Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why does a rapid shift to remote work…
Governance, Ownership & Risk

Why does a rapid shift to remote work increase the risk of unauthorised access and data theft in Salesforce?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

A rapid shift increases risk because long-standing office controls no longer fit the way users actually connect. Unsecured home networks, personal devices, and expanded access paths make it easier for attackers or insiders to steal data, alter records, or exploit overly broad permissions. When security changes move faster than governance, attack surface expands before controls can catch up.

Why remote work changes Salesforce access risk

When work moves out of a controlled office, Salesforce is no longer protected by the same network, device, and supervision assumptions. Users connect from mixed locations and devices, often through personal or poorly managed endpoints, so trust shifts from the office perimeter to the identity layer and the endpoint. That makes stolen sessions, weak home-network hygiene, and overbroad access more dangerous.

Salesforce is especially exposed to this change because it is a high-value business platform with broad data visibility, workflow automation, and integration dependencies. The main issue is not remote work alone, but the speed at which access patterns change before governance, device trust, and permission models are tightened to match the new operating reality.

In practice, the risk rises when controls that worked for office-based access are assumed to work unchanged for remote access. A user who can safely sign in from a corporate network and managed laptop may be materially less safe from a home connection, a shared device, or a browser session that is reused across services.

Why unauthorised access becomes easier

Unauthorised access usually increases when authentication trust is stretched beyond its original design. Remote users may rely more heavily on passwords, browser sessions, and single sign-on tokens, while attackers look for phishing, token theft, or account takeover opportunities. If conditional access and device posture checks are inconsistent, the platform may still grant access to a session that should have been challenged or blocked.

Expanded access paths also matter. Remote work often leads to temporary exceptions, broader roles, and faster onboarding of new tools so employees can keep working. Those shortcuts can create standing access that outlives the original need, and once permissions drift upward, an attacker only needs one compromised account or session to reach far more Salesforce data than intended.

This is where governance breaks down first: not at the login screen, but in entitlement design and access review discipline. If teams cannot quickly tell which users need which records, integrations, and administrative functions, remote access becomes a multiplier for privilege creep rather than a simple change in location.

Why data theft risk rises in Salesforce

Data theft risk rises because Salesforce concentrates customer, sales, support, and operational data in one place, and remote work expands the number of places that data can be viewed, copied, synced, or exported from. Personal devices, unmanaged browsers, local file downloads, and email forwarding all widen the paths by which sensitive records can leave the controlled environment.

Integrations and connected apps also become more sensitive during a remote shift. OAuth tokens, API keys, and third-party connectors can keep working even when the human user is away from the corporate network, which means a compromise may not look like a classic interactive login. If a token is stolen, the attacker can bypass the normal user experience and go straight to data retrieval, record modification, or workflow abuse.

Salesforce exports, reports, and automation outputs are another common leakage point. Remote users often move data into spreadsheets, collaboration tools, or local notes to get work done, and that creates more copies to lose, share, or exfiltrate. The practical result is that the data theft path becomes less direct, but easier to sustain and harder to detect.

What changes when governance lags behind remote access

The biggest failure mode is not a single technical weakness, but a mismatch between access speed and control speed. If the business expands remote access faster than it updates device trust, role design, session monitoring, and offboarding discipline, the environment accumulates blind spots. Attackers benefit from exactly that lag because they need only one weak identity path to reach sensitive Salesforce records.

Remote work also increases the chance that exceptions become permanent. Emergency access, temporary integrations, and “just for now” permission grants can remain in place long after the operational need has passed. In Salesforce, that can leave admins, sales users, or service teams with access paths that are broader than their actual job function, creating both insider-risk and external compromise exposure.

For teams that manage Salesforce at scale, the real question is whether access remains bounded, attributable, and reviewable after the operating model changes. If the answer depends on informal trust rather than enforced policy, the platform is already carrying avoidable exposure.

Risk and Threat Considerations

Remote work increases the chance that attackers can exploit weaker endpoints, weak home-network hygiene, and relaxed access controls to reach Salesforce sessions or tokens. Once inside, they can move from account compromise to record access, data export, or permission abuse without needing to defeat Salesforce itself.

Failure mechanism: The control failure is usually a combination of token theft, weak device assurance, excessive privilege, and stale exceptions that persist after the organisation changes how people work.

Impact: The impact can include customer-data exposure, fraudulent record changes, misuse of connected apps, and a wider blast radius because Salesforce often aggregates sensitive business data and workflow access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageSalesforce tokens and connected-app secrets can be stolen during remote access.
NHI-05 — Overprivileged NHIRemote integrations and tokens often retain broader access than needed.
NHI-07 — Long-Lived SecretsPersistent tokens and sessions increase remote compromise persistence in Salesforce.
Recommendation — Rotate and protect Salesforce-connected secrets to reduce token theft exposure. Reduce connected-app and token privileges to the minimum required scope. Shorten token lifetimes and remove standing credentials where possible.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementRemote Salesforce access depends on secure management of passwords, tokens, and secrets.
AC-6 — Least PrivilegeOverbroad Salesforce roles and remote exceptions expand unauthorized access risk.
IA-2 — Identification and Authentication (Organizational Users)Remote users need strong identity proofing and authentication before Salesforce access.
Recommendation — Manage and rotate authenticators used for Salesforce access. Constrain Salesforce permissions to the minimum necessary access. Require strong authentication for organizational Salesforce users.
ISO/IEC 27001:2022A.5.15 — Access controlRemote Salesforce access hinges on access rules that fit the changed operating model.
A.8.5 — Secure authenticationStolen sessions and weak sign-in controls are central to remote Salesforce compromise.
Recommendation — Review and enforce Salesforce access rules for remote users. Strengthen authentication controls for Salesforce sign-in paths.
CIS Controls v8CIS-6 — Access Control ManagementRemote work widens access paths that CIS access control safeguards are meant to constrain.
Recommendation — Enforce least-privilege access and remove unnecessary Salesforce entitlements.

Practitioner Guidance

What to verify: Confirm that remote Salesforce access is tied to device trust, strong authentication, and current entitlement review, not just successful sign-in. If a user can authenticate from any device and still reach high-value records, the control is too permissive for a rapid remote-work model.

What practitioners underestimate: The hidden risk is often session and token persistence, not the initial login. Review connected apps, long-lived sessions, export privileges, and admin exceptions together, because that is where remote work most often turns convenience into data loss.

Practitioner takeaway: Treat remote work as an access-model change, not a location change. If Salesforce permissions, device trust, and token governance were designed for office-bound users, they need revalidation before the new operating model becomes the new attack surface.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org