Key Takeaways from the SaaS Con PH: Connecting Founders, Enterprises, and Investors

Mark Anthony Tacuboy

Mark Anthony Tacuboy

Tax & Compliance Manager

Key Takeaways from the SaaS Con PH: Connecting Founders, Enterprises, and Investors
As part of the Scrubbed team, I had the privilege of attending the inaugural SaaS Con PH, an exceptional event that marked the first-ever SaaS conference in the Philippines. Alongside my colleagues, including Joy, Gale, and KV, we seized the opportunity to immerse ourselves in this gathering of SaaS industry leaders and investors alike.

The SaaS Con PH aimed to foster connections and facilitate meaningful discussions among SaaS founders, enterprises, and investors. The event featured notable speakers, including Lisa Gokongwei-Cheng, Senior Vice President of Digital Transformation and Corporate Services at JG Summit Holdings; Jaime Alfonso Zobel de Ayala, Head of Business Development & Digital Transformation at Ayala Corporation; esteemed venture capitalists Paulo Campos, founder of Zalora and Kaya Founders; and Paul Santos, Managing Partner at Wavemaker Partners. RJ Ledesma, Co-Founder of Mercato Centrale and Editor-in-Chief of The Business Manual, was also present, among others.

PH SaaS COn 1 1024x768

As we look back on our participation, here are the noteworthy insights from the conference:
  1. SaaS adoption is crucial for the growth of the region’s technology sector, and it can benefit startups, enterprises, and investors.
  2. Digital transformation is a key driver of technology adoption and innovation, and the Philippine government is supporting startups through programs such as the Startup Acceleration Program and the Digital Transformation Centers.
  3. The global state of SaaS is still booming. Worldwide market is projected to reach $261 Billion by 2027. The growth is driven by an increase in adoption, expansion of use cases, and higher usage intensity.
  4. Generative AI is the fourth industrial revolution. There’s a buzz around the topic of AI lately. Some of the best use cases for AI are in education, improving productivity, customer service and cross-selling/up-selling.
  5. Digitization and digital transformation are critical for businesses to remain competitive, and companies like the Gokongwei Group are using technology and customer-centricity to drive growth.
  6. Understanding customer pain points and consumerism is key to building successful SaaS businesses, and startups should focus on creating products that provide more value than any other alternatives in the market.
  7. There is an abundance of talent in the Philippines to support SaaS businesses, and founders should focus on building sustainable platforms and ecosystems.
  8. Startups need to fight for their reasons to exist and prove that they provide more value than any other alternatives in the market. In a highly competitive landscape like the Philippines, startups need to differentiate themselves by offering something unique or valuable that other businesses cannot match.
  9. Scrubbed is in a great position to help develop and grow the SaaS industry in the Philippines. We are serving clients in developed nations and we are in an advantageous position to know what technologies are in and are coming before they even become hot trends in the region. We can use that knowledge to find solutions for problems unique to our country offering strategic insights and support, including fractional CFO services to help SaaS companies scale efficiently and sustainably.

The first SaaS Con PH left a lasting impression on us, igniting our passion for the SaaS industry and reinforcing our commitment to driving innovation and growth in this dynamic sector. We eagerly anticipate future conferences and the continued advancement of the SaaS community in the Philippines.

How Scrubbed can help you?

In the fast-paced world of SaaS, ensuring accurate financial reporting and compliance is vital for your business’s growth. At our Financial Accounting team, we specialize in assisting SaaS companies with their unique accounting needs. Our dedicated experts are here to provide hands-on support, helping you navigate evolving accounting standards and achieve reliable financial reporting with our proven SaaS accounting expertise. If you have any specific inquiries regarding accounting and reporting for SaaS businesses, reach out to us today. Discover how our efficient and effective solutions can optimize your financial processes and drive your SaaS business forward.

