AICHELON
• Case Study • Published 2025 • 6 min read

When SaaS Sprawl Overwhelmed the Security Team

How the University of Cincinnati regained visibility and control across a fast-growing SaaS infrastructure

Data & Analytics
Workflow Usage in Practice
IT Direction
CISO
CIO
Single Case Study

Core Problem

The Security team had witnessed a rapid influx of SaaS applications across departments, but lacked the foundational architecture to quickly align with teams or assess the security status of each application. As security standards were applied piecemeal, the team could not identify or address emerging threats in time.

56,000+
ISSUES RESOLVED
Data conflicts addressed
20+
FRAMEWORKS
Compliance standards supported
48%
REDUCTION
In shadow IT instances

Key Challenges

  1. Decentralized and fragmented security tools across multiple business units
  2. Inconsistent patching and software updates led to widespread vulnerabilities
  3. Lack of visibility into comprehensive inventory of assets led to unmonitored areas
  4. Manual processes resulted in inconsistent response to security threats

Requirements

  1. A single source of truth for all infrastructure and IT environments
  2. Real-time security intelligence across all systems with automated alerts
  3. Streamlined way to address patching and software lifecycle management
  4. A predictive framework for control processes to preemptively mitigate risks

Background & Intent

  1. The University of Cincinnati operates with a distributed technology environment with 100,000+ users, students, faculty, and staff.
  2. SaaS solutions deployed across various departments, creating siloed operational environments.
  3. This growth had resulted in widely varied security protocols and compliance standards across their operations.

Breakdown Analysis

  1. There was no unified monitoring system for their vast infrastructure.
  2. Configuration drift caused frequent breaches, as unpatched systems remained vulnerable.
  3. Relying on static integrations, reacting manually to threats, created significant security windows.

Automation Failures

  1. Analysts had to manually investigate alerts and rebuild workflows to make sense of the data.
  2. Teams performed one-off audits to regain control, revealing deeper systemic gaps.
  3. Human coordination became the only reliable way to validate permissions and compliance posture.

System Adaptation

  1. AppOmni was implemented to provide unified visibility into SaaS configurations and user permissions.
  2. Real-time misconfiguration alerts were fed into the SIEM with contextual tags.
  3. Security, IT, and engineering created a shared workflow using a central dashboard.
  4. Automated checks were established for compliance frameworks and high-risk permission changes.

Resolution & Remaining Risks

  1. The approach: Automated data/infrastructure solutions into three focus categories.
  2. Deployed a unified configuration workflow, reducing disparate systems.
  3. Ongoing data analytics as a team, SAAS platform of advanced operational integrations.
  4. Continuous oversight via machine learning for operational system.

Key Takeaways

  1. Visibility is the foundation of SaaS security; without it, risk compounds silently.
  2. Automation only works when alerts carry context and fit real workflows.
  3. Governance must scale with SaaS growth, not lag behind it.
  4. Cross-team alignment is as critical as tooling in maintaining posture.

Role-Level Impact

CTO: Acquired SaaS governance structures that secure suitable scaling, controls, and compliance.
CFO: Fewer unexpected costs and compliance expenses due to automated cost visibility frameworks.
CISO: Increased monitoring safeguards mean early threat identification, eliminating risk exposure costs.
Data Lead: The solution to reduce workflows on manual maintenance and operations cost.

Closing Takeaway

This case shows that SaaS speed can outpace security faster than teams expect, and that real trust comes from visibility and coordinated human oversight — not assumptions built into the tools.

Popular Agentic: AI resources in industry

Accelerate outcomes that matter most to your organization.

Partner with experts who help leaders transform strategy into measurable results.

Talk to an Expert

Dev Page Switcher

Quickly switch between pages