Professional Services Gain Momentum in Data Protection Software Market

Professional Services Gain Momentum in Data Protection Software Market

While Dependency of Organizations Shifts towards In-house Cybersecurity Professionals A major overhaul of data security led by stringent regulatory mandates has caused a meteoric rise in the adoption of data protection tools. Every enterprise dealing with consumer data has to abide by data security laws
Object Storage for Your Backups

Why You Should Consider Object Storage for Your Backups

Object Storage for Your Backups Ever since we can remember, files and folders have been stored on storage media using the hierarchical file system. This file arrangement has so far been convenient for general purposes like storing documents, photos, and other personal files in limited

CONTRIBUTORS

How To Humanize Your Data (And Why You Need To)

How To Humanize Your Data (And Why You Need To)

How To Humanize Your Data The modern enterprise is digital. It relies on accurate and timely data to support the ...
RSA Conference: FUD-free or filled?

RSA Conference: FUD-free or filled?

IoT 15 Billion Units By 2021 At the annual RSA conference, there were plenty of discussions and presentations on the ...
Cybersecurity Data Breaches: Incident Response Planning

Cybersecurity Data Breaches: Incident Response Planning

Incident Response Planning The topic of cybersecurity has become part of the boardroom agendas in the last couple of years, ...

RECENT NEWS

The New Industrial Revolution – According to the WSJ

The New Industrial Revolution – According to the WSJ

The insert in today’s US print edition of the Wall Street Journal is called The New Industrial Revolution. The paper updates ...
Capgemini in Gartner Magic Quadrant

Capgemini in Gartner Magic Quadrant

Paris, November 9, 2018 – Capgemini, today announced that Capgemini (Prosodie) has been positioned as a Leader by Gartner in its ...
Alibaba's on-demand online services unit valued at $30 billion: sources

Alibaba’s on-demand online services unit valued at $30 billion: sources

HONG KONG (Reuters) - Alibaba Group’s newly formed on-demand online services unit has rocketed in value to as much as ...
Amazon picks New York City, Virginia for $5 billion new headquarters

Amazon picks New York City, Virginia for $5 billion new headquarters

SAN FRANCISCO (Reuters) - Amazon.com Inc (AMZN.O) said on Tuesday it will build offices for up to 25,000 people in ...
Oracle Cloud Unveils New HPC Offerings to Support Mission Critical Workloads

Oracle Cloud Unveils New HPC Offerings to Support Mission Critical Workloads

Oracle Cloud Unveils New HPC Offering Oracle now provides a complete set of solutions for any high performance computing workload, ...
harold-byun

Salesforce Gets Serious About Its Security Ecosystem

Security Ecosystem

Salesforce is one of the fastest growing enterprise software companies in history and while security is a major roadblock for many cloud projects, the company’s extensive security investments appear to be paying off. Salesforce is one of just 9.4% of cloud providers that store data encrypted and they support a wide range of security controls including IP address whitelisting, device pinning, and multi-factor authentication. If there’s a concern about data going to Salesforce’s cloud, it’s a concern about how users treat that data, not the integrity of the platform.

password

Under a shared responsibility model, Salesforce takes care of platform security, while customers are responsible for taking precautions to ensure their users don’t expose that data to risk. That means the end customer is responsible for ensuring their salespeople don’t download all the company’s sales contacts before quitting to join a competitor, or that users have appropriate application permissions that don’t give them access to data they shouldn’t be able to access based on their role at the company.

One of the primary concerns of companies with large Salesforce deployments is a rogue employee taking sales contacts when leaving the company for a competitor. One study found that half of employees took data with them when they left their job and 40% planned to use that data at their next job. Key indicators that something is amiss can include an employee downloading an unusual amount of data. Let’s say this employee typically views 50-100 opportunities each day, and then downloads a report with 1,500 opportunities. That could indicate there’s a problem.

Another threat faced today is the possibility that a user or administrator will sell sensitive data. A shocking survey recently found that 25% of employees would sell company data for less than $8,000. Many companies store a vast amount of sensitive data in Salesforce including customer credit card numbers, Social Security numbers, patient information, and other sensitive or regulated data. Even if a rogue employee is at fault, a company can still be fined and sued if this data is stolen.

Such “insider threats” are increasingly common. Skyhigh recently analyzed data across its customers and found that companies, on average, experience 9.3 insider threat incidents each month. Not all of these events are malicious, they also include users mistakenly sharing data when they shouldn’t. All told, 89.6% of companies experience at least one insider threat each month on average. Salesforce recognizes these concerns and is making investments to support the development of security solutions that help address these concerns.

To help support customers in identifying these types of negligent or malicious activities, Salesforce has made available new event monitoring APIs that provide a record of user and administrator activity within Salesforce. The volume of these events is enormous. In the most recent quarter, Salesforce’s core platform processed 234 billion transactions, including logins, edits, and downloads. That’s an average of 3.7 billion events each business day – quite the haystack to search for a few needles.

API Connect

For customers looking for unusual user or account activity, the sheer number of events in Salesforce would be impossible to manually review. In making these new APIs available, Salesforce is making a significant investment to support its security ecosystem to build solutions that help Salesforce customers understand and manage user activity. Also, these APIs provide a near real-time feed of events that can be captured by security solutions and archived, rather than forcing customers to go to their Salesforce account manager and request logs for a post-incident investigation.

Salesforce is already one of the most secure cloud services available. Owing to its investment in platform security, Salesforce is one of the 8.1% of cloud services that meet the security standards of enterprises today. With the introduction of new APIs to support third party security solutions that give greater visibility into usage and the ability to detect threats, the company is well positioned to continue its leadership position in the cloud market.

By Harold Byun

Harold Byun

Harold is currently VP of Product Management at Skyhigh Networks. Prior to Skyhigh, he worked at MobileIron where he focused on mobile application delivery and security. Prior to MobileIron, he led the product management group at Zenprise (acquired by Citrix), where he launched their mobile DLP product and cloud offering to market. He also worked with the Vontu/Symantec DLP group and is the co-inventor on a patent filed for security risk visualization and scoring.

View Website

Cloud Community Supporters

(ISC)²
Cisco
SAP
CA Technologies
Dropbox

Cloud community support comes from (paid) sponsorship or (no cost) collaborative network partnership initiatives.