Today on the Salesforce Admins Podcast, we talk to Sabrina Simeroth, Product Manager on the Salesforce Security Product Team. Join us as we chat about the new Security Center Essentials feature and how to work security reviews into the rhythm of your organization.
You should subscribe for the full episode, but here are a few takeaways from our conversation with Sabrina Simeroth.
What is Security Center Essentials?
The last time we had Sabrina on the pod, we were talking about Health Check scores. However, as she explains, that number is meant to be an assessment of your organization’s security Configurables at a single point in time. But what about continuous monitoring?
That’s where Security Center Essentials comes in. “With Essentials, we’re trying to give a broader and more ongoing visibility,” Sabrina explains, with a focused set of security metrics you can monitor over time. It makes it easy to see things like what managed packages are supported, which third-party platforms have access to your data, and who in your organization made changes.
In other words, Security Center Essentials gives you a map for how your org is structured, making it easier to spot potential problems and make sure your security and governance are aligned with your business goals.
Two questions to ask for security reviews
So how do you get started with Security Center Essentials? For Sabrina, it’s all about context. Once you’ve run Health Check and dialed in your security settings and policies, you want to use the metrics on Security Center Essentials to get context for how things work in your organization.
From there, Sabrina recommends asking yourself two key questions:
- What should be in my environment?
- Who owns this managed package?
- Who installed it?
- Who is using it?
- What has changed most recently?
- Were you expecting it?
- Who did it?
- How does it affect your business processes?
Sabrina recommends establishing a monitoring cadence around regular business process milestones. If something is updated every Tuesday, check before and after to make sure everything happened as expected. As an admin, you have the best operational context to flag potential problems and bring them to your security and governance team.
Why you shouldn’t chase a perfect Health Check score
While your Health Check score is helpful for giving you a general understanding of how your security standards compare to industry best practices, Sabrina urges you not to chase a perfect score.
“Your Health Check score should begin a security review, rather than ending a review,” she explains. It’s there to flag areas of your org that need a closer look, so you can make decisions about how much intentional risk your business needs to carry. The most dangerous security threats are the ones you don’t know about. It’s OK not to have a perfect Health Check score, as long as you know why you’re doing it.
Make sure to listen to my full conversation with Sabrina about how to use Security Center Essentials and Health Check. And don’t forget to subscribe to the Salesforce Admins Podcast so you never miss an episode.
Podcast swag
Learn more
Admin Trailblazers Group
Social
Full show transcript
Mike:
Security is one of those things where it’s really easy to look at a score and think, “Great. I’m done.” But your Salesforce org doesn’t sit still and neither does your security posture. Today I’m talking with Sabrina Simeroth from the Salesforce Security product team about Security Center Essentials and how admins can use it to understand what’s connected to their org, what’s changed, and what deserves a closer look. We talk about why getting a perfect Health Check score isn’t necessarily the goal and how to work security reviews into the rhythms of your organization. So if you’ve ever opened up a security dashboard and wondered, “Okay, what am I actually supposed to pay attention to?” This episode is for you. Let’s get Sabrina on the podcast. So Sabrina, welcome to the podcast.
Sabrina Simeroth:
Thank you. Thank you so much for having me back.
Mike:
Well, it’s worth talking about because security is always top of mind for Salesforce admins. And the last time I had you and Laura on, we were talking about Security Center Essentials. And I think if memory serves me right, people now have that available to them and admins can start getting in touch with it, right?
Sabrina Simeroth:
Yeah. Absolutely. So that has been launched and it is fully rolled out. They should be able to see that in production orgs and some sandbox orgs as well.
Mike:
Sweet. So you’re integral part of security at Salesforce and you do a lot. Refresh my memory, what’s your domain and what do you handle at Salesforce?
Sabrina Simeroth:
Yeah, absolutely. So I sit on the product management team. I support our security center product and that also incorporates the Essentials product that we just launched and some of our other free tools like Health Check in setup. And then I actually work really closely with a few other PMs that support other features of the premium products like our agentic features and work really closely with the Shield team as well.
Mike:
Shield.
Sabrina Simeroth:
Yes.
Mike:
Yes.
Sabrina Simeroth:
All security, all the time.
Mike:
Our secret MCU product. So let’s talk about Security Center Essentials and actually Health Check. I’d love to know, and probably admins too, we love when we get these features, but what exactly were you trying to solve with Health Check?
Sabrina Simeroth:
Yeah. So Health Check is a really valuable … I would call it a point in time assessment of some of the critical settings that we find in setup. These are your security configurations. Oftentimes if you’ve been to any events, you hear them called configurables. So these are settings like your password policies, your session settings, some of those toggles that you can turn on and off. But with the Essentials, we’re trying to give a broader and more ongoing visibility. So it’s not just a point in time, this is something that extends that capability. Health Check is still really valuable and it is a collection of these configurations that are set against a baseline or a set of standards so that you can see where your posture is at at any given time. But we really wanted to extend that and allow admins the ability to see how changes in their system, how changes in their configuration occur over time, as well as broaden the view of what they’re actually looking at. So not just those toggles.
Mike:
I always liked Health Check was like right now, here’s where you’re at with links to open things. So that makes sense. It’s making the dashboard a little bit bigger. I think for a Salesforce admin who just opens Security Center Essentials for the first time and they have a whole bunch of different metrics looking back at them, where should they focus? I think of a car dashboard. Well, if I start my car and the fuel light comes on, probably the most important thing to pay attention to. But as an admin, depending on the level of security awareness that I have, I may not know what number is the most important number. So help me walk through those different metrics that they’re seeing.
