A Practical SSPM Checklist for Mid-Market Companies
Twelve concrete controls every mid-market SaaS-heavy company should verify this quarter — mapped to SOC 2, ISO 27001, and CIS v8.
SaaS sprawl is the new shadow IT. Most mid-market companies discover 3–5x more SaaS tenants than their IT team can name.
The twelve controls
- Inventory every OAuth grant across Google Workspace and Microsoft 365.
- Disable legacy auth protocols on every identity provider.
- Enforce phishing-resistant MFA on all admin accounts.
- Map every SaaS admin to a named human, not a shared mailbox.
- Continuously diff SaaS RBAC against a known-good baseline.
- Alert on any new external sharing of files tagged "confidential".
- Auto-revoke OAuth tokens unused for 90 days.
- Rotate every long-lived API key on a 90-day cadence.
- Centralize SaaS audit logs into a single SIEM lake.
- Detect impossible-travel sign-ins across all SaaS apps, not just IdP.
- Block downloads to unmanaged devices via conditional access.
- Quarterly access reviews — actually performed, not just scheduled.
Mapping to frameworks
Each of the above maps cleanly to SOC 2 CC6, ISO 27001 A.9, and CIS v8 controls 5 and 6. Auditors love checklists. So do attackers — make sure yours is shorter than theirs.
