COMPANY
Georg Fischer (BFS)
INDUSTRY
Industrial/Manufacturing
REGION
Europe/North America
SALESFORCE USERS
1200 internal users
SALESFORCE PRODUCTS
Sales Cloud, Service Cloud, Marketing Account Engagement, CPQ, Experience Cloud
SOLUTION
Cloud Protection for Salesforce
1200
Salesforce users protected across 2 continents
~2000
URL security events detected over two years
~600
Confirmed threat elements identified over two years
10 days
From sign-up to full production deployment
“Take cyber security seriously, especially for Salesforce environments with significant external interaction. Unvalidated external data is a larger threat surface than most teams realize. Ask yourself who is submitting data to your system, and how. Understanding it early lets you focus on getting full value from the platform, instead of managing incidents after the fact.”
Sankar Sivagnanam, Director, IT Sales, Marketing and PLM, Georg Fischer
THE CHALLENGE
When your CRM is also your biggest open door
98%
of malicious Salesforce detections are URL-based, not file-based
WITHSECURE THREAT LANDSCAPE REPORT 2026
0
of those URLs are caught by traditional perimeter defenses
WITHSECURE THREAT LANDSCAPE REPORT 2026
1000s
of external cases processed monthly through GF BFS’s Salesforce instances
GEORG FISCHER (BFS)
Georg Fischer (BFS) uses Salesforce as the operational backbone of its global sales and service organization. Across two Salesforce instances covering Europe and North America, around 1200 internal users rely on it daily for managing customer relationships, processing orders, running marketing campaigns, and handling service cases. Hundreds of external partner portal users interact with GF BFS through the platform, too.
That level of external interaction is exactly what makes Salesforce so valuable. It is also what makes it a target. Every month, several thousand cases arrive through email-to-case and web forms, each one potentially carrying files or URLs submitted by people outside GF BFS’s network, and none of it passing through traditional perimeter defenses. According to WithSecure’s 2026 Salesforce Threat Landscape Report, 98% of malicious detections in Salesforce environments are URL-based, not file-based, and standard security tools are not built to catch them.
For Sankar Sivagnanam, this was not a theoretical concern. A security incident prompted the team to take a hard look at their Salesforce environment, and what they found gave them pause for thought: they had no systematic tooling to validate inbound files or URLs, and a manual process that could not keep pace with the volume they were handling.
“Unvalidated external data flowing into Salesforce is a large and often underestimated threat surface. A single incident is enough to cause serious reputational damage.”
Sankar Sivagnanam
Director, IT Sales, Marketing and PLM, Georg Fischer
THE SOLUTION
Cloud Protection for Salesforce. Native to Salesforce. In production in under 10 days
Why Cloud Protection?
- Native Salesforce integration meant no context-switching and no external tooling.
- Dashboard reporting accessible to the team where they already work.
Deployment process
- GF BFS’s Salesforce team validated the configuration in a development environment first, then promoted to production.
- The entire process took under 10 days.
Sivagnanam’s evaluation covered four areas: vendor reputation, cost, effectiveness, and native Salesforce integration. Cloud Protection for Salesforce met all four criteria. But what sealed it was understanding exactly how the product works. Scanning happens directly inside Salesforce, with only encrypted, anonymized metadata leaving the platform, ensuring speed, privacy, and compliance. For GF BFS’s team, that meant no added infrastructure, no disruption to existing workflows, and protection that runs quietly in the background. GF BFS’s Salesforce team completed the full setup in under 10 days, validating in a development environment before moving to production.
“WithSecure provided the right combination of everything we were looking for: vendor reputation, cost, effectiveness, and being truly native to Salesforce. It’s easy to configure and easy to use.”
Sankar Sivagnanam
Director, IT Sales, Marketing and PLM, Georg Fischer
THE IMPACT
Two years of threats caught. Zero complexity added
Since go-live, Cloud Protection for Salesforce has processed every case flowing through GF BFS’s two instances, adding up to several thousand interactions each month. Over the following two years, the product detected nearly 2000 URL security events, with approximately 600 confirmed threat elements identified within those detections.
The most prevalent threat type was linked to a Facebook Business Manager phishing campaign, a scheme that exploits platform workflows to harvest credentials and compromise accounts. To understand why that matters, consider what happens without protection in place: a service agent opens a case, sees what looks like a routine customer message, and clicks a link. In seconds, their Salesforce credentials are harvested. From there, an attacker with valid credentials inside a live CRM environment has access to customer records, open cases, partner portal data, and internal workflows. Nearly forty major companies have been listed on leak sites tied to breaches in their Salesforce environments. The link gets clicked before anyone realizes it was malicious. This is exactly the kind of URL-based attack that WithSecure’s 2026 Salesforce Threat Landscape Report flags as the dominant vector in Salesforce environments.
Cloud Protection for Salesforce intercepts that moment. The URL is flagged at the point of submission, before it ever reaches an agent’s screen. Monthly threat statistics are now reported to GF BFS’s cyber security team and visible to management, contributing directly to an improved internal security score for business applications.
Key outcomes
- Nearly 2000 URL security events detected over two years across two global Salesforce instances
- Approximately 600 confirmed threat elements identified within those detections over two years
- Full deployment completed in under 10 days
- Several thousand monthly inbound cases now systematically validated for files and URLs
- Improved internal security score for business applications
- Monthly threat reporting now visible to management and the cyber security team
Is your Salesforce environment exposed?
If your team processes files or URLs from external sources through Salesforce, whether through email-to-case, web forms, partner portals, or community sites, the same exposure GF identified exists in your environment, too. Most organizations only discover it after an incident.
Cloud Protection for Salesforce is native to your Salesforce environment, deploys in under 10 days, and starts protecting every inbound interaction from day one. No additional infrastructure. No disruption to existing workflows.
See how it works for your team.
Get a free demo
THE #1 SALESFORCE MALWARE PROTECTION SOLUTION
Fill the form and get:
Free 15-day trial – test the product without limitations
Real attack simulation and product demo
Free customized and actionable risk assessment