Agentforce Security:Salesforce上のAIエージェントは高速です。しかし、サイバー脅威はそれ以上に高速です。

AIエージェントが膨大な量のデータを処理するにつれ、セキュリティリスクも高まります。悪意のあるファイルやURLによって、マルウェアやフィッシングの脅威が持ち込まれる可能性があります。Agentforc…

新たな攻撃対象領域、新たな緊急性

Agentforceセキュリティ — 2025年に考慮すべき新たなセキュリティの側面

Agentforceは、皆様の働き方だけでなく、攻撃者の侵入方法をも変えようとしています。自律型AIの新たなユースケースの登場は、セキュリティ戦略において考慮すべき「新たな攻撃対象領域」を生み出しています。

現在、AIエージェントは営業、サービス、サポートを自律的に処理し、膨大なデータを瞬時に処理しています。しかし、業務がエージェントのスピードでスケールする一方で、攻撃対象領域も同様に拡大しているのです。

そこには、ファイルやリンクに対する組み込みのスキャン機能はありません。エージェントにフィッシングを検知する機能もなければ、デフォルトのセーフティネットも存在しません。

悪意のあるコンテンツは機械的なスピードで移動します。つまり、マルウェアや資格情報のフィッシングといった脅威が、Agentforceのワークフローを介して一瞬で拡散する可能性があります。ユーザーがアップロードし、エージェントがそれを取得し、自社のチームや顧客へと配信されてしまうのです。

そして、攻撃者はすでにこの事実に気づいています。UNC3944などのグループによる最近の攻撃キャンペーンは、SalesforceのようなSaaSプラットフォームが、今やフィッシング、アイデンティティ侵害、そしてラテラルムーブメントの主要な標的になっていることを示しています。攻撃者のターゲットがSalesforceなどのSaaSプラットフォームへと移行する中、この新たなAI主導のワークフローは実質的なリスクをもたらしています。

セキュリティ対策がそのペースに追いつかない限り、Agentforceは業務を自動化するのと同じ速さで「リスクも自動化」してしまう可能性があります。

Agentforceデータの保護は「利用ユーザーの責任範囲」です

Agentforceはビジネスを加速させますが、同時にリスクも加速させます。実際、Salesforceの報告によると、セキュリティリーダーの79%が「AI主導の脅威は間もなく従来の防御策を追い越すだろう」と懸念しています。

AIエージェントは、ポータル、フォーム、そしてSlackやWhatsAppといった外部連携ツールからのファイルやURLを、人間の目による確認や組み込みの脅威スキャンを経ることなく処理します。

これは、皆様のセキュリティ境界に以下のような脅威が含まれるようになったことを意味します。

  • フィッシングリンク: エージェントによって瞬時に共有され、資格情報の窃盗やアカウントの乗っ取りにつながります。
  • 悪意のあるファイル: 顧客やパートナーによってアップロードされ、ランサムウェアやその他の脅威を含んでいます。
  • 人間とエージェントの相互作用: エージェントが従業員にデータを引き渡す際、チーム全体に脅威が拡散します。
  • コラボレーションツール: 共有されたファイルやリンクにより、リスクがSalesforceを超えて、接続されているすべてのツールに拡大します。

Salesforceは、デフォルトではこれらのコンテンツをスキャンしません。また、エージェントは自ら脅威を見つけ出す方法を知りません。

「責任共有モデル」に基づき、Salesforce環境に出入りするデータを保護するのは、クラウドを利用するお客様の責任範囲です。それが人間によって操作されたものであれ、AIエージェントによるものであれ、設定やアクセス権、そして通過を許可するデータを含め、そのデータを保護することは皆様の責任となります。

Agentforceにおける攻撃シナリオの例

リアルタイムのスキャンがなければ、脅威は防御のスピードを追い越してしまいます。

例えば、以下のようなシナリオが考えられます。

  1. 顧客がポータルを介してファイルをアップロードします。一見PDFのように見えますが、内部にマルウェアが隠されています。
  2. AIエージェントが、サポート依頼や営業の問い合わせを処理するために、そのファイルを読み込みます。
  3. エージェントは、そのファイルを従業員に送信するか、Slackやメールなどの別のツールに転送します。
  4. ファイルが開かれ、マルウェアが実行されます。この時点で、すでに社内環境への侵入を許してしまっています。
  5. そこから脅威は横方向に広がり、アカウント、データ、そして接続されたシステムを侵害していきます。

この間、人間の目は一切ファイルを介しておらず、誰もフィッシングリンクをクリックしていません。それでも、脅威は侵入に成功したのです。

これこそが、「エージェントのスピード」が「攻撃者のスピード」になってしまう仕組みです。これを防ぐには、すべてのファイル、URL、そしてエージェントのアクションをリアルタイムでスキャンする必要があります。

