Salesforce Security Best Practices 2026: The 12-Point Checklist
Digital Stratify Team
August 4, 2026
6 min read

Salesforce Security Best Practices 2026: The 12-Point Checklist

Salesforce is not insecure, but it becomes insecure the moment a busy admin skips one of these twelve controls. Here is the 2026 checklist we run on every audit.

Salesforce is not insecure by design, it becomes insecure the moment a busy admin skips one of these twelve controls. Every incident we investigate maps back to one or two items missed on this list. Here is the 2026 security checklist we run on every audit, in priority order.

The 12-Point Checklist

  1. MFA enforced for all interactive users. No exemptions "for now."
  2. Session settings hardened. 2-hour timeout max (30 minutes in regulated industries), lock to IP, force logout.
  3. Login IP ranges defined per profile, even the CFO does not log in from Moldova.
  4. Health Check score above 85. See our Health Check guide.
  5. Connected Apps audited, scopes, owners, usage. See our Connected Apps guide.
  6. Profiles reviewed quarterly. Nobody keeps "Modify All Data" past their onboarding week without justification.
  7. Field Audit Trail or Field History Tracking on personal-data fields.
  8. Sandbox anonymization for anything with real customer data. See our anonymization guide.
  9. Sharing rules audited. Public Groups and Manual Shares tend to accumulate, quarterly cleanup.
  10. Public Sites and Experience Cloud pages audited, no unintended object exposure.
  11. Backup + tested restore. A backup you have not tested is a hope, not a plan.
  12. Documented incident response. Who does what when the incident is real? Answer this before the incident.

The Three Silent Killers

  • Shared user accounts for integrations, creates a credential blast radius when compromised.
  • Trusted URLs for Cross-Site Scripting misconfigured for legacy apps that no longer exist.
  • Metadata API access granted to third-party tools with over-broad scopes.

What Shield Actually Adds

Salesforce Shield is the paid security bundle: Platform Encryption, Event Monitoring, Field Audit Trail. Worth the price if you have regulated data (health, finance, government) or if compliance requires SIEM-grade event streaming. Not necessary for every org.

Frequency of Checks

  • Weekly: Health Check score, failed logins, MFA compliance.
  • Monthly: Connected App usage, Chatter for suspicious activity, Public Site changes.
  • Quarterly: Full profile audit, sharing rules, external orgs, backup restore test.
  • Annually: Full penetration test on custom code and Experience Cloud.

Regional Notes

  • EU (France, Germany, Belgium, Luxembourg, Switzerland): GDPR fines up to 4% of global revenue focus mind. See our GDPR guide.
  • US & Canada: SOC 2, HIPAA, state-level (CPRA, Colorado) and Quebec Law 25 all overlap with this checklist. See US, Canada.

Frequently Asked Questions

Is Salesforce PCI-DSS compliant?

Salesforce itself is compliant as a processor. Your org is compliant only if you configure it correctly and never store PANs.

Do we need Shield to pass an audit?

Not always. Standard Salesforce plus rigorous configuration passes many audits. Shield helps when SIEM or extended audit is required.

How often should we test our backup?

Full restore test at least once a year, sampling monthly.

What is the single biggest gap in most orgs?

Connected Apps with over-broad scopes and no owner. Every quarter finds one.

Get a Fixed-Fee Security Audit

Our Salesforce audit runs the 12-point checklist plus a prioritized fix list in 2 weeks. Book a 30-minute call.

If this sounds like your CRM, let's look at it together.

Thirty minutes, no deck, no pitch. You leave with a diagnosis either way.