Related Content

Blogs

Securing Your Web Applications: Understanding and Preventing Broken Access Control

Securing Your Web Applications: Understanding and Preventing Broken Access Control

Introduction Broken Access Control (BAC) might sound like a minor issue, something easily spotted, but it’s actually one of the most frequently overlooked security flaws. While many focus on threats like Remote Code Execution (RCE) or Cross-site Scripting (XSS), BAC silently allows unauthorized users to perform actions they shouldn’t, often without any complex attack. A simple forgotten backend check can lead to sensitive data exposure or elevated permissions, just by slightly modifying the target web address. In this post, we’ll walk through how you can test for Broken Access Control using Open Worldwide Application Security Project (OWASP) Juice Shop—an intentionally vulnerable web application that makes it easy (and safe) to demonstrate these issues in practice. Understanding Broken Access Control Access control directs who can do what in a system. When it’s broken, users can act outside their intended permissions. Users might be able to read other users’ data, modify other roles, or access administrative functionality without authorization. OWASP defines this category broadly and it includes: Vertical privilege escalation: Accessing higher privilege functions (e.g., a user accessing admin functions). Horizontal privilege escalation: Accessing same role resources (e.g., viewing another user’s order). IDOR (Insecure Direct Object Reference): Accessing data by manipulating object references like user IDs or filenames. Forced browsing: Accessing hidden resources or unlinked pages directly. While it might be hard to understand these concepts at first, Juice Shop does a great job showcasing these problems in a safe, intentionally vulnerable playground. Testing for Broken Access Control For this simulation, you will need to install Juice Shop in your local environment and use Burp Suite to capture traffic while interacting with it.Gaining Privileged Access Juice Shop is a deliberately vulnerable web application that exhibits the classic Forced Browsing and Vertical Privilege Escalation vulnerability. Imagine if someone could access admin functions by just visiting a URL; that would be a security nightmare. Fortunately, we can demonstrate this in Juice Shop without the risk. You can test this by attempting to access hidden resources or unlinked pages directly using keywords such as “admin,” “root,” or other common path names in the URL. In our case, the Administration page can be accessed by visiting the “/#/administration” path. This page was not linked anywhere in the standard UI, yet entering the URL directly allowed full access to the user listing and the ability to remove customer feedback.Note that this vulnerability is accessible if you are already logged in or tagged as an admin role user inside OWASP Juice Shop. However, given that this is hidden in the user interface even if you log in as an admin user, we can infer that it was not meant to be exposed to users (including admin users). In some real-world scenarios, some web applications allow access to the affected endpoint to all users as long as they enter the correct address. But you’re probably curious how we can access this page using a regular, low-privileged accountFirst, inspect how the authentication works. Upon logging in, a token will be sent to your browser and subsequently attached to every HTTP request made to Juice Shop.At this point, you will have to study JWT, but let’s assume that you already know it. What do you think would happen if we change the JWT role parameter or claim to something else, like “admin”?You guessed it right. Modifying the JWT and changing it to “admin” allowed us to access the “/#/administration” page while logged in as a regular user. All you need to do is use Burp Suite’s JWT Editor extension, modify the role parameter or JWT claim to “admin,” go to your browser’s local storage, and replace the token key with the modified JWT, and Voila! You now have access to the Administration page even as a regular user.Viewing and Tampering Another User’s Basket This is an example of Insecure Direct Object Reference (IDOR) and Horizontal Privilege Escalation. Imagine if you have an e-commerce site and anyone can add or delete items in another user’s shopping cart. That would leave your customers confused. To test this vulnerability, log