How to Assess SaaS Vendors' Security Before You Sign How-To & Hardening
- CIO Brief: Third-Party Ransomware and Your Disclosure Obligations CIO Briefings