As SaaS companies scale rapidly, they face increasing pressure to maintain security without ballooning resources. Doug Kersten, Appfire’s Chief Information Security Officer, shares key strategies to embed security responsibility across teams, swiftly onboard apps into trust frameworks, and prioritize investments to guard against data breaches.
- Embed security responsibility company-wide to prevent breaches
- Standardize trust criteria and onboarding for multiple apps
- Prioritize security efforts with flexibility for growth and partnerships
What happened
Doug Kersten, Appfire’s Chief Information Security Officer, highlights the challenges SaaS companies face when scaling operations while maintaining security. Drawing from over two decades of experience, Kersten shares how Appfire has earned top international security certifications by implementing a comprehensive strategy centered on trust and shared responsibility.
This strategy includes developing a strong security culture where every team member understands their role, creating standardized security baselines for multiple applications, and introducing efficient onboarding and compliance processes. These efforts protect both the company and its customers as Appfire expands its portfolio through organic development or acquisitions.
Why it matters
As companies grow, the complexity of managing numerous applications and partnerships increases the risk of security gaps that could lead to data breaches. Without a clear, distributed responsibility model, new employees or teams may overlook suspicious activity, placing the entire organization at risk.
By fostering a security culture that empowers individuals to identify and report threats, alongside clear policies and vendor collaboration, SaaS providers can reduce vulnerabilities. Standardized security criteria across a product portfolio also ensure consistent protection, which is crucial for maintaining customer trust and meeting compliance obligations.
What to watch next
Organizations scaling their SaaS offerings should monitor how their security culture develops, particularly focusing on training and communication to reduce the 'bystander effect' among new hires. Establishing clear responsibilities early helps prevent overlooked risks causing breaches.
Additionally, keep an eye on how companies integrate acquired or partner applications into their security frameworks. Success depends on creating flexible prioritization methods for investments and ensuring all parties uphold high security standards to protect the broader ecosystem as partnerships deepen and product portfolios expand.