Blog
Recent
Cybersecurity

LastPass CISO Mario Platt on Shadow SaaS Discovery and Security

Shireen Stephenson • PublishedOctober 08, 2026
When a vendor switches on AI inside a SaaS app without telling you, who on your team finds out first? In the latest Deploy Securely podcast, host Walter Haydock asked LastPass CISO Mario Platt how to govern AI without becoming the department that says "no" to innovation.
See Mario's answers to Walter's most intriguing questions below. [Catch the full conversation on YouTube].
What is SaaS in cybersecurity?

SaaS in cybersecurity refers to cloud-delivered tools organizations use to protect users, applications, and data. This includes password managers, SaaS app security solutions, and IAM platforms.
 
Effective SaaS security comes down to three questions: Who has access, which apps are in use, and what data is being shared.
 
But you can only answer those questions if you have visibility: The biggest risk often isn't the apps you already know about, but the ones you didn't know existed. That's a visibility problem most organizations underestimate.
 
The 2026 LastPass State of AI & SaaS Security Report shows the scale of shadow SaaS: At least 65.5% of the apps employees sign up for go unused within 30 days, and at least 64.4% are in a category where another app already exists.
 
In the Deploy Securely podcast, LastPass CISO Mario Platt argues that visibility is the foundation of SaaS security. Before organizations can govern AI or manage risk, they need to understand what employees are actually using.
 

How does LastPass describe its mission today?

Mario Platt: LastPass started as the first password manager, with the goal of making work safe and simple. That's still true, but we're now moving into the area of SaaS and AI protection.
This week, we expanded our Business Max offering with new AI visibility and governance capabilities. Our goals are no longer just password management but comprehensive security for SMB and midmarket organizations. We want to make sure these organizations can manage risk effectively and affordably.

How does LastPass approach SaaS discovery and asset inventory for AI?

Mario Platt: Generally, we use web proxies and procurement systems to get a sense of what's out there. Then, as part of our procurement process, we introduce review routines to better understand the contracts associated with our highest-risk suppliers.
So, we use existing inventories and check those against web logs. We correlate that with what's being used, not just what's on the procurement system. That doesn't always tell the same story, but both relate to effective governance and security.

How do you govern AI when leadership pushes speed over security and privacy controls?

Mario Platt: Based on my experience talking to industry peers, many companies are trying to govern what they can't see. That's a challenge.
At LastPass, we had the privilege of starting slowly. We began by blocking access to all AI apps while we figured out what controls we needed. Over time, we started opening up. We had that experience where we moved very, very slowly, which wasn't good for innovation. My security team has since learned what's acceptable and what's not. And now we're in the process of accelerating.
We need to be cognizant about what experimentation looks like, so we can enable our stakeholders to test the benefits they provide. We also need processes that are not overly prescriptive or long, that can help support adoption at speed within the organization.

What's the biggest blind spot you see organizations run into when they adopt generative AI?

Mario Platt: I'm going to call out my bias; I believe shadow AI is one of the biggest challenges. One issue I don't think is addressed nearly enough is how AI compounds existing challenges in organizations with immature SaaS risk management and security. Our research reinforces this concern.
A couple of weeks ago, we released the 2026 LastPass State of AI & SaaS Security Report. There are some statistics in it worth noting.
First, 92% of organizations say employees are using AI but 42% have no technical controls to manage that usage.
Second, nearly 53% of users reuse passwords across accounts, and about 21% regularly log in with a credential that has surfaced in a data breach.
It goes back to what I stated at the beginning of this conversation: We can't govern what we can't see. That said, visibility isn't necessarily about blocking.
We always think the only way to reduce risk is to block things. But I think our job as security people is to ask, "How do I nudge users to the types of behaviors that I would like to see?" This idea of nudging users is the concept behind our AI Protect capability, which provides a real-time warning before users share sensitive data with an AI tool.
This type of nudging is something many security teams argue against, however.
They say a sufficiently adversarial person can bypass it. True, but most of your employees aren't adversarial or trying to circumvent your policies. If what you're dealing with are adversarial employees, then you have a business culture problem, not just a security one. 

What does an effective AI governance framework look like, or how do you operationalize governance?

Mario Platt: One of the elements we are working on at the moment is what we are calling a "policy enforcement architecture." So, we've got a bunch of places where we can introduce policy: at the network level, at the browser level, at the plugin level, etc.
So, considering all of these points, we have some level of control where we can enact policy at runtime.
So basically, you have policy enforcement points, where specific controls apply to specific interactions, and you avoid building policies without clearly defined enforcement points.
At LastPass, we had the privilege of starting slow before putting controls in place and then moving them to the policy enforcement point.
We nudge people at the point of risk, in regard to the kind of behavior we want to see, as opposed to a policy document people acknowledge once a year, which may or may not affect their behavior on a daily basis.

What questions should boards be asking about AI risk that they aren't asking today?

Mario Platt: I'm lucky that I get asked very specific questions about that subject, and I have to report on them. There's an element that goes back to how we even think about the policies themselves. How are we enforcing policies? That covers not only the use of chat-based tools but also how we're integrating business systems with AI capabilities.
Between those two types of things, there's a lot that can go wrong, and there's a lot of places where policies should be enforced and maybe aren't.
So, I think boards should ask more specifically:
  • You've got these AI policies. I can see that they're written. How are you enforcing them?
  • What happens when someone opens their laptop and lands on a website, tries to paste data into a chat tool, or brings a new supplier into the business?
  • Do we have logging capabilities to know how people are interacting with AI tools
  • What type of data is being transferred into those tools?
  • Do we have visibility at each policy enforcement point, so we know whether policies are being followed?

What's one AI security assumption organizations are making today that will prove dangerously wrong?

Mario Platt: Are we asking whether our suppliers are focusing on the adversarial component, especially where it's demanded for internet facing systems?
I mentioned that red teaming is a good sniff test. It tells you whether the vendor is thinking about the long-term viability and security of their product.

Is LastPass Business Max a fit for my organization?

LastPass Business Max may be a fit if you want browser-level visibility and in-the-moment warnings without adding agents or infrastructure.
The latest LastPass Business Max capabilities are designed to help close the AI governance gap through browser-native monitoring and controls:
  • SaaS Monitoring & Protect provides visibility into which SaaS & AI apps employees are accessing, so you can find shadow SaaS.
  • AI Monitoring & Protect surfaces shadow AI and provides real-time guidance when users attempt to share sensitive info with major AI platforms.
  • Web Monitoring & Protect provides visibility into website usage and access controls across 25+ website categories.
These capabilities directly address key concerns identified in the 2026 State of AI & SaaS Security Report, including limited AI visibility, uncontrolled shadow AI, and sensitive data entering AI systems.
To achieve measurable security outcomes while enabling innovation, listen to the full podcast and then try Business Max free for 14 days (no credit card required)

About the CISO

Mario has been a security leader for more than 20 years. He leads security strategy and governance at LastPass, with expertise spanning penetration testing, security operations, security engineering, identity security, and SaaS risk management. As CISO at LastPass and a former consultant in medtech, fintech, and crypto, he brings relevant perspectives on protecting sensitive data, managing security risk, and operationalizing governance in highly regulated environments. 
Hear Mario's full conversation with Walter Haydock on:
Share this post via:share on linkedinshare on xshare on facebooksend an email