In December 2021, a former employee of Cash App Investing logged back into internal reporting tools he no longer had any business touching and downloaded records tied to 8.2 million customers. The company did not disclose the breach for months. When it finally did, in an SEC filing reported by Bank Info Security, the explanation was almost mundane: the employee had legitimate access during his employment, and nobody had gotten around to removing it after he left.
You do not need 8 million customers for that exact failure to hit your business. You need a handful of software subscriptions nobody is tracking, a few department heads with a company card and a login screen, and no single person whose job it is to know what your business is actually running and who still has the keys. For most small and mid-sized businesses, that describes the current state of their software stack pretty accurately. It has a name: SaaS sprawl.
What SaaS Sprawl Actually Looks Like at a Small Business
SaaS sprawl is what happens when cloud software accumulates faster than anyone manages it. A marketing hire signs up for a design tool with a personal card. Sales adds a scheduling app to book demos. Someone in operations starts a free trial of a project tracker that turns into the team's permanent home for client work, and finance never sees the bill because it renews on a personal card and gets expensed a year later as a rounding error. None of it looks reckless in the moment. Each decision solves a real problem for the person making it. The trouble is what accumulates underneath: a growing pile of logins, payment methods, and data-sharing agreements that IT never approved and, in a lot of cases, does not even know exist.
The scale of this varies with company size but shows up everywhere. Industry research consistently puts small businesses in the range of roughly 80 to 150 active SaaS applications, a figure that Breeze's 2026 analysis of SaaS sprawl pegs at around 152 apps for small companies specifically, with more than half of all licenses sitting unused across organizations of every size. That is not a large-enterprise problem that trickles down. It is often worse proportionally at smaller companies, because there is rarely a dedicated person whose entire job is watching the stack.
Where the Risk Actually Lives
Money leaking out through unused licenses
The most visible cost of sprawl is the simplest: paying for software nobody opens. Industry-wide, more than half of provisioned SaaS licenses go unused in a given year, and duplicate tools solving the same problem in different departments are common rather than rare. A marketing team paying for one design platform while sales pays for a nearly identical one is a normal outcome of decentralized buying, not an edge case.
Shadow IT creates blind spots attackers look for
Every app your team signs up for outside an approved process is a piece of shadow IT, and each one is a door your security stack was never configured to watch. Check Point's research on shadow SaaS points out that attackers actively look for these unmanaged apps because their security controls tend to be weaker than what a company enforces on its sanctioned systems, and a breach in a small, forgotten tool can become a foothold into everything else an employee's account touches.
This is not theoretical. A 2025 vulnerability in Microsoft OneDrive's file-sharing interface, documented by BetterCloud's rundown of common SaaS security risks, let hundreds of connected third-party apps gain access to a user's entire OneDrive account when that user only meant to share a single file. The vulnerability lived in the connection between sanctioned software and a long tail of apps most IT teams had never individually reviewed.
Offboarding gaps leave the door open after people leave
This is where the Cash App incident becomes directly relevant to a 20-person company instead of a payments giant. Deprovisioning a departing employee from your email and your main file server is routine. Deprovisioning them from the 87 to 150 individual SaaS tools your business actually runs is a different problem entirely, and it is the one most offboarding checklists quietly skip because nobody has a complete list of what needs to be revoked in the first place.
Accounts tied to former employees are attractive targets precisely because they generate no normal activity to flag as suspicious, and they often survive in tools finance forgot to cancel long after HR closed the file.
Compliance exposure grows with every unmanaged app
If your business handles customer financial data, health information, or anything covered by a state privacy law, every unmanaged SaaS tool is a potential compliance gap. The FTC's Safeguards Rule guidance requires covered businesses to know who has access to customer information and to review that access on a regular basis. That requirement is nearly impossible to meet honestly if your business cannot produce a current list of every application touching customer data in the first place. A tool nobody remembers approving is a tool nobody is reviewing, and regulators do not treat "we didn't know it existed" as a defense.
One weak vendor can become everyone's problem
Every SaaS subscription is also a trust relationship with a vendor whose own security posture you generally cannot verify beyond a marketing page. When one of those vendors gets breached, the exposure flows straight through to your business and your customers, whether or not anyone at your company remembers signing up for the tool.
Getting Control Back Without Slowing the Business Down
The goal is not to lock down every new tool request behind a six-week approval process. Small businesses win by staying nimble, and a security program that fights that instinct will just get routed around. The goal is visibility and a few consistent habits.
- Build a real inventory. Pull bank and credit card statements for recurring software charges, check what is connected to your Google Workspace or Microsoft 365 admin console under third-party app access, and ask department leads directly what they are paying for. This alone usually surfaces more tools than anyone expected.
- Assign an owner to every tool. If nobody can say why a subscription exists or who uses it, that is your signal to cancel it, not a reason to leave it alone for another quarter.
- Route new software requests through one simple check. Not a committee, just a standing rule: before anyone puts a business tool on a company or personal card, IT gets a heads-up and a quick look at what data the tool will touch.
- Turn on single sign-on and multi-factor authentication everywhere it is supported. This turns your identity provider into a single source of truth for who has access to what, which makes both audits and offboarding dramatically faster.
- Make offboarding a checklist tied to the full app inventory, not a memory exercise. The moment someone gives notice, IT should be working from a documented list of every system that person can reach, not reconstructing it from memory under time pressure.
- Review access quarterly, not just at renewal time. A short recurring review catches dormant accounts and forgotten trials long before they turn into a finding during an audit or, worse, an entry point for an attacker.
For a starting framework, CISA's small and medium business cybersecurity resources include guidance built specifically for organizations without a dedicated security team, covering exactly this kind of cloud application visibility.
Frequently Asked Questions
What is SaaS sprawl?
SaaS sprawl is the uncontrolled accumulation of cloud software subscriptions across a business, usually because individual employees or departments sign up for tools independently without a central process for approval, tracking, or eventual cancellation.
How many SaaS applications does a typical small business use?
Estimates vary by source and company size, but research generally puts small businesses in the range of roughly 80 to 150 active applications, a surprising number for organizations that often have no single person tracking the full list.
Why is SaaS sprawl a security risk and not just a budget issue?
Every unmanaged application is a potential entry point that your security tools were never configured to watch. Unauthorized or forgotten apps frequently have weaker security controls than sanctioned software, and they can give attackers a path into connected systems once compromised.
What happens to SaaS accounts when an employee leaves?
Too often, nothing, at least not right away. Most offboarding processes cover email and the main file server but miss the long tail of individual SaaS tools an employee had access to, leaving active accounts that nobody is monitoring.
Does SaaS sprawl create compliance problems?
Yes, for any business handling customer financial, health, or other regulated data. Rules like the FTC Safeguards Rule require businesses to know who can access customer information and review that access regularly, which is difficult to demonstrate honestly without a complete inventory of every application in use.
How do we start fixing SaaS sprawl without disrupting the team?
Start with visibility rather than restriction. Build an inventory of what is actually in use, assign an owner to each tool, and put a lightweight check in place for new software requests. Locking everything down first tends to push the behavior underground instead of fixing it.
About ITGuys IT Support & Consulting
For 15 years, ITGuys has helped small and mid-sized businesses manage the technology decisions that actually move the needle, from everyday IT support to the security and compliance work that protects what you've built. If your software stack has grown faster than your visibility into it, that is exactly the kind of problem we help sort out.
Managed IT Services | Cybersecurity | Compliance Support | Contact Us
Recent Comments