Salesforce Security Posture Kit
What a misconfigured Salesforce org actually exposes — to a compromised user, a malicious OAuth grant, or an anonymous visitor who never logged in. The 2025–2026 breach wave did not start with a compromised account, and this kit scores the two entry points that did it above the one the other posture kits share.
What this actually gives you
- The 2025–2026 breach wave did not start with a compromised account. It started with an anonymous guest user who never logged in, and with a single OAuth approval on a connected app. This kit scores three entry points, and weights those two highest.
- The root cause is a checkbox: "API Enabled" on the guest profile plus Organization-Wide Defaults at Public Read/Write. No password, no session, no MFA, no login history — nothing to compromise, only a door left open.
- The connected-app token chain that began with a third-party sales tool reached roughly ten times as many organisations as prior Salesforce-direct incidents. The OAuth surface here is grounded in that, not a hypothetical.
- Without Shield or the Event Monitoring add-on, retention is about one day. That is why these incidents are discovered late, and file 06 makes it the headline. Standard Salesforce also cannot say who viewed a record.
- No CIS benchmark exists for Salesforce. File 04 maps to Security Health Check and the community Security Benchmark for Salesforce, and discloses the substitution.
The highest-impact Salesforce exposures of the last two years did not start with a compromised account. They started with an anonymous guest user — a visitor who never logged in, never had a password and never triggered MFA — hitting an internal API endpoint that was never meant to be public. And separately, with a single OAuth approval on a connected app that then persisted access with no further login. The M365, Workspace and Okta kits all model "what can a compromised account reach". Salesforce forces a different question, and this kit asks it: three entry points, not one, with the two that actually drove the 2025–2026 incidents weighted highest.
The root cause has a name, and it is a checkbox. "API Enabled" on the guest user profile, combined with Organization-Wide Defaults at Public Read/Write. That identity has no password, no session, no MFA and no login history — there is nothing to compromise, only a door left open. The campaign that targeted hundreds of organisations and threatened over a billion records in 2025–2026 walked through it with a modified inspection tool and a pagination bypass around the platform's query cap. File 03 scores the guest-user rows at the highest weight in the tool and explains why in plain words, with an N/A status for orgs that do not run Experience Cloud.
The OAuth chain had a measured blast radius. The connected-app token breach that began with a third-party sales tool in 2025 reached roughly ten times as many organisations as prior Salesforce-direct incidents, and its effects ran into the 2026 customer-success-platform incident: token revocation, AppExchange removal, the same group attributed. The Connected Apps surface in this kit is grounded in that history, not in a hypothetical.
No CIS benchmark exists for Salesforce, and the kit says so. File 04 maps to Salesforce's own Security Health Check and the community-maintained Security Benchmark for Salesforce, and discloses the substitution in its README tab rather than faking parity with its siblings.
The detection finding is a timeline problem. Without Shield or the Event Monitoring add-on, an Enterprise Edition org gets about one day of retention on a small set of log types. That is why these incidents are discovered late, and file 06 makes it the headline rather than a licensing footnote. Standard Salesforce also cannot answer "who viewed this record" — only who changed it — and file 05 surfaces that plainly.
What you get
01 Assessment Methodology (DOCX) — why the risk model differs, the five modules, run order, cross-links and assumptions.
02 Identity & Access Review Workbook (XLSX) — MFA & Session Security, Connected App OAuth Policy (admin pre-approval, scope creep, dormant authorisations, IP relaxation), Admin Hygiene (System Administrator count, delegated admin, the permission-set transition most orgs have not finished) and Guest User Governance — 16 weighted controls rolling into one identity posture score.
03 Blast Radius Scoring Tool (XLSX) — the flagship module. Select edition and Shield status, pull the guest profile's object permissions if Experience Cloud is in use, answer the control questions across Guest User / Experience Cloud, Connected Apps, permission sets & profiles and detection, and get one score, a band on the same bands as the sibling kits, and a closure list ranked by risk-weighted points.
04 Security-Benchmark Hardening Checklist (XLSX) — Org Baseline Settings, Guest User & Experience Cloud (including Aura and Lightning Web Runtime endpoint review), Connected App Governance, and Permission & Data Access ("Modify All Data" and "View All Data" to a documented minimum), scored gap-to-target.
05 Data Governance Review (DOCX) — Shield Platform Encryption where licensed and whether it is actually applied to the fields that matter, Field Audit Trail versus the standard 18-month Field History, and sharing-rule and bulk-export posture.
06 Detection Readiness Matrix (XLSX) — Event Monitoring source mapping by edition and Shield status, each row stating whether it can reconstruct guest or OAuth abuse.
07 Executive Summary Template (DOCX) — one page, with a dedicated Experience Cloud / guest user exposure section separate from the general findings, because that surface has driven a disproportionate share of real incidents.
sfdc01.json — scoring bands, entry points, edition components, the benchmark substitution and the module map.
A worked example throughout. Hollow Creek Outfitters, a fictional mid-market outdoor-goods retailer on Enterprise Edition without Shield, running a customer-facing Experience Cloud portal with API Enabled checked on the guest profile for an order-status lookup.
Where it sits. The fourth kit of the Cloud Identity Posture set with the M365, Google Workspace Okta and GitHub / GitLab kits; the set of five is cheaper than buying them separately. The IR Runbook Library is the response layer — runbook 18 is a third-party SaaS breach, runbook 09 confirmed data exfiltration. Run it against a vendor's org, or when a connected-app vendor is the vector, with the TPRM Program Kit; hand file 07 to the Director's Cyber Oversight Kit.
Written against Salesforce edition, Shield and Experience Cloud terminology and public incident reporting as of Q3 2026. Not Financial Services Cloud or Health Cloud overlays. Salesforce re-tiers Shield components regularly, so the licensing logic is marked verify. Scores are a prioritisation aid, not a certification, an audit opinion or an insurance-underwriting determination. Not legal advice.
Also available in a bundle
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee