Salesforce is the largest PaaS in the world. As customers put more sensitive data into the platform, more customers ask “How do I align our Salesforce to our company’s Security Posture?” Listen to our guest experts discuss the nuances of Salesforce Security and how to bridge the gap between Infosec, Compliance and Salesforce teams.
As the volume, velocity, and variety of data in Salesforce continues to increase, so have the demands on Data and System Architects to accelerate the pace of innovation. Together, these trends have led to a growing call for data security to be embedded earlier in the DevOps cycle. While this idea of “shifting left,” isn’t new, getting it right can be difficult. From CI/CD to OCD, you’ll learn how to enable and influence developers to do the right thing. Whether you’re committed to DIY or ready to implement automation tools, we’ll discuss what to look out for and a rubric for decision-making.
Our speakers include Brian Olearczyk, CRO of RevCult, Craig Probus, Director of Product of OwnBackup, Lorenzo Frattini, CEO of Clayton, and Andrew Hart, Director of Technical Architects at OwnBackup.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Business leaders and Information Security pros alike will continue to be challenged with both managing data and securing it. Data classification can be foundational by providing a data governance framework that makes securing data easier, but also unlocks insights into its value and best uses.
In this episode, Andy Ognenoff, Managing Director, Certified Technical Architect at Accenture and Brian Olearczyk, CRO at RevCult, share insights on why data classification is important, and how it contributes to sustainable data security, governance & compliance. Also, the benefits of data classification (and common misconceptions), such as improving business operations, and increasing value from security budgets; why your project must start with getting enterprise-wide buy-in and how to sell it to your stakeholders; the complexities of classifying data on Salesforce, and the choices between automation and tooling vs manual, people-powered approaches; and best practices and recommendations for leveraging data classification to create an enterprise-wide data governance framework.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Extreme agility. Always have a strategy. Focus on the basics instead of “shiny objects.“ Earlier this year, our panelists summed up what they learned in 2020 with these nuggets of wisdom – along with some unexpected positives – and what drove their security mindsets for 2021.
Now, we’ve invited them back to share more of what they’re learning, thinking and doing about security and innovation on their mission-critical platforms. In this episode, we talk with senior security executives: Thomas Davis, CISO, Terminix; Pat Benoit, VP, Global Cyber GRC/BISO, CBRE; and Jonathan Hay, SVP/CISO, Cadence Bank, N.A., and the discussion is moderated by RevCult’s Brian Olearczyk, CRO. Our topics for this informal discussion include:
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
The Salesforce Security Playbook – Learn how to bridge the gap between InfoSec and Salesforce DevOps: Salesforce has evolved far beyond a traditional CRM into an enterprise PaaS solution that stores high risk, mission critical information – yet companies don’t have clear visibility into the risk exposure of their Salesforce environment because they don’t have a clear security program for Salesforce or the tooling to support it. In this episode, Brian talks with two of RevCult’s Salesforce security practice leaders, Devin Bushweller, Solution Architect, and Laura Nesbitt, Partner Success Leader, about the most common security problems that Salesforce Administrators and Developers run into, the risks of not having a security program specifically tailored to Salesforce, best practices for efficient, effective collaboration between InfoSec & Salesforce DevOps teams – and more!