Agentforceワークフローを保護する方法

Agentforceは数秒で意思決定を行います。したがって、セキュリティはそれ以上の速さで動作しなければなりません。

WithSecure™ Cloud Protection for Agentforceは、自律型AIと人間のワークフローの双方をリアルタイムで保護するために構築されています。Salesforceプラットフォームの内部で直接動作するため、遅延や摩擦、脅威の見落としは一切ありません。

  • エージェントの速度に合わせたリアルタイム保護
    ファイルやURLは、アップロード、ダウンロード、クリック、またはエージェントによる取得時に瞬時にスキャンされ、危害を及ぼす前に処理されます。当社の検知処理は、ほとんどのAIエージェントが動作するよりも早く完了します。
  • 100% Salesforceネイティブな統合
    外部でのデータ処理は不要です。複雑さが増すことも、隠れた脆弱性が生まれることもありません。プラットフォーム内でシームレスかつ摩擦のない、認定された保護機能を提供します。
  • すべての相互作用を保護
    顧客によるアップロードやポータルフォームから、オムニチャネルのサポートワークフローに至るまで、脅威がどこから侵入しようとも、その入り口で遮断します。
  • 稼働率と信頼性の維持
    Iの自律性を損なうことなくワークフローを保護し、エージェントの効率性とセキュリティの両立を保証します。

Agentforce向けネイティブ保護の詳細を見

規模への備え

Agentforceの導入スピードは加速する一方です。チームがより多くのワークフローにAIを導入し、より多くの非構造化データを処理するようになれば、セキュリティ上のリスクも同じ速さで高まります。

保護対策がそのペースに追いつかない限り、ファイル、リンク、そしてリスクは増え続ける一方です。

WithSecure™ Cloud Protectionは、これらの変化に先手を打つサポートをします。当社のネイティブソリューションは、企業のAIトランスフォーメーションに合わせてスケールし、以下を提供します。

  • すべてのアシスタント(エージェント)および人間のタッチポイントにおける一貫した保護
  • ワークフローの拡張に合わせて迅速にスケールするリアルタイムのカバー範囲
  • セキュリティがAIトランスフォーメーションのスピードに追いついているという安心感、そしてさらなる展開への自信

Agentforceはビジネスをより迅速に進めるためのものです。私たちは、それが「安全に」行われることを保証します。

30秒でわかるAgentforceセキュリティ

まだご不明な点がありますか?

WithSecure™は、皆様がセキュリティ上の責任を果たしつつ、SalesforceおよびAgentforceを最大限に活用できるよう支援することをお約束します。私たちは共に、エージェントを活用したデジタル変革を、安全で、シームレスで、未来に対応できるものにしていきます。ワークフローをどのように保護できるかについて詳しくお知りになりたい場合は、ぜひお気軽にお問い合わせください。

Doesn’t Salesforce protect against these threats already?

Salesforce doesn’t scan links or files shared in Agentforce workflows unless you implement an additional security layer. It’s your responsibility to protect the data flowing through your AI workflows and automations.

We already have endpoint/email protection. Isn’t that enough?

Files and links can bypass traditional tools completely. If your AI agent clicks a phishing link or opens a malicious file inside Salesforce, your other tools may never see it. Only a native solution scans content where the agent acts, and at the point of entry.

How does this integrate with our setup?

WithSecure™ Cloud Protection is 100% Salesforce-native. It integrates seamlessly with your environment – no external routing, no added complexity, and no impact on agentic performance. The Agentforce extension comes with the main managed package at no additional cost. There’s no separate management portals or interfaces, no extra charge.

What makes this better than other security tools?

Only WithSecure scans inside Salesforce in real time — at the point of agent action. Competitors scan externally, after the fact, or not at all. That’s why real-time + native + agent-aware protection is unmatched.

Is this compliant and auditable?

Yes. You get full audit-ready logs, policy history, and certified trust (ISAE 3000 Type 2 / SOC 2 Type 2, ISO 27001). Every scan and decision is traceable, even the seemingly invisible agent actions.

Secure your agent workflows — in real time, with zero friction

WithSecure™ Cloud Protection protects what Agentforce accelerates. Real-time file and link scanning. 100% native. No added cost. No added complexity.

Agentforce security – the new security aspect to consider in 2025.

Agentforce is changing how you work and how attackers get in. New agentic AI use cases create a new attack surface to consider in your security strategy.

AI agents now handle sales, service, and support autonomously, rapidly processing vast amounts of data. But while your operations scale at agentic speed, your attack surface does too.

There’s no built-in scanning for files or links. No phishing awareness in agents. No default safety net.

Malicious content moves at machine speed. That means threats like malware or credential phishing can flow through Agentforce workflows instantly: uploaded by a user, retrieved by an agent, delivered to your team or customers.

And attackers have noticed. Recent campaigns by groups like UNC3944 show how SaaS platforms like Salesforce are now primary targets for phishing, identity compromise, and lateral movement. As attackers shift toward SaaS platforms like Salesforce, this new AI-driven workflow introduces real risk.