in as a regular user and inspect HTTP requests and responses related to user basket actions. In Burp Suite, notice that visiting your own basket generates a “GET /rest/basket/6” request to Juice Shop. Immediately, you can see from that request that our basket has an ID of “6.” Out of curiosity, if we change the basket ID to another number, will we be able to access other users’ baskets? It turns out we can. There are a couple of ways to test this, but by going to the browser’s Developer Tools > Storage > Session Storage, we can see a “bid” parameter. Modifying it to another number, in our case “3,” and refreshing the page would let us access basket #3—with no ownership check, just the data. This is an example of a horizontal IDOR vulnerability, where users at the same privilege level can access each other’s data by simply modifying object references.Alternatively, the details for basket #3 can also be accessed by repeating the original HTTP request in Burp Suite and modifying the ID to “3”.We were able to see the details of the other user’s basket, but how do we tamper with it? Let’s go back to Burp Suite and study the HTTP request and response flow. Notice that, besides viewing your own basket, adding items to our basket requires a “BasketId” parameter. This is the key to the attack. What if we modify the “BasketId” before sending the request? Will we be able to modify another user’s basket successfully? The short answer is yes, but it is not as easy as it sounds. But before we do the attack, we have the following in basket #3. Remember, our basket is basket #6.Now, let’s modify the “add to basket” request and change the “BasketId” to a different number. However, you will notice that trying to change it won’t modify the basket content of our target.So, what should we do? There are many things you can try, but to cut a long story short, you might discover that adding a second “BasketId” would push the request and modify our target’s basket as well.This tells us that if the backend interprets the requests, and if it finds another “basketID,” it will apply the same action to it. Do you see where I’m going with this? Perhaps adding more “basketID” values would enable a multi-basket attack, but I will leave that for you to try. This means that ignoring access control measures can lead to numerous issues in your web application, potentially affecting multiple accounts by disclosing sensitive information or, as in our case, the contents of a user’s basket. Forged user reviews In Juice Shop, as with almost every e-commerce site, users are allowed to write and submit reviews. This generally benefits both the store owner and enhances the overall user experience. But what if someone could forge a user review? What if a customer review was written and attributed to someone else, perhaps a high-profile user of the site? That would greatly affect the product’s performance, right? This is what we wanted to achieve here: post a user review and attribute it to a different user. Now, you’ll notice that whenever you write and submit a product review, this PUT request is sent.Remember our previous attack that affected another user’s basket? How about the attack where we found the admin email address (see Gaining Privileged Access)? Let’s test that. What would happen if we modify the author before sending it to the endpoint? Would that change the author itself? Let’s see.And what do you know, we were able to post a review using a different user! And we can confirm that by browsing the exact product in the web application.So, the lesson here? Yes, broken access control also helps attackers forge account actions. Directory enumeration and restricted file download One common pitfall of improperly implemented access control is that restricted directories and their included files become accessible for download. This vulnerability is often found in applications rushed to production or those that don’t undergo regular security testing. While this may be harder to find in the real world today, this vulnerability still exists in some web applications. But fret not, Juice Shop exhibits this weakness. If you’ve explored Juice Shop before, you might have stumbled upon various directories, including the `/ftp/` directory. You’ll notice that accessing this directory reveals a number of files without requiring any additional authentication. You can even access some of the files enumerated.Clearly, some of these files are not intended to be