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
To request a PDF copy of RevCult’s Salesforce Security Playbook, send a request to Info@RevCult.com with subject line: Send me RevCult’s Salesforce Security Playbook
NIST and Salesforce—how does it all work? In this episode, we are joined by cybersecurity experts from Salesforce, FairWarning, and OwnBackup to discuss how organizations using Salesforce can leverage the NIST Cybersecurity Framework to mitigate security risks. You’ll walk away with tangible next steps for governing Salesforce, like data classification, access management, encryption at rest, user access management, compliance reporting, and more.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Most users are unaware of the large amount of sensitive data that resides in their Salesforce orgs and are living some major data security gaps. We know this because RevCult regularly conducts Security Risk Assessments (SRAs) for our clients and recently published a State of Salesforce Data Security report based on an aggregation our findings. In this episode, Brian, Pete, and RevCult’s Security Practice Engagement Leader, Ed Ponte, summarize the five key findings from the report. They explain business impacts and recommend how your organization can control these persistent risks. The discussion also covers future challenges and opportunities, giving our take on how you can bolster data security on your cloud platforms in 2021 and beyond.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Pete Thurston, Chief Product and Solutions Officer at RevCult, explains how to know when it’s time to get your Salesforce org assessed for risk from a security and compliance perspective. Pete shares common trends and key issues that have emerged from the hundreds of security risk assessments RevCult has performed over the years for clients. You’ll hear how prevalent these issues are, why they occur, and what you can do to avoid them…proactively.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates. Presented at Resilience.Work, hosted by Salesforce® and Ownbackup.
Get up to speed on the latest cybersecurity trends and threats in this episode. Experts from NIST, Salesforce, RevCult, FairWarning, and OwnBackup discuss how organizations can leverage cybersecurity frameworks, Salesforce Shield, and additional security controls (including those needed for remote workforces), to create a robust and innovative cybersecurity program. Listen now to learn how to build a defense-in-depth approach to Salesforce security.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Most companies aren’t using Salesforce as it was originally deployed and have applied a tremendous amount of innovation to the platform. But this incredible innovation largely happens outside the oversight of InfoSec. In this episode, RevCult’s Brian Olearczyk outlines the challenges many organizations now face with how to confirm their security controls have been implemented, as they continue to evolve Salesforce (and adapt to remote workforces). Brian offers clear tactics to evaluate your Salesforce risk exposure, take back control of your security, and proactively manage it going forward.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates. Presented at Resilience.Work, hosted by Salesforce® and Ownbackup.
For many companies, data security and governance in Salesforce is an afterthought. But not Cadence Bank. The bank’s development and innovation efforts in Salesforce have kept security front and center. In this episode, Cadence Bank’s CISO and VP, Jonathan Hay, and Applications System Specialist, Carl Lange, join Pete and Laura Nesbitt, RevCult’s Partner Success Leader, to discuss bringing InfoSec and Salesforce COE teams together, primary drivers for security and compliance, innovation strategies, biggest security journey challenges, operationalizing data security, and much more.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Last year, most security leaders were forced to adapt on the fly and completely rethink their strategies for 2021. This episode takes a conversational approach to discussing those strategies and how others are handling urgent data security challenges in these unusual times. Moderated by Brian, our panel of speakers includes Pete, and our guests are senior security executives Thomas Davis, CISO at Terminix (ServiceMaster), Pat Benoit, VP, Global Cyber GRC / BISO at CBRE, and Jonathan Hay, CISO at Cadence Bank. The discussion covers “boots on the ground” lessons from 2020, real-world examples of InfoSec and corporate security priorities for 2021, solutions to support current security initiatives, and more.
– Visit RevCult’s Resources to learn more and sign up to receive news and updates.
How does a remote workforce impact the security of your Salesforce data? In this episode, security leaders from RevCult, FairWarning, and OwnBackup discuss how COVID-19 upended the operations of virtually every company, leaving InfoSec and Compliance executives scrambling to adapt their Salesforce policies. The hosts explain the Shared Responsibility for Security model, why it’s so important, and how to achieve data governance in this ever-changing environment. Listen in to learn how your organization can protect and secure its Salesforce data, while also promoting business growth and connecting with employees around the world. – Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Best-selling author and Data & Analytics Strategy Innovation Fellow at West Monroe, Doug Laney makes his case for how CIOs are the caretakers of a company’s most valuable asset: it’s data. And yet many CIOs and CFOs use antiquated accounting regulations to value company data, instead of taking a more proactive and modern approach. Doug explains how to accurately quantify the value of your data, which leads to more effective management, use, and ultimately monetization of that data. Doug is joined by security experts from RevCult, FairWarning, and OwnBackup to give their input on how companies can secure and protect their sensitive Salesforce information. – Visit RevCult’s Resources to learn more and sign up to receive news and updates.
