Your CISO Doesn't Actually Know What Apps You Use (Sorry)
- Martin Snyder

- May 13
- 3 min read
Pull aside any CISO and ask them how many SaaS applications their company uses. You'll get a number. They'll say it with confidence. They might give a range — somewhere between 60 and 80, maybe 90 if they're at a big shop. The answer will be wrong.
It's not their fault. Or rather, it's not personally their fault. It's a structural feature of the role.
The CISO has three data sources. All three of them lie.
The CISO's mental model of "what apps we use" is built from three sources. The first is procurement. The second is the identity provider. The third is the conversations they have with VPs of other functions about tools their teams have requested. Each source has its own systemic bias, and each one undercounts in a predictable way.
Procurement undercounts because half of modern SaaS adoption is on corporate cards under expense reports rather than POs. The identity provider undercounts because half of modern SaaS apps don't federate. The VP conversations undercount because each VP is doing the same selective curation that the CISO is doing — telling you about the tools they want you to know about, not the tools their team is actually using.
The gap is consistent across companies
Across discovery exercises in companies of every size, the same pattern emerges. The CISO's estimate is in the range of 50 to 100 apps. The actual count, including OAuth-connected integrations and embedded AI features, is typically 200 to 400. The ratio of perceived to actual hovers around 1:3.
This isn't a Waldo Security marketing claim — though we obviously have opinions on it. The same multiple shows up in industry research. "We use 30 apps. Are you sure?" walks through the discovery curve in a typical mid-market environment. The Cloud Security Alliance and Productiv and BetterCloud have all published comparable findings. Reality is consistent enough that you can predict the gap before running the scan.
This is not a critique of CISOs
It's important to say this clearly: the CISO is not failing at their job. The expectation that any one person could maintain a current mental inventory of every SaaS app, OAuth grant, AI integration, and embedded feature across 5,000 employees is unrealistic. The role doesn't have the data sources to produce that picture. The data sources it does have are biased toward undercounting.
What CISOs can be expected to do is recognize the structural limit and put a discovery layer in place that produces the real number. That's the only way the CISO's mental model gets closer to reality. Wait, that's not the URL — let me try again. Sorry — the right reference is "Your SaaS and AI inventory is fiction". It's the directly relevant analysis.
What boards should actually ask
If you're on a board, here's the better question to ask: "How do you know that's the full list?" Not as a gotcha. As a structural check. A confident answer with no measurement underneath should make you uncomfortable. A "we measure it continuously and the current count is X with confidence interval Y" should make you considerably more comfortable. The Verizon 2025 DBIR's analysis of credential-driven breaches reinforces why this matters — most modern breaches start in an app the security team didn't think about.
If you're a CISO, the move is simple. Get the real number first. Then plan against it. Waldo Security's SaaS Discovery produces the number agentlessly in days. The new number is going to be higher than your current estimate. That's not a problem — it's the starting point.
Want the real number for your environment? Schedule a 30-minute walkthrough. Bring a coffee. You'll be surprised.



Comments