An interview with LastPass CEO Karim Toubba on the company-wide changes after the 2022 data breach, new services such as controls to fight shadow SaaS, and more
ZDNET's key takeaways — LastPass's CEO says the 2022 data breach has driven the company to greater security heights.
Context & Ripple Effects
LastPass’s post-2022 recovery is rooted in disclosures that attackers obtained backups containing encrypted and unencrypted vault data after compromised cloud-storage access keys. The later account of an RCE-led compromise of a DevOps engineer’s device tied the incident to internal operational security, not just a customer-facing product failure.
The CEO’s interview frames company-wide changes and shadow-SaaS controls as an effort to turn that breach legacy into a broader security-services position. It matters because the company’s credibility now depends on whether its operational reforms and new controls address the access risks highlighted by the vault-backup theft disclosure.
First-order effects
- LastPass is extending its offering beyond password management with controls aimed at identifying or limiting shadow SaaS, while presenting internal security changes as a core part of its product and operating posture.
- Existing customers and prospective buyers gain another access-governance capability to evaluate alongside LastPass’s password-management service, but the interview itself does not establish adoption or efficacy.
Second-order effects
- The move places LastPass more directly in the access-management and SaaS-governance buying conversation, where vendors must show that security controls are backed by credible internal safeguards.
- Enterprise security teams may increasingly assess credential tools and SaaS-use controls together, since unmanaged applications can create new paths for account, data, and administrative-access sprawl.
Third-order effects
- If password managers continue adding SaaS governance, identity security may consolidate around broader control of how employees obtain and use access—not merely where credentials are stored.
- The durable constraint is trust: after major incidents, vendors’ security claims are likely to be judged as much on operational resilience and disclosure quality as on added features.
The trend: Password-management vendors are broadening into access-governance platforms as enterprises seek to control both credentials and unsanctioned SaaS use.