A serious security incident has come to light: hackers have reportedly stolen data from more than 200 companies by exploiting a connection via Gainsight to their Salesforce environments.
For CFOs and finance leaders, this breach isn’t just a technical problem. It’s a business risk. Sensitive financial and customer data housed in Salesforce could be exposed via third-party integrations, undermining both trust and compliance.
Here’s what you need to understand and how Swan Technology Solutions can help you harden your org through encryption.
What Happened: A Supply-Chain Attack via Gainsight
- Salesforce issued an advisory after detecting “unusual activity involving Gainsight-published applications” that were accessing customer orgs.
- According to Google’s threat intelligence team, over 200 Salesforce instances may have been compromised.
- The hack appears to be related to the external connection (Gainsight apps), not a vulnerability in Salesforce’s core platform.
- In response, Salesforce revoked all active access and refresh tokens for these Gainsight-connected applications.
This kind of attack reflects a growing trend: threat actors are targeting third-party integrations (like customer-success apps) rather than Salesforce itself.
Why This Matters to CFOs
- Data Risk Is Business Risk
As CFO, your org likely stores sensitive financial, customer, or transactional data in Salesforce. A breach not only risks regulatory non-compliance, but also reputational damage. - Supply-Chain Vulnerability
Even if your Salesforce implementation is solid, insecure third-party apps can be the weak link. The Gainsight incident shows that attackers might exploit OAuth tokens or API access. - Control Over Your Data
This kind of breach underlines the importance of encrypting data at rest. Encryption can prevent or limit damage even if unauthorized access is obtained.
Encryption as a Defensive Strategy: What Salesforce Offers
Salesforce provides Shield Platform Encryption, a powerful way to protect data at rest. Here are the key types and what they protect:
- Field-Level Encryption: Encrypts individual fields on objects (standard/custom).
- Database Encryption: Covers a broader set of data, potentially including entire data volumes.
- Other Elements: Files, attachments, search index data, event logs, and more can also be encrypted
Shield also supports Bring Your Own Key (BYOK), meaning you can manage your own encryption keys. A big plus for financial leaders who want control over key lifecycle, rotation, and storage.
Trade-offs and Considerations
Encryption is powerful, but it’s not “set and forget.” There are important trade-offs CFOs and technical leaders must be aware of:
- Functional Limitations: Encrypted fields may have reduced functionality, for example, not all SOQL filters or sorting options work when fields are encrypted.
- Flow & Automation Impact: Encrypting data can affect how Flows work. For instance, certain flow orchestration input fields (like in Work Item objects) might need specific encryption settings.
- Key Management: You need a strategy to rotate, back up, and possibly destroy encryption keys securely. Mismanagement of keys can lead to data loss.
- Performance & Deployment: Enabling encryption requires careful planning. Salesforce’s encryption setup must be validated, especially in sandbox environments, before rolling out to production.
How Swan Can Help?
At Swan Technology Solutions, we specialise in helping finance and operations leaders secure their Salesforce orgs with best-practice encryption strategies. Here’s what we offer:
- Encryption Strategy & Planning
- We assess which objects and fields are most sensitive (e.g., financial, customer PII, payment data)
- We help define an encryption policy aligned with business risk and compliance needs
- Implementation of Shield Platform Encryption
- Configure deterministic vs probabilistic encryption where appropriate
- Encrypt not just fields, but files, attachments, and other data artefacts
- Set up BYOK if you want to manage your own keys
- Testing & Validation
- Evaluate how encryption affects your existing automations (Flows, Triggers, Reports, Integrations)
- Validate compatibility with managed packages and third-party tools
- Key Lifecycle Management
- Establish key rotation policies
- Securely store, back up, and manage keys
- Provide training and processes to ensure only authorised users can access key material
- Ongoing Monitoring & Support
- Use Shield’s Platform Encryption Analyzer (via the Shield Extension) to monitor encrypted fields. (Salesforce)
- Provide continuous security reviews as your org evolves
The Gainsight-Salesforce breach is a stark reminder: even well-architected Salesforce orgs can be compromised through external apps. For CFOs, this is a call to action. Protecting data isn’t just about access control but deeply embedding encryption into your Salesforce architecture.
Swan is ready to help. If you’d like a security review of your Salesforce org, especially from an encryption perspective, let’s talk