accessed, which in itself indicates an access control violation. If you further explore the directory, you’ll discover that attempting to access files with extensions other than “.md” or “.pdf” results in a restriction notification. As curious individuals, we’ll want to bypass this. Fortunately, Juice Shop is vulnerable to null-byte injection.Null-byte injection is essentially an implementation-related vulnerability stemming from a weakness in the framework, underlying library, logic, or a combination of all these three. To perform a null-byte injection, we need to append a null-byte (`%00`) to the filename, hoping that the application won’t sanitize our request.Initially, adding `%00` to the end of the URL might not yield results, perhaps because the server expects a valid file extension. To address this, let’s append a `.pdf` extension.Still not working, right? Perhaps something is blocking our request. Let’s see if encoding will help us get through. Let us encode % and see what happens.Well, what do you know, it works! Now we can access the restricted file and see its content. Clearly this is a violation of access controls. How to Prevent Broken Access Control? If you’re building or maintaining web applications, Broken Access Control (BAC) is one of the most important risks to address. Here’s what you can do to avoid the issues above: Enforce Access Controls on the Server Side Don’t rely on client-side code or hidden links. Every sensitive operation should include server-side checks against the user’s authenticated identity and role. Use Context-Aware Authorization and Centralize Access Control Logic Implement logic that not only checks the user’s role but also whether the user owns the resource in the specific transaction context. For example, confirm “user.id == order.ownerId” before returning order data. Centralize your authorization logic into a single reusable library or service. This ensures that robust authorization rules are applied consistently. This also simplifies maintenance.Adopt a “Deny by Default” and Least Privilege Principle Don’t assign admin rights unless explicitly needed. Make roles granular and restrictive by default. Implement Indirect and Unpredictable Resource Identifiers Use randomly generated identifiers like UUIDs/GUIDs. Implement an indirect reference map that translates a public identifier to a real database ID only after the authorization check has passed. Apply Rate Limiting and Throttling Apply rate limiting to endpoints, especially to sensitive ones such as authentication and data access, to slow down attackers trying to bruteforce identifiers Block IPs or users that exhibit anomalous behavior or exceed reasonable request thresholds Implement a Secure Development Lifecycle (SDLC) Include security unit tests and access control checks as part of your CI/CD pipeline. Use test accounts with varying roles to test for both vertical and horizontal privilege escalation. Monitor and Log Access Violations Set up alerts for unusual access patterns or repeated unauthorized attempts. Log every access control failure, including the user, IP address, and specific resource they are trying to access. Perform regular security assessments Perform regular Web Application Penetration Tests (VAPT) against your web applications. Engage qualified professionals to perform penetration testing at least annually or after any significant changes to the environment. Final Thoughts Broken Access Control topped the OWASP Top 10 list for a reason: it’s one of the most common and dangerous issues that plague web applications. While OWASP Juice Shop is intentionally vulnerable, the lessons it teaches are very real. If you are a developer, product owner, or cybersecurity professional, the insights from Juice Shop offer a humbling reminder of why access controls must be built defensively and verified thoroughly. Looking for support to assess your web applications? If your goal is to get a real-world, adversarial assessment of your security posture, including your access controls, Scrubbed can help you perform Web Application Penetration Testing. We can test Broken Access Controls and other vulnerabilities to help you secure your applications. Not your cup of tea? We also offer other information security related services such as IT audit, Security Awareness Training, and SOC assessment support. Get started in securing your organization. Contact us at https://content.scrubbed.net/contact-us/ (Risk Advisory).

