Salesforce Security: 5 Risks Every Admin Should Know

By Heather Black

|
October 5, 2026
|
6 min read
A deleted dataset. A suspicious attachment. A contract nobody can trace.
Would you know what to do next?

The risk is real—and it reaches beyond Salesforce settings

Why Salesforce security deserves your attention

The consequences of a security breach can reach far beyond lost data. IBM’s 2026 Cost of a Data Breach Report puts the global average cost at US$4.99 million across industries, including the costs of investigating incidents and lost business. Source: IBM.

Salesforce customer environments have also been affected by significant attacks.

In August 2025, the Salesloft Drift supply-chain breach impacted more than 700 organisations. Attackers stole authentication tokens and used them to access connected systems, including Salesforce. Salesforce confirmed that the incident arose from compromised integration credentials, rather than a vulnerability in its core platform. Sources: FINRA and Salesforce.

People and processes are another important part of the picture. Google’s Threat Intelligence Group documented attackers impersonating IT support over the phone and persuading employees to authorise an attacker-controlled application, enabling Salesforce data theft. Source: Google Threat Intelligence Group, June 2025.

Broader research reinforces the importance of supporting users to work securely. Verizon’s 2025 Data Breach Investigations Report found that 19% of breaches in Europe, the Middle East and Africa involved unintentional mistakes. This is an across-industry finding, but it provides useful context for investing in clear guidance, usable processes and change management. Source: Verizon.

Recovery also deserves attention: 48% of breaches analysed in Verizon’s 2026 report involved ransomware. This broader statistic highlights why organisations should consider how they would restore operations alongside measures to prevent attacks. Source: Verizon.

Together, these findings show why Salesforce security requires an understanding of access, integrations, monitoring, recovery and user behaviour

How to mitigate the risk as as Salesforce Security Practitioner

As a Salesforce professional, you help your organisation get value from its technology. You build processes, manage access and support users. But how confident are you that the data, files and documents moving through those processes are properly protected?

This Cyber Security Awareness Month, Supermums is introducing our new FREE Salesforce Security Practitioner programme, exploring data backup and recovery, file scanning, document security, password management, compliance and audits, Salesforce Shield, and the role of change management.

Sign up to the FREE Salesforce Security Practitioner programme now and join our live webinars on Tuesday 13 October.

What happens when everyday work creates unexpected risk?

Picture four familiar situations.

A colleague uploads a document supplied by a customer.

Another runs a bulk update that overwrites important records.

A sales team edits a contract outside the agreed approval process, then saves several versions in different places.

A person rings up and says they can’t login in.

These are ordinary business activities. Yet each raises a different security question:

  • How are uploaded files checked for threats?
  • Could you restore the right data if something went wrong?
  • Could you show who changed and approved a document?

Managing permissions is an essential part of Salesforce administration. Developing security practitioner skills means widening your view to include prevention, recovery, evidence and the way people work.

1. Could you recover the data your business depends on?

If important records were deleted or corrupted tomorrow, who would lead the recovery? Which backup would you use? How would you know the restored information was complete?

These questions turn backup from a background task into a business conversation.

Our programme includes data backup and recovery, with Flosum in the mix. Flosum’s Backup & Archive offering supports protection of Salesforce data and metadata, with restoration capabilities.

The learning opportunity is to understand the questions behind a recovery approach: what needs protecting, how much data loss the business could tolerate, and how recovery would be tested.

Your first check: ask when your organisation last tested restoring its Salesforce data.

2. Do you know how files entering Salesforce are checked?

Customer documents, supplier attachments and files submitted through business processes all need consideration in your security approach.

A file being stored in Salesforce does not, by itself, tell you which malware checks have been applied to it.

The programme includes file scanning, featuring EzProtect, whose offering focuses on detecting malware and other threats associated with files and links in Salesforce.

For admins and consultants, the starting point is understanding how files enter the organisation, which controls cover those routes, and what happens when a threat is detected.

Your first check: identify your main file-upload routes and find out how suspicious files are handled.

3. Could you demonstrate that your document processes are controlled?

Imagine being asked: “Where is the document being created and saved, who approved this contract, which version did they approve, and what changed afterwards?”

Would the answer be easy to find?

Our document automation content focuses on security, compliance and audits, with Documill in the mix. Documill supports structured document creation, workflows, approvals and audit trails.

This is an opportunity to explore how document processes can reduce external document risk, support consistent approvals, traceable changes and clearer accountability. The aim is to understand how automation supports the controls your organisation needs and the evidence it must retain.

Your first check: follow one important document from creation to final storage. Where are its changes and approvals recorded?

4. Do you understand where Salesforce Shield fits?

Salesforce Shield adds capabilities including encryption, event monitoring, field auditing and sensitive-data detection.

Deciding whether to use it starts with your organisation’s requirements. What information is sensitive? Which activity needs monitoring? What history must you retain?

Our programme includes exploring Salesforce Shield and the considerations around using it. Building your understanding helps you contribute to these decisions and recognise how different controls fit together.

Your first check: establish whether your organisation uses Shield and who owns decisions about its configuration and use.

5. Are your users supported to work securely?

A security process needs to make sense to the people following it.

Do colleagues know how to report a suspicious file? Are document approvals straightforward?

Do they understand why sharing restrictions exist, or are they finding workarounds?

Change management connects security expectations with everyday behaviour.

Clear communication, relevant training and easy reporting routes help people put guidance into practice.

As part of this blog series, we will teach you about change management techniques to change security habits.

Your first check: ask a colleague what they would do if they noticed a security concern.

Build your confidence this Cyber Security Awareness Month

If you are a Salesforce admin or consultant looking to strengthen your security knowledge, these are useful conversations to start having.

You can begin by understanding your organisation’s risks, asking better questions and recognising where technology, processes and user support need to work together.

The Supermums Salesforce Security Practitioner programme brings these topics into one learning journey, with EzProtect, Flosum and Documill in the mix.

Sign up now and join our live webinars on Tuesday 13 October to start developing your Salesforce security practitioner knowledge.

Share

Written By:

Heather Black
Heather is the founder of Supermums Recruitment and Training. With an extensive background in Salesforce Consultancy, Career Coaching and Training she is passionate about empowering people with the right skills, attributes and knowledge to be successful in their career.

Subscribe To Our Weekly Top Tip Bulletin

Get Updates And Learn From The Best






By submitting this form you agree to the terms of Supermums Privacy Policy: https://supermums.org/privacy-policy/


Shopping Basket