Karsten Wenzlaff, Advisor
August 26th, 2025
Cybersecurity | May 14, 2025

Image: Freepik/DC Studio
Patrick Opet, JPMorgan Chase’s Chief Information Security Officer, has dropped a rare public warning that the modern SaaS (Software-as-a-service) model is enabling cyberattacks and embedding systemic risk into the global economy. His message is that the security architecture is breaking down, and software providers are not doing enough to fix it. Below are some urgent quotes from his discourse and why they matter for Canadian fintechs, investors, and regulators.
1. “SaaS has become the default... embedding concentration risk into global critical infrastructure.”
Many fintechs are using the same core SaaS vendors for payments, data, and automation, exposing them to a single point of failure. If one of these vendors is compromised, the effects can spread fast like wild fire on a dry summer's night. For fintech startups, the risks may be inherited without full visibility.
2. “Over the past three years, our third-party providers experienced a number of incidents... requiring us to act swiftly and decisively.”
Canadian fintechs with lean security teams need contingency plans for third party supplier compromise and must monitoring vendor behaviour or risk the full wrath of a serious attack that will disrupt operations, result in data theft or leakage, fraud and financial loss, regulatory and legal exposure, reputational damage and even cascading or 'fourth party' risks. Even a global bank must isolate vendors during incidents. Read OSFI's Guidance here: Third-Party Risk Management Guideline.
3. “Fierce competition among software providers has driven prioritization of rapid feature development over robust security.”
Security is often sacrificed for speed. Fintechs should require vendors to provide (1) strong and secure default settings, (2) regular third-party audits, and proof or evidence of strong internal security programs such as SOC 2 Type II or ISO/IEC 27001 certification.
4. “Modern integration patterns dismantle essential boundaries... relying on overly simplified interactions between third-party services and firms’ sensitive internal resources.”
OAuth tokens and API integrations are often misused, allowing third and unwanted parties to access internal systems. Without strong segmentation and logging, attackers can move quickly once access is gained. Microsoft Threat Intelligence recently confirmed state actors are now targeting common SaaS apps to infiltrate customers.
5. “The most effective way to begin change is to reject these integration models without better solutions.”
Canadian fintechs should ensure procurement policies require secure integration design, advanced authorization models, and greater transparency from vendors. Startups should reference the Canadian Center for Cybersecurity Top 10 IT Security Actions for implementation guidance.
SaaS brought convenience and speed but also concentrated risk across fintech infrastructure. For smaller Canadian firms who often lack internal security engineering, the consequences of a poorly or unsecured SaaS integration can be severe. This warning should not be ignored.
Fintech leaders should:
OSFI and the CSA have made it clear that third party oversight is now a priority, so fintechs can expect questions on cybersecurity controls and operational resilience during regular reviews. SaaS is here to stay but without stronger default security and safer integrations and oversight, it'll remain a growing liability.
Fintech startups and scale-ups cannot rely on vendors to lead. Security must be a shared responsibility across the ecosystem, and it begins with better architecture, more transparency, and smarter procurement.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Leave a Reply