working wikily
Smarter ways to work
Software ·

Nudge Security Adds Adaptive Risk Management

Nudge Security Adaptive Risk Management updates SaaS and AI risk scores as employee access, integrations, and data use change.

By Working Wikily Newsroom
Nudge Security dashboard showing residual risk metrics, app counts, a trend chart and a color-coded risk heatmap.
Image: Nudge Security

Nudge Security has launched Adaptive Risk Management, a new capability that updates SaaS and AI risk assessments as employee use changes after approval. The platform combines vendor security information with internal usage signals, including access, data handled, integrations, authentication, and security controls. It uses more than 30 risk factors and can identify up to 29 data types when classifying applications. The feature is available now to all Nudge Security customers.

Risk Scores Update With Usage

Vendor assessments are often completed during procurement, before employees connect more business applications or AI agents, share sensitive data, or invite new collaborators. Nudge Security’s new capability recalculates an application’s risk score as those conditions change.

Each application receives a dynamic score based on the vendor’s external security posture and factors inside a customer’s environment, including approval status, access granted, data touched, MCP connections, users, controls, and failing security findings. The system also tracks signals such as stale OAuth grants, connected AI agents or integrations, and whether employees use single sign-on or standalone credentials.

“Nudge provides a relational view across applications, users, integrations, browser extensions, and authentication that surfaces where security actually needs improvement. For example, an organization can have very strong controls in a tool like Slack, but if users connect less-secure third-party apps into it, that can create a breach path without anyone realizing a new risk was introduced. That integrated perspective on risk is what makes Nudge unique.”

Diego Izquierdo, Senior Cybersecurity Engineer, Third Party Risk Management at Mercado Libre

Controls Linked To Risk Gaps

The platform ranks control gaps by the amount each fix could reduce an application’s risk. In some cases, security teams can act from the risk panel, including by enabling SSO or closing a stale OAuth grant.

Nudge Security also changes its monitoring as an application’s importance changes. When a team marks an app business-critical, the platform begins surfacing added findings, such as password reuse or weak authentication, that were not previously tracked. Customers using compensating controls including SSO and MFA can reduce an app’s residual risk by as much as 60%, according to the company.

Vendor Profile Data

Nudge Security built its risk model on its own data, using a self-populating database of more than 250,000 SaaS and AI vendor security profiles. The company says this allows Adaptive Risk Management to assess an application when it enters an environment without vendor cooperation, manual data entry, or prior knowledge that the application was in use.

“Too many organizations still treat third-party risk as an annual exercise, while in reality, the conditions that impact risk change every single day. An application approved for a handful of employees becomes entrenched across the business. Someone connects an AI tool to sensitive data or grants an integration broader access. A breach at one of your vendors suddenly turns that access into a potential path into your environment. Your last vendor assessment won't tell you what's at risk now. We built Adaptive Risk Management to connect changes in usage, access, and a vendor's security posture so security teams can continuously reassess their exposure and act as it changes.

Jaime Blasco, co-founder and CTO at Nudge Security

Available To Customers Now

Adaptive Risk Management is available to all Nudge Security customers now. It is intended for security teams tracking SaaS and AI application risk after an initial procurement review, as employees add integrations, expand access, and bring more tools into use.

From an announcement by Nudge Security.

More in Software