Read More >
Blogs

The One Big Beautiful Bill Act (OBBBA): Major Changes to Individual Taxation

The One Big Beautiful Bill Act (OBBBA): Major Changes to Individual Taxation

The “One Big Beautiful Bill Act” (OBBBA), enacted in 2025, aims to provide lasting tax relief for middle-class families, simplify the tax code, and introduce new benefits for families, workers, and students. Here’s a concise overview of the most significant changes and their impact, effective primarily for tax years beginning after December 31, 2024.Permanent Rate Reductions and Standard Deduction IncreasesTax Rates: The Act permanently establishes the lower individual tax rates first introduced by the Tax Cuts and Jobs Act (TCJA), preventing a scheduled return to higher pre-2018 rates. The seven-bracket system remains, with the top rate at 37% for high earners.Standard Deduction: The increased standard deduction is not only made permanent but further enhanced. For 2025, the standard deduction rises to $23,625 for heads of household, $31,500 for married filing jointly and $15,750 for single filers, with inflation adjustments in future years. This change means more taxpayers will benefit from a larger deduction without itemizing.Modifications to Deductions and ExemptionsPersonal Exemptions: The suspension of personal exemptions is made permanent, but a new $6,000 deduction is introduced for seniors (age 65+), subject to income phaseouts and Social Security number requirements, through 2028.Itemized Deductions: The Act introduces a new limitation, reducing itemized deductions by 2/37 of the lesser total deductions or income above the 37% bracket threshold. The Pease limitation remains suspended.State and Local Tax (SALT) Deduction: The SALT deduction cap is increased to $40,000 ($20,000 for married filing separately) for 2025, with a phase-down for high-income taxpayers and a return to the $10,000 cap after 2029.Mortgage Interest and Casualty Losses: The $750,000 cap on mortgage interest is made permanent, and the casualty loss deduction is limited to federally or state-declared disasters.Miscellaneous Itemized Deductions: The suspension of most miscellaneous itemized deductions is made permanent, except for educator expenses, which are expanded to include coaches and certain supplies.New Middle-Class Tax Relief InitiativesNo Tax on Tips and Overtime: For 2025–2028, individuals can deduct up to $25,000 in qualified tips and up to $12,500 ($25,000 joint) in qualified overtime pay, with phaseouts at higher incomes. These deductions are available even to non-itemizers.Car Loan Interest Deduction: For 2025–2028, up to $10,000 of interest on loans for new, U.S.-assembled passenger vehicles is deductible, subject to income limits.Enhancements to Family and Education-Related CreditsChild Tax Credit: The credit is permanently increased to $2,200 per child, with inflation adjustments and stricter Social Security number requirements for both the taxpayer and child.Dependent Care and Adoption Credits: The child and dependent care credit is enhanced, with a higher applicable percentage and expanded income thresholds. Up to $5,000 of the adoption credit is now refundable.Employer-Provided Child Care and Dependent Care Assistance: The employer-provided child care credit is increased to 40% (50% for small businesses) of expenses, with higher maximums. The exclusion for dependent care assistance rises to $7,500 ($3,750 MFS).Education Credits and Student Loan Relief: The American Opportunity and Lifetime Learning Credits now require a Social Security number. The exclusion for employer-paid student loan assistance is made permanent and indexed for inflation.Specialized Provisions and New AccountsABLE Accounts and 529 Plans: Contribution limits for ABLE accounts are increased, and 529 plans are expanded to cover more K-12 and postsecondary credentialing expenses, with the annual K-12 limit doubled to $20,000.Trump Accounts: A new tax-advantaged savings vehicle for children under 18, with a $5,000 annual contribution limit, is introduced. Employer and charitable contributions are allowed, and a government-funded $1,000 pilot program is available for newborns through 2028.Qualified Small Business Stock (QSBS): The gain exclusion is expanded—50% after 3 years, 75% after 4 years, and 100% after 5 years for new stock, with higher per-issuer and asset limits, both indexed for inflation.Remittance Excise Tax: A new 1% excise tax is imposed on certain cash remittance transfers sent abroad, collected by remittance providers.Other Notable ChangesCharitable Deductions: An above-the-line charitable deduction of up to $1,000 ($2,000 joint) is made permanent. For itemizers, only contributions exceeding 0.5% of AGI are deductible; for corporations, only those exceeding 1% of taxable income are deductible.Opportunity Zones and Housing Credits: The Opportunity Zone program is renewed with decennial re-designations and expanded reporting. The Low-Income Housing Tax Credit and New Markets Tax Credit are made permanent and enhanced.Implementation TimelineMost provisions take effect for tax years beginning after December 31, 2024, with some (such as the new standard deduction and child tax credit enhancements) effective for 2025. Temporary provisions, like the tip and overtime deductions and car loan interest deduction, apply through 2028. The Act also includes various transition rules and inflation adjustments to ensure continued relevance.ConclusionThe One Big Beautiful Bill Act represents a comprehensive overhaul of individual taxation, locking in lower rates, expanding deductions and credits, and introducing new benefits for families, workers, and students. Its focus on permanent middle-class relief, simplification, and targeted incentives marks a significant shift in U.S. tax policy.

