Salesforce’s Security Overcorrection Is Locking Out the Wrong People
Salesforce has increased security measures by restricting VPN access, but this approach misses the mark by primarily targeting enterprise firms already using VPNs. Instead, it inadvertently blocks smaller customers, consultants, and partners who are not typically the sources of security breaches. The key issue is that customers lose control over their own security management, with broad policies that may reduce trust and hamper legitimate users. Salesforce teams should consider more nuanced controls that protect without excluding smaller and trusted users.
- Enterprise VPN restrictions mainly impact smaller customers and partners unfairly.
- Security controls should provide customers more autonomy over their own security policies.
- Overbroad security enforcement can alienate trusted consultants and partners.
- Targeting security measures where breaches originate is more effective than blanket bans.
I get that Salesforce is finally stepping up their security, and I appreciate it. But this solution does not solve for the problem. ShinyHunters are largely going after enterprise firms, which largely use enterprise VPNs in the first place. That freezes out smaller players instead. Customers should also have some level of control over their own security. Indiscriminate overreach on security doesn't make most of us more safe. This is especially true for those who understand and operate securely, protecting our customers in good faith. The current controls are overbroad. They disproportionately harm consultants, partners, and small customers who aren't the source of the breach problem in the first place. The post Salesforce’s Security Overcorrection Is Locking Out the Wrong People appeared first on Salesforce Break .