Federal regulations around securing personal and financial data are incredibly strict (as, likely, are your internal data security policies). RevCult and FairWarning co-host this episode to explain how to meet these strict guidelines by addressing the two sides of the data security coin: proactive management of user access to data and reactive measures if the worst happens. Kevin Thompson, Security Architect with Salesforce, also joins the discussion.
– Visit RevCult’s Resources page to learn more and sign up to receive news and updates.
Jeff DiMuro, Chief Security and Compliance Architect for Salesforce, is back with us again – this time, our topic is data privacy and how our privacy practices have to evolve in the “Age of Contact Tracing.” Listen and learn how to take back the controls to assure data is managed securely and policies comply with corporate security posture. Along with RevCult’s Brian Olearczyk and Pete Thurston, we discuss why it’s time to take a proactive approach to Salesforce data security, and to understand the differences between data privacy and data security – and why one can’t exist without the other. We tackle the hardest questions about privacy by design, data protection, accountability, individual rights, and control of data.
What’s a CASB? Why Salesforce Shield? In this episode we welcomed our friend, Tuhin Kumar, Senior Product Manager at Salesforce, to help us understand why migrating from a CASB to Salesforce Shield (a Salesforce-native encryption solution) can improve platform performance along with encryption. Tuhin shares best practices, common pitfalls, and considerations for an ideal encryption migration journey. RevCult’s Pete Thurston and Brian Olearczyk share a client case study to illustrate a real-life implementation journey. The discussion wraps up with a best-practice migration road map and recommendations for managing and operationalizing adoption.
Rachel Beard, Principal Security Architect for Salesforce, joins RevCult data security experts Pete Thurston and Brian Olearczyk to explore developments in the Health & Life Sciences space. Learn how organizations are currently thinking about securing sensitive data, whether it’s patient data or intellectual property and competitive insights. Companies are also navigating the transition of data storage from on-premises to the cloud, and rethinking their security posture, as a result. It’s at this point that the Shared Responsibility model is useful for understanding the native security controls that Salesforce offers and where InfoSec, Salesforce COEs, and Compliance teams need to step up and collaborate on how controls are configured and whether additional security products are needed. We also touch on best practices for managing regulatory compliance for HITRUST, GDPR, CCPA, and more. Rachel shares practical advice about who needs to be part of a company’s data governance team, and recommendations for who should lead the implementation and enforcement of data governance policy. During the live Q&A, Rachel fielded questions on Salesforce Shield vs out-of-the-box security controls and the importance of spending time on a thorough data classification exercise.
If you’re like most of our customers, you’re gaining tremendously more value out of Salesforce than the original “CRM” you implemented. Have your auditors kept pace with their understanding of Salesforce? What are the common controls that auditors are focusing on in your Salesforce instance? Special guest Cory Cowgill, CTO of Fusion Risk Management, Salesforce MVP and “Wall of Famer,” shares the brilliant basics on how to audit your Salesforce instance. Tune in now to learn which assets are essential in an audit process. Cory uncovers the key challenges auditors face when understanding your Salesforce data. Learn simple steps to create audit reports within your Salesforce instance. Get the exclusive on the most popular security controls that auditors use for their encryption tools. Discover the ultimate auditor’s guide to Salesforce – this is a can’t-miss episode!
Security in the Clouds’ veteran guest Jeff DiMuro from Salesforce joins us to discuss how to establish the proper data protection and data confidentiality techniques for your Salesforce instance. Learn how to ensure authentication credentials for applications and databases are sufficiently strong. Discover how to use event tools to trigger alerts for anomalous behavior.
Tune in to listen as Mike Mason of FairWarning, along with Brian Olearczyk and Pete Thurston of RevCult, discuss how to monitor for anomalous events, and documenting both current states and modified states of any changes to facilitate an error-free recovery. Discover the compensating controls that need to be in place to help ensure the security of your Salesforce platform. Learn how to protect against common threats such as misconfigured security settings, password policy change, and/or exfiltration of data.
Join us for a virtual fireside chat, it’s time for some Salesforce security & governance community-building! We explore how RevCult bridges the gap between data security and humanity. Tune in to hear how you can learn from our security experts how to align your Salesforce to your security posture. Hang out with us to get the tools you need to secure your Salesforce data and talk about Shield implementation best practices, tips on how to conduct a data risk assessment and key factors of change management for enabling a remote workforce – all coming to you from our home offices as we work remote, too!
Salesforce only has Sales and Marketing information, right? WRONG! Over the years, Salesforce has grown and evolved exponentially. Companies are leveraging Salesforce in many ways, adding even more sensitive customer data to the platform. While Salesforce is very secure, it’s still a platform that can be implemented in a way that puts your data at risk. So how do you know Salesforce is implemented in a way that meets your compliance needs? And how do you actually align your Salesforce implementation to your security posture? It all starts with data governance, the foundation for Salesforce security. Data governance provides the ability to effectively manage data using appropriate controls throughout the information lifecycle to meet various internal and external requirements. We’ll explain the basics and then dive into the more complex topics on how Salesforce, the lifecycle of customer data, and regulatory compliance can all effectively co-exist. Learn the nuances of Salesforce and what questions to ask your Salesforce team to ensure Salesforce is implemented in a way that aligns to your security posture! Listen NOW!
Does your company too quickly close the door on Salesforce governance questions and pretend it’s not relevant? If so, you won’t want to miss this cross-functional team of experts review how the world’s best in class organizations approach Salesforce governance. Tune in now to discover what you need to know about the Salesforce Shared Responsibility Model.
As Banks and Credit Unions look to realize greater return on investment from their digital transformation initiatives, the presence of a strong governance strategy is a leading indicator of success. Centers of Excellence are no longer an option; they are a critical component of goal-setting and execution within this highly-regulated market. During our session, you’ll hear how to align compliance, security and Salesforce Center of Excellence objectives. Discover how to define encryption, event monitoring, and reporting requirements.
Is Salesforce security and compliance a key resolution? If so and like all resolutions, it starts with an honest assessment of your current state to inform and prioritize the daily, weekly, and monthly steps to execute upon your resolution. Listen now to discover the key elements you should include in your Salesforce assessment. We’ll also discuss Salesforce Shield and how best to apply it in your Org. Based on the Risk Assessments we completed in 2019: 86% of all users have Read and Edit access to sensitive data.
Data Inventory is the first step to implement proper Data Governance for Salesforce. In part two of our podcast series with guest experts Jeff DiMuro, Chief Security & Compliance Architect at Salesforce and Marla Hay, Director of Product, Privacy & Data Governance we will explain step-by-step, how to conduct data inventory using best practices, standards and advanced tools. In this episode we’ll cover how to know what data is living in your Salesforce org. Also, we will discover how to set restrictions on how data can be used.
Do you know what data is living in your Salesforce? Listen Now!
Do you know what data you’re storing in Salesforce? Data Classification is the first step to ensuring Salesforce is aligned to your company’s Security Posture. Learn how to categorize and classify your Salesforce Data. Discover how to implement “principle of least privileged” best practices. RevCult and Jeff DiMuro Chief Security & Compliance Architect at Salesforce have partnered together to unravel the steps to take to accomplish the path to compliance.
Learn what to look for when assigning severity levels and identify who has access to sensitive information. Listen Now!
Roman Seleznev aka Track2 is known as one of the most prolific cyber-criminals for his role in a $50 million cyberfraud ring involving online identity and credit card theft.
Guest expert Mike Smith, Security Architect at Salesforce, tells this shocking story of Seleznev to illustrate key considerations businesses must take to protect their customer data from hackers, and common mistakes to avoid.
Learn how to take advantage of Salesforce’s security capabilities to make your customer data more secure. Listen Now!