Read More >
Blogs

Tired of Turnover? Rethink In-House with Fractional Accounting

Tired of Turnover? Rethink In-House with Fractional Accounting

As your business grows, so do your financial needs, but relying on an in-house accounting team or turning to traditional outsourcing aren’t your only options. At Scrubbed we’re encouraging CPA firms and mid-sized companies in industries like SaaS, renewable energy, real estate, and e-commerce to rethink their in-house strategy and make the switch to a fractional model especially when specialized skills like SaaS accounting expertise are needed.Fractional accounting means hiring part-time or project-based accountants to seamlessly integrate with your team and provide critical support for day-to-day or strategic financial operations. Unlike a traditional outsourced accounting team, which focuses on completing delegated tasks, fractional accounting provides both greater flexibility and a team that can offer insight and suggestions to actively support your financial strategy.The Hidden Costs of In-House AccountingMany businesses underestimate just how difficult and expensive it is to maintain an in-house accounting team. Consider these industry realities:High Turnover and Recruitment Costs: In-house finance teams often experience high levels of churn. About 50% of in-house teams see high turnover every year, and one in six accounting firms deals with more than 20% turnover. For CPA firms, the average annual turnover is 15%. Added to that, the direct costs associated with replacing an in-house accountant can be as much as 50-60% of the employee’s annual salary.Talent Shortage: With 340,000 fewer accountants in the workforce than five years ago and 75% of CPAs reaching retirement age, hiring and retention have never been more difficult. In 2024, 83% of senior leaders reported an accounting talent shortage, a dramatic increase from 70% in 2022. The talent shortage is driving up salaries ( accounting managers are currently commanding salaries of $173,000 and rising) and makes it harder for businesses to find the specialized accounting expertise they need.Operational Inefficiencies: In-house teams can be inefficient, thanks to limited resources and difficulty scaling quickly. The result can be delayed financial reports and other operational slowdowns. According to the Wall Street Journal, more than 600 U.S.-listed companies cited the lack of accounting professionals in-house as a reason for material weaknesses in their financial reports over a 12-month period.The Fractional Accounting AdvantageStability and Retention: Fractional providers often experience lower turnover than in-house or traditional outsourcing services. For example, Scrubbed boasts a 96% retention rate, giving you a consistent, reliable accounting team that understands your business.Access to Top-Tier Expertise: The fractional model gives you immediate access to highly skilled finance professionals with Big 4-level experience in areas like tax strategy, compliance, financial reporting, and strategic planning. No need to hunt for the specialist talent you need in a tight market.Scalability: Whether you need extra support during busy times or specific advice for a significant project, a fractional team adapts in real time and can provide the resources you need with no fuss. Services like fractional CFO services make it easier to scale up quickly, giving you access to senior financial guidance exactly when and where it’s needed.Cost Savings: Eliminating the costs of full-time salaries, benefits, and recruitment means significantly lower overhead. Fractional teams can be far less expensive than other options because you’re only paying for expertise when you need it, not year-round.Instead of grappling with high turnover and rising costs, switching to a fractional accounting model gives your business flexibility to innovate and grow. Here’s how:It's Time to Embrace Fractional Accounting and FinanceThe traditional in-house model is no longer sustainable for many businesses thanks to rising costs, talent shortages, and inflexible in-house arrangements. Rethinking in-house and making the switch to fractional accounting can be the key to reducing costs, improving agility and efficiency, and mitigating your compliance risks.How Scrubbed Can Help Transform Your Accounting FunctionScrubbed’s fractional accounting teams do more than just handle the numbers. We provide fully customizable, high-level financial support that grows with your business:From overwhelmed to optimized. Our team becomes an extension of your business, seamlessly handling everything from bookkeeping and financial reporting to CFO-level strategic support.From limited resources to top talent. Work with highly skilled finance professionals without the commitment of full-time hires.From turnover chaos to stability. With our 96 percent retention rate, you can rely on a consistent, knowledgeable team with minimal turnover.

Read More >

Contact Information

SF Bay Area Headquarter
111 Anza Boulevard, Suite 320, Burlingame, CA 94010, United States

Phone: (800)837-5160
Email: [email protected]

"Scrubbed" is the brand name under which Scrubbed Advisory, LLC and Scrubbed Assurance LLP provide professional services. Scrubbed Advisory, LLC and Scrubbed Assurance LLP practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. Scrubbed Assurance LLP is a licensed independent CPA firm that provides attest services to its clients, and Scrubbed Advisory, LLC provides tax, finance, and support services to its clients. Scrubbed Advisory, LLC is not a licensed CPA firm.

Copyright © Scrubbed. All rights reserved.