Is your customer data truly secure?
Don't guess when it comes to compliance and security. Request our Complimentary 15-Minute Salesforce Security & Exposure Audit today to receive a comprehensive, 2-page Executive Risk. Just complete our form and we will get in touch to arrange this for you.
Navigating Salesforce Security & MFA Compliance
The Shared Responsibility Trap: Why Standard Salesforce Logins alone may Not be as Secure as you thought
Salesforce secures the infrastructure, but you own the keys. We lock down your identity hardening, passkey configuration, and integration security.
Many UK SMEs and charities assume that because Salesforce enforces login security at the front door, their customer data is automatically safe and compliant under UK GDPR. Under the Cloud Shared Responsibility Model, this is a dangerous misconception. Salesforce guarantees that their cloud servers are hardened. However, if your team assigns full System Admin credentials to third-party integrations, leaves public email addresses as usernames, or fails to monitor administrative permissions, your organisation remains 100% legally liable for any resulting data breach.
Most CRM breaches do not occur via platform hacks, but rather through human error and integration vulnerabilities. Silent integrations—apps connected via simple OAuth handshakes or full licenses that are forgotten over time—represent silent backdoors that can expose your entire customer database if compromised.
Additionally, Salesforce security rules have significantly changed. Phishing-Resistant MFA is now mandatory for System Administrators and users with broad administrative permissions (such as 'Modify All Data' or 'Customize Application'). Standard SMS codes or authenticator pushes are no longer sufficient. If your company uses Single Sign-On (SSO) through identity providers like Azure AD or Okta, Salesforce actively audits the Authentication Method Reference (AMR) signal. If your SSO setup fails to transmit a phishing-resistant signal, your privileged users risk getting locked out entirely.
How Zon Projects Hardens Your Security Posture
Through our Platform Guard and Managed Operations retainers, we close the security gap so your organisation remains compliant and secure:
Our Security & Hardening Strategy
• Identity Hardening & Username Obfuscation: We decouple your staff's Salesforce usernames from public email addresses, neutralizing brute-force and credential-harvesting attacks.
• Passkey and SSO Alignment: We configure your Identity Provider (AMR/ACR) signals and enforce passkey-first policies across administrative roles, securing logins without causing lockouts.
• Integration License Migration: We migrate connected applications (like Xero, forms, or marketing suites) off expensive, over-privileged Admin seats and onto restricted, highly cost-effective API licenses.
• Systematic Security Auditing: We benchmark your system against native Salesforce security standards and UK Cyber Essentials access rules to eliminate permission creep and over-privileged roles.

