WP_User Object ( [data] => stdClass Object ( ) [ID] => 0 [caps] => Array ( ) [cap_key] => [roles] => Array ( ) [allcaps] => Array ( ) [filter] => [site_id:WP_User:private] => 0 )
Back
Securing the SaaS Apps of the Future
Read Summary
Applications Expert Presentations

Securing the SaaS Apps of the Future

Apr 22, 2024 | 3 mins

In this keynote presentation, Brett Winterford, APJ CSO at Okta emphasises the importance of updating security requirements for SaaS app vendors to address emerging threats, particularly related to session token theft and machine-to-machine authentication.

He highlights existing non-negotiable requirements such as single sign-on and automated provisioning but propose adding new conditions like phishing-resistant authenticators and endpoint security measures.

Brett draws attention to recent incidents involving session token theft, stressing the need for heightened security measures. He explains how adversaries target session tokens using various methods like malware and transparent proxies.

Ensuring the implementation of measures such as phishing-resistant authenticators and robust endpoint security protocols is crucial for effectively mitigating these threats.

Furthermore, Brett introduces advancements in security protocols such as OAuth2 extensions to address machine-to-machine authentication risks. He discusses the importance of limiting token scope, implementing short-lived tokens, and enforcing proof of possession to enhance security.

Use acquisitions like Auth0…

Research & Advisory
Client-Exclusive Content

Members of ADAPT’s Research & Advisory platform have access to an entire suite of local market research, case studies and resources to help them execute in their role.

Learn More Already a member?
ADAPT