A Deep Dive into SaaS Risks and Backups episode artwork

EPISODE · Apr 30, 2025 · 28 MIN

A Deep Dive into SaaS Risks and Backups

from QPC Security - Breakfast Bytes · host QPC Security

Join Felicia King in this eye-opening episode of Breakfast Bytes as she unravels the concept of third-party information security risk management. Felicia highlights the growing debates around software as a service (SaaS) platforms and the complexities they entail, raising poignant questions about security, backups, and risk. Dive deep into the intricacies of backups—from on-premise practices to the vulnerabilities introduced with SaaS. Felicia draws parallels between the supply chain practices of ancient times and the critical information security strategies needed in today's digital landscape. Through vivid storytelling and expert insights, discover why making informed decisions about SaaS requires more than just evaluating business functionalities—it demands a comprehensive risk management strategy and the right technological expertise. Don't miss this narrative packed with actionable advice for becoming an informed risk decision maker in the world of technology.   Quick recap Felicia discussed the importance of third-party information security risk management in the technology industry, emphasizing the need for comprehensive backup methods and informed decision-making when evaluating software as a service solutions. She highlighted the misconception that Business Continuity and Disaster Recovery is primarily an IT problem, stressing the importance of business processes and human continuity. Felicia emphasized the crucial role of involving a qualified Chief Technology Officer in the evaluation process of software as a service solutions to ensure proper security measures, backup capabilities, and role management are considered before making procurement decisions.   Third-Party Information Security Risk Management Felicia discussed the importance of third-party information security risk management, also known as counterparty risk, in the technology industry. She highlighted that this topic has been underestimated and is becoming increasingly relevant as more legacy applications are being considered for replacement into software as a service (SaaS). Felicia emphasized the need for informed risk decision-making and raised awareness about the nuances of backups, which are crucial for information security risk management. She also mentioned that the approach to backups should be based on the end goal of restoration, and that relying on a single method for backups can be naive.   Comprehensive Backup Strategies for Businesses Felicia discussed the importance of backup methods for businesses, emphasizing the need for a more comprehensive approach than the standard 3-2-1 method. She highlighted the limitations of cloud storage and the need for brick-level backup, which allows for the recovery of individual objects or databases, rather than the entire server. This flexibility is crucial for businesses, especially those with complex systems like enterprise resource planning tools, where rapid and easy recovery from backups is essential for scenario planning and testing.   BCDR: Business Processes Over IT Felicia discussed the misconception that Business Continuity and Disaster Recovery (BCDR) is primarily an IT problem, emphasizing that it is 80% about business processes and human continuity. She highlighted the importance of moving away from legacy apps due to their high maintenance and operational costs. Felicia also pointed out the limitations of on-premise infrastructure in meeting uptime requirements, suggesting that software as a service could be a more viable option. She concluded by stating that most businesses cannot afford the same level of uptime as software as a service, despite what are sometimes higher monthly fees for SaaS.   Involving CTO in Software Evaluation Felicia emphasized the importance of involving a Chief Technology Officer (CTO) in the evaluation process of software as a service solutions. She highlighted that without a CTO, the evaluation process lacks essential technical questions, such as security, access control, integration with onboarding and offboarding processes, and backup and restore capabilities. Felicia stressed that these technical aspects are crucial for a successful procurement and should be evaluated before making a business decision.   Involving Right People in Pre-Procurement Felicia emphasized the importance of involving the right people in the pre-procurement phase of software as a service, such as a qualified CTO, to ensure proper backup and security measures are in place. She used the example of XERO, an accounting platform, and its lack of native backups, requiring an additional third-party add-on, Control C, for backup solutions. Felicia stressed that without a competent CTO, it's impossible to make informed decisions based solely on price quotes from software companies, as additional costs for competent reporting and backup solutions need to be factored in.   QuickBooks Backup Limitations and Security Risks Felicia discussed the limitations of QuickBooks Online's backup and restore capabilities and suggested considering alternatives like Odoo for more control over data. She emphasized the importance of understanding third-party information security and risk management to make informed decisions. Felicia also highlighted the risks associated with software as a service, including potential privacy violations and lack of full control over access logs. She advised considering the security implications of software development and the need for ongoing security processes.   Saas Platform Evaluation Challenges Discussed Felicia discussed the challenges of managing roles and responsibilities in software as a service applications. She highlighted that only a small percentage of these applications allow for customization, which is a significant issue. Felicia emphasized the importance of considering various factors when evaluating a SaaS platform, suggesting that it's a task best suited for a Chief Technology Officer (CTO). She encouraged attendees to consult with their preferred CTO for guidance on evaluating Saas platforms.  