Unless your security keeps pace, Agentforce could automate risk as fast as it automates work.

Securing Agentforce data is your responsibility

Agentforce accelerates business. But it also accelerates risk. In fact, 79% of security leaders believe AI-driven threats will soon outpace traditional defenses, as reported by Salesforce.

AI agents process files and URLs from portals, forms, and integrations like Slack or WhatsApp, without human review or built-in threat scanning.

That means your security perimeter now includes:

  • Phishing links: Instantly shared by agents, leading to credential theft or account compromise.
  • Malicious files: Uploaded by customers or partners, containing ransomware or other threats.
  • Human-agent interactions: Agents hand off data to employees, spreading threats across teams.
  • Collaboration tools: Shared files and links extend risk beyond Salesforce to every connected tool.

Salesforce doesn’t scan this content by default. And agents don’t know how to spot threats.

According to the Shared Responsibility Model, it’s up to you, the cloud customer, to secure the data flowing in and out of your Salesforce environment. Whether it’s touched by a human or an agent, protecting that data is your responsibility – including how it’s configured, accessed, and what’s allowed to pass through.

What an Agentforce attack scenario looks like

Without real-time scanning, threats can move faster than your defenses.

Imagine this:

  1. A customer uploads a file through your portal, which it looks like a PDF, but it’s hiding malware.
  2. An AI agent retrieves the file to process a support request or sales inquiry.
  3. The agent sends it to an employee or forwards it to another tool like Slack or email.
  4. The file is opened and malware executes. It’s already inside your environment.
  5. From there, it spreads laterally, compromising accounts, data, and connected systems.

No human saw the file. No one clicked a phishing link. But the threat still made it in.

This is how agentic speed becomes attacker speed. Unless you scan every file, URL, and agent action in real-time.

How to secure Agentforce workflows

Agentforce makes decisions in seconds. Your security needs to move even faster.

WithSecure™ Cloud Protection for Agentforce is built to protect both autonomous AI and human workflows in real time. It operates right inside the Salesforce platform. No delays, no friction, no missed threats.

  • Real-time protection at agent speed
    Files and URLs are scanned instantly at upload, download, click, or agent retrieval before they can cause harm. Our detection completes faster than most AI agents can act.
  • 100% Salesforce-native integration
    No external processing. No added complexity. No hidden vulnerabilities. Just seamless, frictionless, certified protection inside the platform.
  • Secures every interaction
    From customer uploads and portal forms to omni-channel support workflows — threats are intercepted wherever they enter.
  • Built for uptime and trust
    Protects workflows without disrupting AI autonomy, ensuring agent efficiency and security go hand in hand.

Learn more about native protection for Agentforce

Preparing for scale

Agentforce adoption is only accelerating. As your teams deploy AI across more workflows and process more unstructured data, the security stakes grow just as fast.

More files. More links. More risk – unless your protection can keep pace.

WithSecure™ Cloud Protection helps you stay ahead of these changes. Our native solution scales with your AI transformation, giving you:

  • Consistent protection across all agent and human touchpoints
  • Real-time coverage that scales as fast as your workflows do
  • Confidence to expand, knowing your security keeps up with your AI transformation

Agentforce will help you move faster. We make sure you move securely.

Agentforce security in 30 seconds

Still have questions?

At WithSecure™, we’re committed to helping you make the most of Salesforce and Agentforce while fulfilling your security responsibilities. Together, we can ensure your agent-powered digital transformation is secure, seamless, and future-ready. If you’d like to learn more about how we can help safeguard your workflows, let’s connect.

Doesn’t Salesforce protect against these threats already?

Salesforce doesn’t scan links or files shared in Agentforce workflows unless you implement an additional security layer. It’s your responsibility to protect the data flowing through your AI workflows and automations.

We already have endpoint/email protection. Isn’t that enough?

Files and links can bypass traditional tools completely. If your AI agent clicks a phishing link or opens a malicious file inside Salesforce, your other tools may never see it. Only a native solution scans content where the agent acts, and at the point of entry.

How does this integrate with our setup?

WithSecure™ Cloud Protection is 100% Salesforce-native. It integrates seamlessly with your environment – no external routing, no added complexity, and no impact on agentic performance. The Agentforce extension comes with the main managed package at no additional cost. There’s no separate management portals or interfaces, no extra charge.

What makes this better than other security tools?

Only WithSecure scans inside Salesforce in real time — at the point of agent action. Competitors scan externally, after the fact, or not at all. That’s why real-time + native + agent-aware protection is unmatched.

Is this compliant and auditable?

Yes. You get full audit-ready logs, policy history, and certified trust (ISAE 3000 Type 2 / SOC 2 Type 2, ISO 27001). Every scan and decision is traceable, even the seemingly invisible agent actions.

Secure your agent workflows — in real time, with zero friction

WithSecure™ Cloud Protection protects what Agentforce accelerates. Real-time file and link scanning. 100% native. No added cost. No added complexity.