CRM is your prized possession, so why are you treating it as out of scope?

Ask any sales leader what the most valuable system they have in use, and they’ll tell you without hesitation: it’s Salesforce. Ask the security team the same question, and you’ll likely get a different answer – one that involves the network, the endpoint estate, or identity infrastructure.

That gap is a problem. And it’s a bigger one than most organizations realize.

The data that runs the business

Think about what actually lives in your Salesforce org:

  • Every active opportunity and its value.
  • Your entire customer and prospect base, with contact details, relationship history, and account intelligence built up over years.
  • Revenue forecasts.
  • Renewal dates.
  • Contractual terms.
  • Notes from sales calls that contain more competitive intelligence than most internal briefing documents.

This is not peripheral data, it’s the operational core of the business. It drives hiring decisions, informs product strategy, and sits at the centre of almost every commercial conversation. The moment something goes wrong with it – whether through loss, corruption, or unauthorized access – the effects ripple outward. Fast.

And yet, in most enterprise security program, the CRM sits somewhere between an afterthought and a blind spot.

How this happened

It’s worth understanding why this is the case, because the gap didn’t emerge from carelessness. It emerged from the way security thinking evolved alongside cloud adoption.

For most of its history, enterprise security was built around the perimeter. You protected what sat on your network. When SaaS platforms arrived, the mental model didn’t fully keep pace. The often-unstated assumption was that SaaS providers handled security, so internal teams could focus elsewhere. That assumption was never entirely accurate, but it became baked into how security programs were structured and budgets allocated.

Salesforce, specifically, reinforced this with its reputation for reliability and enterprise-grade compliance certifications. If it ticks the SOC 2 box, it must be secure. The organization relaxed, and the CRM dropped off the threat model.

“It’s still common for Salesforce to be recognised as business-critical, but not always treated as security-critical. The turning point typically comes when organizations stop thinking of it as ‘just another SaaS application’ and start viewing it as one of their most valuable data stores. Once that shift happens, conversations naturally move toward governance, identity, continuous monitoring, and recovery. The same disciplines they’d already apply to their most critical business systems,” believes Karmina Aquino, Head of Threat Intelligence at Cloud Protection for Salesforce.

What attackers already know

Here’s the uncomfortable truth: the people who want access to your data are not making the same assumption.

A compromised Salesforce org is extraordinarily valuable. A single account with broad access can expose your full customer list, the pipeline at every stage, pricing structures, and renewal vulnerabilities. Sadly, this is the kind of intelligence a competitor or malicious actor would pay handsomely for.

Threat actors increasingly rely on stolen credentials, infostealer logs, and social engineering to gain legitimate access to CRM platforms, because they provide direct access to high-value business data and trusted customer relationships. Social engineering campaigns are crafted around the account and opportunity data they’ve already scraped from a compromised org.

Meanwhile, your security team is focused on the endpoint that got the phishing email, rather than what the access was subsequently used to reach.

“To a threat actor, a CRM is far more than a customer database. It’s a blueprint of how the business operates. Once attackers obtain legitimate credentials, they can identify key customers, upcoming renewals, high-value opportunities, trusted relationships, and the people behind them. That intelligence allows them to prioritise victims, craft highly convincing social engineering campaigns, and make follow-on attacks such as fraud, phishing, and extortion significantly more effective. The initial compromise is often just the beginning,” Aquino states.

The scope problem in practice

Treating Salesforce as out of scope has concrete consequences beyond the abstract risk. It means the platform is rarely included in pen testing. Salesforce configurations aren’t reviewed during security audits. User access isn’t subject to the same periodic review cycle as Active Directory. Offboarding processes often have gaps specific to the CRM. Data classification policies that apply everywhere else simply don’t cover the org.

The result is that one of your highest-value assets is running with less scrutiny than the average file share.

The takeaway

However, there is good news. Bringing the CRM into scope doesn’t require rebuilding your entire security program. It requires a deliberate decision that Salesforce is a critical asset and therefore treating it accordingly. This means understanding who has access to it, what they can do with that access, how the data is protected, and what your recovery position looks like if something goes wrong.

Solutions like Cloud Protection for Salesforce exist precisely because your CRM deserves the same level of dedicated protection as any other critical business system: continuous monitoring, access visibility, and the ability to recover quickly when the unexpected happens.

Your sales team already knows Salesforce is the most important system in the business. It’s time your security program caught up.