Austin, Texas, September 30, 2026 / PRNewswire / -- SaaS and AI Security Governance Company Nudge Security today announced the launch of a new feature, Adaptive Risk Management (Adaptive Risk Management). The company stated that this feature can respond to changes in risks from SaaS and AI suppliers, as well as changes in internal usage, helping security teams to more effectively manage the growing risk landscape associated with SaaS and AI attacks.
The company stated that most organizations only conduct an assessment of suppliers during the procurement phase and consider that assessment to be the final conclusion. However, the importance and risks associated with a particular supplier for a given organization are not static. After the supplier review and approval process is completed, employees often connect that supplier to other business applications and AI proxies, sharing more sensitive data, or inviting additional internal and external collaborators—often without the knowledge or review of the security team. Traditional third-party risk tools are designed to monitor the external security posture of suppliers and to implement one-time internal security controls; they are not designed to re-assess risks or add additional security measures as the organization's usage of those suppliers changes.
According to Nudge Security, their platform can accomplish both of the following: continuously monitor the external risk landscape of suppliers, and recalculate the risk scores of applications as internal usage patterns change. As these risk scores evolve, Nudge Security will implement and recommend appropriate mitigatory and compensatory controls through native functions and third-party security integrations, thereby forming a truly adaptive risk management solution.
Mercado Libre Senior Cybersecurity Engineer in Third-Party Risk Management Diego Izquierdo stated: " Nudge provides a cross-application, user, integration, browser extension, and authentication-related view that can reveal where security actually needs improvement. For example, an organization may have strong control measures in tools like Slack, but if users integrate third-party applications with weaker security, it could create an invasion path without anyone realizing that new risks have been introduced. It is this integrated risk perspective that makes Nudge unique."
According to the 2026 Verizon Data Breach Investigation Report, security incidents involving third parties increased by 60% year-on-year, accounting for 48% of all data breaches. The company states that after the Mythos era, the vulnerability cycle has been compressed, and this trend may accelerate further; recent supply chain incidents—including those that occurred in Vercel, Salesloft Drift, and LastPass—have shown how quickly granting access rights to a single application can expose the entire environment. Security teams are now increasingly required to answer not only whether a particular supplier is secure but also what access rights that supplier currently has within their environment, as a one-time review alone cannot address this issue. The company also mentioned that the vast majority of organizations currently only proactively manage 30% to 40% of the tools actually in use with SaaS and AI, and after adopting Nudge Security, the number of tools discovered is usually two to three times what was initially anticipated.
The company stated that Adaptive Risk Management is aimed at bridging this gap by continuously integrating known information from supplier security, supply chain risk, and compliance initiatives, as well as actual situations that occur within the customers' own environments.
- Critical Layering of Automation Applications:Each application is automatically classified based on its level of usage within the organization and the sensitivity of the data it typically processes. The company claims that this process utilizes a proprietary AI model, which can identify up to 29 different types of data, allowing the security team to determine which applications are the most critical without the need for manual review of each one.
- Continuous Risk Scoring:Each application will receive a dynamic risk score, which is based on more than 30 factors. This score takes into account the supplier's external security posture and how the application is actually used in the customer's environment, including approval status, granted access permissions, data that is accessed, MCP connections, who or what is using it, what security controls have been deployed, and which security findings have not passed. The company states that as these factors change, the score is automatically updated, rather than waiting until the next scheduled review. These signals include: whether the supplier's OAuth authorization is outdated or not in use, whether there are AI proxies or integrations connected to the application, and whether employees are authenticated through single sign-on or independent credentials.
- Direct path from risk to action:The company stated that Nudge Security will prioritize specific control gaps that can reduce risk after they are addressed, such as enabling SSO or disabling outdated OAuth authorizations; in many cases, the security team can take action directly within the risk dashboard. The platform also adjusts its monitoring scope according to changes in the importance of applications: if an application is marked as business-critical, Nudge will automatically start displaying more previously untracked findings, such as password reuse or weak authentication.
The company stated that as the aforementioned factors change, the risk score will be automatically updated; whereas Nudge Security customers who employ strong compensatory control measures such as SSO and MFA, can reduce the residual risk of a certain application by up to 60%.
Nudge Security, co-founder and chief technology officer, Jaime Blasco stated: "There are still too many organizations that treat third-party risks as an annual task, but in reality, the conditions that affect these risks change every day. An application that was initially approved for use by only a few employees can gradually become deeply integrated into the entire business. Someone might connect a AI tool to sensitive data or grant broader access rights. A single data breach by one of your suppliers could suddenly turn those access rights into potential pathways into your environment. Your last supplier assessment cannot tell you what risks you are facing now. We created Adaptive Risk Management to link changes in usage, access rights, and the security posture of suppliers, allowing the security team to continuously re-evaluate their risk exposures and take action as needed."
The company stated that the risk model for Nudge Security is built on its own data, rather than relying on third-party scoring services. It is based on a self-expanding database that contains over 250,000 security profiles of SaaS and AI suppliers. This means that Adaptive Risk Management can begin evaluating a certain application from the moment it enters the environment, without the need for supplier cooperation or manual data entry, and even without prior knowledge that the application is already in use.
Availability
The company stated that Adaptive Risk Management is now available to all Nudge Security customers.
About Nudge Security
Nudge Security indicates that the company provides SaaS and AI security governance services at “Workforce Edge”, which refers to the scenario where employees make thousands of technical decisions every day. Its automated, policy-driven protection mechanisms reach out to employees during their work and at their work locations, supporting the rapid adoption of new technologies while minimizing risks and their spread. The company claims that with its detection capabilities, AI-driven risk insights, and interactive methods based on behavioral science, its goal is to make security a natural part of modern work, rather than an obstacle to innovation. Nudge Security was founded in 2021 by Russell Spitler and Jaime Blasco, and has received support from Cerberus Ventures, Ballistic Ventures, Forgepoint Capital, and Squadra Ventures.
Media contact:
Danielle OstrovskyHi - Touch PR[ email protected ]










