The ‘SSO tax’ is forcing businesses to choose between affordability and security. Cutting corners on cyber security to save costs may seem practical in the short term, but it exposes organisations and everyone they interact with to financial and operational risks.
So, what is the SSO tax? Why is it bad for business and consumers? And what can you do to minimise your exposure to it?
The term ‘SSO tax’ refers to the practice of SaaS and software vendors only including single sign-on (SSO) authentication in their premium subscription tiers.
‘Single sign-on’ enables users to access multiple services or software applications with a single set of login credentials.
Rather than remembering a password for every service, the user logs into a single identity provider. This provider then identifies the user to other services, such as SaaS platforms, by exchanging secure, cryptographic tokens rather than usernames and passwords.
The benefits of switching to SSO over old-fashioned passwords and usernames include:
If SSO is only available to premium subscribers, everyone else is less productive and less secure. To fix this, they have no option but to pay more.
For instance, if you want to subscribe to the project-management platform Trello, SSO is only included as standard in the top-tier subscription, which costs $17.50 per user per month. Users with any other subscription must pay an additional $4 per user per month for SSO authentication. This is the SSO tax in action.
According to one study, nearly a third of data breaches involved weak, stolen, or improperly shared passwords.
In addition to its other benefits, using SSO significantly reduces the risks associated with poor password management and weak password security.
This is why secure access should never come at a premium:
It’s also worth remembering that if your users can sign up for SaaS services without oversight, you may be paying the SSO tax without your IT team realising it.
In the long term, the SSO tax simply can’t continue. SSO pricing models shouldn’t treat security as a luxury add-on.
Here's why things need to change:
The SSO tax also works against the interests of software and SaaS vendors by undermining trust in their products.
However, SSO is not the only option businesses have to strengthen their cyber security stance. Cyber Essentials (CE) guidance states that "Your organisation must implement Multi-Factor Authentication (MFA), where available – authentication to cloud services must always use MFA".
Texaport is one of the UK’s leading managed service providers (MSPs). Drawing on our experience, we can help you choose the best licences, subscriptions, and technologies to get both the features and security you need, without overpaying.
As noted by the UK’s National Cyber Security Centre (NCSC), choosing the right SSO provider with a security posture that aligns with your organisation's specific needs is essential. Otherwise, you may not realise the full benefits of switching to SSO.
Contact us to learn more about how you can get the right mix of software and SaaS platforms for your needs, without increasing your exposure to risk.