Episode metadata supplied by the publisher feed · Published Apr 30, 2025

Embed this episode

Felicia discussed the importance of third-party information security risk management in the technology industry, emphasizing the need for comprehensive backup strategies and business continuity planning when transitioning to Software as a Service (SaaS) platforms. She stressed the critical role of involving a qualified Chief Technology Officer in evaluating SaaS solutions, highlighting the need to consider security, access control, and backup functionality before procurement. Additionally, Felicia addressed the challenges of role-based access control and privacy concerns in SaaS platforms, emphasizing the importance of having subject matter experts to develop appropriate roles and ensure proper security measures are in place.

Distinct summary based on available episode metadata or transcript content.

Ready to play

A Deep Dive into SaaS Risks and Backups

0:00 28:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

The Wall Ronald W. Chapman II and Sean Weiss The Wall protects our republic by safeguarding our democratic processes, civil liberties, and national security through laws and institutions. Its role in protecting the republic involves balancing security concerns with humanitarian and legal considerations.With over 50 years of legal and government experience combined, Ron Chapman and Sean M. Weiss pull back the curtain on the US government, the U.S. Judicial System, and some of the most influential trials in history that continue to shape our nation today.Join every week for unfiltered conversations, in-depth analysis, and commentary from some of America’s boldest thought leaders.Be sure to follow the podcast on your favorite platform so you never miss a new episode. From Passion to Profit: Heart Centered Strategies for FitPros Nichola Page Welcome to From Passion to Profit, the ultimate resource for fitness professionals driven by their passion to inspire and empower others on their business journey. Hosted by Nichola Page, a seasoned health and fitness business specialist, this show is tailored for FitPros and Studio Owners looking to supercharge their small business.Discover game-changing strategies and actionable tactics that will not only help you attract and retain clients but also transform your health & fitness venture into a thriving small business. Dive deep into topics like marketing, sales, financials, client retention, and business scalability. Learn how to master the art of growing a health & fitness business, and unlock the secrets to financial security, freedom, and flexibility.Join Nichola each week as she and her industry guests provides invaluable insights to guide you towards a successful and sustainable fitness business. Whether you've had your business for years or just starting ou Iran's Gambit Ali Alfoneh "Iran's Gambit" is a weekly podcast produced by Ali Alfoneh, on Iranian politics, and Iran's national security strategy, intentions, capabilities and impact. Mark Kollar’s Financial Cornerstone Mark Kollar Mark Kollar is a well-known financial educator in the Chicago area and hosts the popular weekly financial radio show, Retirement and Income Radio. He is sought after throughout the state of Illinois for his expertise in retirement planning and retirement income planning. His clients include retirees from United Airlines, AT&T, McDonald’s, Chicago Transit Authority, and HFC.As a retirement and income planning specialist, Mark helps retirees and those near retirement protect their savings, reduce income taxes and taxes on social security benefits and create a retirement income guaranteed to last as long as they do. Mark graduated from Loyola University of Chicago where he received his B.B.A. degree. He is a Registered Financial Consultant and a Certified Estate Planning Professional and has pledged always to put the needs of his clients above his own.

Frequently Asked Questions

How long is this episode of QPC Security - Breakfast Bytes?

This episode is 28 minutes long.

When was this QPC Security - Breakfast Bytes episode published?

This episode was published on April 30, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this QPC Security - Breakfast Bytes episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!