Why understanding Salesforce security is important
Salesforce is a powerhouse in CRM solutions, delivering a wide range of digital experiences to its users. Its widespread adoption across industries – including critical enterprises and governmental agencies – makes it a prime repository of high-value data. That goldmine inevitably draws the attention of financially motivated cybercriminals.
The scale of the threat became impossible to ignore in late 2025, when the ShinyHunters group launched a systematic campaign targeting misconfigured Salesforce Experience Cloud sites. By early 2026, the group claimed 300-400 breached organizations – including Adidas, Cisco, IKEA, Marriott, and Toyota – extracting and ransoming data at scale before the FBI seized the BreachForums domain used as their extortion site. If companies of that size and sophistication can be breached through Salesforce, you cannot afford to treat it as a secondary security concern.
Shared responsibility model sets the rules in Salesforce data security
Salesforce’s security framework is based on a shared responsibility model. This model defines the security obligations between Salesforce and its users. While Salesforce provides a highly secure cloud infrastructure with plenty of security controls, users are responsible for configuring these settings and mitigating external risks to protect their data effectively. This collaborative approach ensures that every layer of potential vulnerability can be addressed by the correct roles.
Multiple levels of Salesforce data security measures
Understanding Salesforce’s comprehensive security setup is crucial for effective data protection. Salesforce structures its security model into four levels:
- Organizational level security: Basic and platform-wide access controls, including login restrictions and authentication requirements.
- Object level security: Controls which users can access which data objects (akin to tables in a database).
- Field level security: Controls access to specific fields within an object, ensuring users see only the data essential to their role.
- Record level security: Controls access to individual records within an object, with options for role hierarchy, sharing rules, and manual sharing.

Organizational level security
At the foundational level, organizational security involves securing access to your Salesforce system. Traditionally this meant setting trusted IP ranges and login hours. In 2026, Salesforce has gone significantly further, enforcing several mandatory controls across all orgs:
MFA for all users – Multi-factor authentication is now required for every direct and SSO login, across both production and sandbox environments.
Phishing-resistant MFA for privileged users – Standard authenticator apps and push notifications no longer meet the bar for admin and privileged accounts. Hardware keys or passkeys are required.
Step-up authentication for reports – Users must re-verify their identity when accessing reports, with admins able to configure the window as tight as two minutes.
High-risk IP blocking – Connections from anonymising VPNs, proxies, and flagged IP ranges are blocked by default.
These are not optional best practices – they are now enforced platform-wide. Administrators should also enforce strong password policies and consider layering in additional solutions, such as WithSecure’s Cloud Protection for Salesforce.
Object level security
In Salesforce, an object is akin to a database table and houses data sets relevant to specific business functions. Object access has historically been controlled directly through user profiles, but Salesforce is actively moving away from this model. All investment in access management is now focused on Permission Sets and Permission Set Groups, with Salesforce having announced the retirement of permissions on profiles (postponed from Spring ’26, but the direction is firm). The best approach today is a minimal baseline profile combined with layered, role-based permission sets – avoiding the profile sprawl and permission creep that make orgs difficult to audit and secure.
Field level security
Field level security pertains to access controls at the individual field level within an object. This setup ensures that sensitive fields can be tightly controlled and varied between users depending on their role. Administrators can configure these settings through Permission Sets, keeping them decoupled from profile assignments.
Record level security
Record level deals with access to individual entries within an object. Salesforce offers several mechanisms to manage this, such as:
- Organization-wide defaults: Set baseline access levels for all records within the organization.
- Role hierarchy: Enables users higher in the hierarchy to access records below them.
- Sharing rules and manual sharing: Facilitate lateral sharing within teams or direct sharing for specific records, ensuring collaboration without compromising security.

External access and advanced cyber security measures on Salesforce
Salesforce administrators must safeguard against external threats arriving through Salesforce Experience Cloud, third-party APIs, and, increasingly, AI agents running within the platform.
Agentforce introduces a significant new attack surface. Because AI agents act on delegated permissions – reading records, updating data, triggering flows, and interacting with connected systems – an over-permissioned agent can unintentionally amplify exposure across your entire org. More critically, agents are vulnerable to prompt injection: a disclosed vulnerability chain called ForcedLeak (CVSS 9.4) demonstrated how an attacker could insert malicious instructions into an untrusted lead capture form, causing a Salesforce agent to exfiltrate sensitive CRM data. Treat agents with the same least-privilege discipline you apply to human users: scope their permissions tightly, audit their actions, and scan content they interact with.
For API and Experience Cloud access more broadly, permissions should be configured with the strictest settings possible to minimize the attack surface for external connections.
Keep your data safe with Salesforce Shield and WithSecure Cloud Protection for Salesforce
Salesforce Shield enhances file encryption and audit trails, adding a critical layer of security for data stored in the cloud.
WithSecure Cloud Protection for Salesforce takes security against external threats a step further, providing real-time defense against viruses, malware, ransomware, and phishing. It scans all files and URLs as they are uploaded to Salesforce – and again whenever a user or AI agent interacts with that content. This proactive approach blocks known threats and uses advanced behavioral analysis to detect zero-day attacks and emerging techniques, including those arriving through Agentforce workflows.
Last piece of advice: secure every access point
For enterprises using Salesforce, protecting every point of access and every point of data interaction – internal and external, human and AI – is critical. WithSecure Cloud Protection for Salesforce complements Salesforce’s built-in capabilities by offering real-time, proactive protection across files, URLs, and AI-driven workflows. Whether threats arrive through a customer support form, a community portal, or a prompt injection attack on an AI agent, your environment and your users stay protected.
