
October is Cybersecurity Awareness Month, and the National Cybersecurity Alliance’s 2026 theme is refreshingly blunt: “Don’t Make It Easy for Them.” The premise is that attackers rarely need brilliance–they need the weak password, the missed update, the rushed click. If the past year of Salesforce-targeted campaigns proved anything, from the vishing playbook that put Scattered Spider in headlines to the OAuth integration breach at Klue, it’s that the same logic holds at org scale. Attackers didn’t out-engineer Salesforce; they walked through doors that someone left open. So this month, rather than reposting generic awareness tips, we’re translating each of the NCA’s four core behaviors into its Salesforce org-level equivalent–and launching something new: the Tython CISO Pulse, a weekly LinkedIn poll series measuring how security leaders are actually handling the questions this year raised.
Four Behaviors, Translated to Org Altitude
The NCA’s guidance targets individuals: use strong passwords and a password manager, turn on MFA, keep software updated, and recognize and report scams. Every one of those has a bigger, quieter counterpart in your Salesforce org.
- “Use strong passwords” becomes credential hygiene for non-humans. Your human users have MFA. Your integration users, connected app client secrets, and Named Credentials are the passwords nobody rotates. The September 30 Marketing Cloud secret expiry was Salesforce forcing this behavior; the rest of your credential inventory is still on the honor system.
- “Turn on MFA” becomes enforce it everywhere, including the exceptions. MFA has been contractually required for years–but audit the carve-outs: API-only users, legacy auth flows, permission sets that waive it, and SSO configurations that quietly downgrade.
- “Update your software” becomes release and enforcement readiness. Salesforce ships three releases a year plus security enforcement waves, and the orgs that get hurt are the ones that treat release notes as optional reading. Health Check, security alerts, and retiring legacy API versions are your “install updates” button.
- “Recognize and report scams” becomes training for vishing and OAuth consent phishing. The dominant Salesforce attack of the past two years isn’t an exploit–it’s a phone call. Awareness training that still centers on suspicious email links is fighting the last war.
Introducing the Tython CISO Pulse
Awareness campaigns are good at prescribing behavior and bad at measuring it. So each week this October we’re running a one-question LinkedIn poll aimed at CISOs and security leaders, and at the end of the month we’ll publish the results with analysis:
- Week 1 (Oct 2-8): Has your org deployed AI agents–Agentforce or otherwise–in production with access to customer data?
- Week 2 (Oct 9-15): Who explicitly owns your AI agents’ identity and permissions–security, the admin team, or nobody?
- Week 3 (Oct 16-22): Do agent actions that send, post, or modify data externally require human confirmation in your org?
- Week 4 (Oct 23-29): One year after the Salesforce extortion wave: has your SaaS security budget actually changed?
Vote, share, and argue with the framing–the point is a real snapshot of where the industry stands. Results and analysis land here on October 30.
Deeper Dive
Why “Easy” Is the Right Word for the Salesforce Threat Model
Look at the incidents we’ve covered in the past twelve months and sort them by attacker sophistication. The zero-click Agentforce research was genuinely clever–and it was found by defenders, reported responsibly, and patched before exploitation. The attacks that actually moved a billion records were vishing calls, stolen OAuth tokens, and guest user profiles misconfigured to expose data to the open internet. The pattern is stark: in the Salesforce ecosystem, novel vulnerabilities get patched by the vendor, while easy openings get exploited at scale because they live in customer configuration, where no patch can reach. “Don’t make it easy for them” isn’t a slogan here; it’s an accurate description of the entire defensive job.
A Week-One Checklist That Takes One Hour
If you do nothing else for Awareness Month, do this audit before Friday:
- Run Health Check (Setup → Health Check) and record your score. You can’t improve what you haven’t measured, and the score is a ready-made baseline for reporting progress at month’s end.
- List your connected apps and sort by last-used date. Anything unused in 90 days is attack surface with no business justification–the Klue breach started with exactly this kind of forgotten integration.
- Check guest user profiles on every Experience Cloud site. Object permissions, sharing rules, and the external sharing model. Misconfigured guest access was still being actively exploited as recently as this spring.
- Inventory accounts that bypass MFA. API-only integration users, service accounts, and anyone with “Multi-Factor Authentication for User Interface Logins” waived. Each one is a password-only door.
- Ask who owns your Agentforce agent’s permission set. If the answer takes more than one Slack message to determine, you’ve found this month’s real project–and previewed our Week 2 poll.
Most of that checklist is permissions archaeology, and it’s exactly the work we built Data Defense, our AppExchange app, to shortcut. It lets you search across every profile and permission set in the org, compare users side by side, and track how permissions change over time–so steps like the MFA-bypass inventory and the agent permission audit become minutes of filtering instead of an afternoon of Setup clicks. If Awareness Month is the nudge you needed to finally baseline your org’s access, install it and let it do the digging.
What We’re Watching This Month
October’s content calendar here follows the Awareness Month arc. Next week marks one year since the ShinyHunters extortion site named 39 companies and claimed nearly a billion records–we’ll look at what actually changed. The week after, we’ll survey the agent-security reckoning now sweeping the broader industry, from zero-click flaws in AI coding tools to Nvidia shipping containment infrastructure. Then agent governance, and finally the CISO Pulse results. Don’t make it easy for them–and don’t make it boring for yourself. This is the most interesting October the Salesforce security world has had in years.
Book a 15-Minute Security Strategy Call
Reference(s):
https://www.cisa.gov/resources-tools/resources/cybersecurity-awareness-month-toolkit