Some Scary Stats to Keep in Mind if You’re Building a SaaS Product

If you’re an aspiring SaaS founder (or investor), this could save you some pain.
In recent weeks I’ve been interviewing Seed / Series A-stage SaaS CTOs in the UK, Southeast Asia and Europe about security and scalability. The results were… unexpected.
(The people I spoke to were all post-revenue — mostly >$1m ARR — between Seed and Series B, established for 3-5 years, and all had in-house tech teams.)
Here’s what I learned:
#1. More than 75% of the SaaS CTOs told us their software was reaching its maximum capacity and would soon have scaling issues(!).
#2. More than 50% said their software needed significant refactoring, if not a total rebuild, within 18 months, for which they would require investment that—for now—was not in the budget.
#3. More than 60% said their solutions were a potential security risk, mostly stemming from outdated “user access control” (the bit that determines what permissions and rights you have as a user). This had worked fine when they were small companies, but was not capable of managing the fine-grained permissions, rights and roles required by larger, more sophisticated customers.
#4. One CTO told us that their permissions were so inflexible that, instead of refactoring, the team had chosen to rewrite its entire pricing policy. Although suboptimal, this was more pragmatic (and in the short term cheaper) than making the required technical changes.
So what?
Well, often as founders and investors, we focus on the exciting aspects of our technology — the bits that will change people’s lives. Meanwhile we assume that our CTOs and technical teams will just “make it work”.
The reality is not so simple.
According to OWASP – a non-profit dedicated to improving software security – more than 94% of applications tested in 2021 suffered from some level of broken user access control, making it the number 1 cybersecurity threat on the web.
The problem is, doing the basics properly tends not to get prioritised, because it’s not “core functionality”. It costs money and time, but it doesn’t win customers or close your Series A.
Thanks in part to the funding situation, many SaaS solutions may soon start to plateau because they’ve been focusing on the parts that customers 𝘥𝘦𝘴𝘪𝘳𝘦, and not the bits that they expect.
Makes you think.
So, if your solution works, take a moment to thank your technical team. It’s not as easy as it looks.
And if you’re assessing that next SaaS investment, or choosing a technical cofounder, find out how they plan to solve the user access control problem.
For now, on behalf of all non-technical founders…
THANK YOU to all the CTOs out there.
We appreciate you dealing with our unrealistic expectations!!


