Stop thinking of Salesforce security as ‘set and forget’

Stop thinking of Salesforce security as ‘set and forget’

DHM Team
9 December 2025
Businesswoman In Cubicle Wearing Headset Talking To Colleague In Busy Customer Services Centre
Businesswoman In Cubicle Wearing Headset Talking To Colleague In Busy Customer Services Centre
Businesswoman In Cubicle Wearing Headset Talking To Colleague In Busy Customer Services Centre
Businesswoman In Cubicle Wearing Headset Talking To Colleague In Busy Customer Services Centre

Stop thinking of Salesforce security as ‘set and forget’

DHM Team
9 December 2025

Salesforce is one of the most secure cloud platforms in the world. But that doesn’t mean your security is automatic.

For many organisations, Salesforce security sits quietly in the background until something goes wrong. A misconfigured community, an overexposed API user, or a forgotten connected app suddenly opens a door no one knew existed. And when that happens, it’s often not the platform that failed. It’s the way it was set up and managed.

Salesforce’s shared responsibility model means exactly that. Shared. Salesforce secures the infrastructure. You secure how it’s used.

Why secure by default isn’t the same as secure forever

Salesforce gives you a remarkable level of security capability. Encryption, two factor authentication, audit trails, IP restrictions, connected app control, the list is long and robust. But it’s not automatic. You need to turn features on, configure them correctly, and review them as your business evolves.

It’s like locking your house. The builder gives you solid doors and high quality locks, but it’s your job to actually turn the key.

Too often, security settings are only reviewed when there’s a new implementation, a security incident, or a compliance audit. But Salesforce environments are living systems. New users join, apps are installed, automations change, data flows shift. Without regular review, your risk profile changes too, quietly and continuously.

The hidden cracks most admins miss

Doug Merrett, founder of Platinum7 and a former Salesforce platform security specialist, has performed more than 70 security assessments across industries. What he finds most often isn’t sophisticated breaches. It’s simple oversights.

Common ones include:

  • System admin profiles used for external API integrations
  • Connected apps left active long after the project that needed them ended
  • Communities configured with public data visibility
  • Sharing settings that expose far more than intended

None of these issues come from malicious intent. They come from the understandable belief that Salesforce takes care of that stuff.

Salesforce does a lot. But the last mile of security, the configuration and ongoing governance, belongs to you.

Where to start strengthening your org today

The good news? You don’t need to overhaul everything at once. Start small and focus on visibility.

  1. Run the Salesforce Health Check.
    It’s built in, simple to use, and highlights low hanging fruit. Not every finding is critical, but the top level items are worth fixing quickly.
  2. Review your user and permission model.
    Move towards permission sets and permission set groups rather than loading everything into profiles. It gives you more flexibility and control as your organisation grows.
  3. Apply the principle of least privilege.
    Give users only what they need to do their job, nothing more. It’s the simplest way to reduce risk.
  4. Audit your connected apps.
    You might be surprised how many are still active. Review them regularly, and if you don’t recognise one, disable it and investigate.
  5. Educate your people.
    Security isn’t just about settings. It’s a habit. Make sure everyone in your organisation understands how data moves through Salesforce and where responsibility sits.

Why culture matters as much as configuration

Even the most secure settings can’t protect against human shortcuts. Default passwords, open tabs on shared devices, or approving unknown apps are all common weak points.

That’s why real security comes from culture. When teams understand why controls exist, not just how to follow them, they make smarter choices every day.

Training doesn’t need to be complex. Even simple reminders about strong passwords, avoiding suspicious links, or checking who’s requesting access can make a major difference.

As Doug says, “The human is the last line of defence. Don’t blame them, support them.”

Security as a continuous story, not a checklist

Treat Salesforce security the same way you treat customer trust. It’s something you earn and maintain over time. The more confident you are in your controls, the more confidently you can innovate. Whether that’s rolling out new integrations, scaling digital experiences, or using Data Cloud for richer insights.

Security isn’t a blocker to progress. It’s what makes sustainable progress possible.

If it’s been a while since you looked under the hood, start with a health check and review your sharing model. The earlier you spot the gaps, the easier they are to fix. Let’s talk about how to make your Salesforce environment secure, trusted, and ready for what’s next.

InsightsRecent Articles