Sabrina Simeroth:
Yeah. You are so spot on. So I think there’s a tendency to want to stack rank, which is the most important thing to look at. If I could put it very simply, so we started with a very narrow scope of, let’s call it metrics. So we wanted to extend the capabilities of Health Check. We wanted to give a broader view and give admins access to what does the actual state of your org look like? What are the things that are connected to your org? What are the managed packages that are being supported? Where are your access points? Those types of things. These are all really critical things for admins to be aware of because it’s basically how is your org structured? So I think that that’s the key. It’s not that you should focus on or stack rank immediately any one metric in Essentials. It’s more around let’s figure out what our baseline is and what is the actual standard for our environment. So I would resist saying one over the other. Obviously, I think the tendency is to lean towards let me look at the thing that has a score. Let me look at Health Check. I would actually say, ask yourself two questions as an admin. What looks unfamiliar to me? So look at the seven metrics. And I apologize in advance because come Dreamforce, we’re extending that seven metrics to 14 metrics, but we’re still keeping the scope very narrow.
Mike:
It’s no like Salesforce to just double anything, right?
Sabrina Simeroth:
No. Not at all. But we’re trying to bring the most critical things for you to pay attention to the forefront and just keep it narrow so that you have a really, really solid idea of what should be in my environment and then what has changed most recently. Those are the two things to be really looking at so that you can start asking yourself questions. Does this actually make sense? Should it be here? Is there an assigned owner? These are the types of questions. It’s really about laying out a map for the admin to start getting the right context about how the org is configured and then start evaluating is this good or bad and does it align with the business needs? So that would be my advice using essentials.
Mike:
Yeah. No. It makes sense. And I think you pointed out that what’s really nice is you’re not just seeing today’s configuration, you’re seeing how things changed and that if you’re a Salesforce admin, whether you’re just getting started in a new org, you can watch that progression. Or if you’re coming to a fresh org, if you just got hired, that was always, and I still think is top of mind for a lot of admins. “Hey, when I parachute into a new company, what do I do to look at an org that I’m inheriting?” And so I think let’s apply security center essentials to that and say, “If I inherited an org tomorrow, how could I use that to see how things are changed or understand a little bit more about the org that I’m working in?”
Sabrina Simeroth:
Yeah. That’s a great question. So if we look at the metrics that are included in Essentials, it’s things like what types of packages do I have installed? What type of connected apps? So how is data interacting with third party packages? How is data interacting? And the great thing about these metrics is we’re giving you visibility into who actually installed these packages? So is that normal? It’s that type of context. First take inventory, see what’s connected into your apps, see what IP ranges you have associated with your different profiles. What are your trusted IP ranges? Take a look at your security configurations through the Health Checkout. Are you using any baselines that were already set up? So if this is a new org did somebody already have a baseline, have they already done a security review? Check those things first and then start establishing your context.
So the metrics do a really great job of showing you who may have been the owner of those, who may have installed or made specific changes at any given time. So use that as your starting point and start to do your own investigation, building context around which teams are using this? Who is the true owner at this point? Does this make sense? Is it still actively being used? That context is going to be really helpful when you start to get into the monitoring piece, which is when changes are made, then an admin can more easily flag like, that doesn’t align with what I’m expecting. Does that make sense?
Mike:
Oh, absolutely. That whole connected apps and packages part is … If you’re working with people in a larger team or … Boy, I got to tell you, I’ve done this accidentally where you set up a user and you forgot to deny them access to install packages.
Sabrina Simeroth:
Oh yeah. Just delete access.
Mike:
And I remember I had this power user. I found this whole app exchange and we can download apps. And my face just went white. Because I was like, “But you couldn’t do that, right?” And they’re like, “Oh no, I did totally.” “Oh, well, you’re not going to be able to after I finish my salad.”
Sabrina Simeroth:
Yeah. And that’s so true. It’s very hard when things are scattered all over the place to maintain that. It is a very complex platform for a reason. It provides so much flexibility to the users to really align with business. The challenge then becomes like, okay, how do you make sense of that to make sure that you’re doing the right things as it relates to security? And so that’s the whole goal. It’s let’s bring some of those key elements so that you can quickly identify where those changes, those missteps, they always happen. They’re not going to be able to be avoided. But how quickly can you evaluate and then shift and make changes to address any gaps or concerns or what we consider gaps in your posture?
Mike:
Right. Right. One thing that I loved about Health Check was it gave me a score and admins love score, got to get perfect score on everything. The idea of making it to a hundred on Health Check being perfect as a goal, is that really a goal or how should admins think about that number?
Sabrina Simeroth:
That is such a good question, and this is so common. So I was a part of the Own acquisition. I’ve been working with Salesforce security products for the past 10 years. And in that previous role, I actually helped customers implement their security programs and implement their security tooling. And we would get this all the time, customers just really wanting to reach 100. There is this-
Mike:
I want to be perfect. Come on Sabrina.
Sabrina Simeroth:
Strive for perfection. It’s so common. And when it comes to risk scoring, the desire is always to reach perfection. Here’s how I would look at it. A higher score is a very useful signal. A low score is a very useful signal, but 100, I would say, should not become like a trophy or the end goal without very valuable context. So context really matters. So Health Check compares settings with a standard baseline, but every organization can have very legitimate reasons for different settings or the need to actually carry some risk in their system in order to be able to operate the business. So not every setting makes sense for every customer. So the score should really begin a review rather than ending a review. It really needs to be treated more of … We were talking about the car. It’s more of a gauge. It’s not like a report card that tells you you’re good or bad. It is telling you where to look so that you can actually evaluate and get the right context to say, does it make sense for our business to actually secure this or remove this or lock this down, restrict this? Because there will be some legitimate reasons why you don’t want to align with that.
There will be impacts to the system or things that are restricted from users that need access to sensitive data in order to do their job. That is acceptable risk if it’s well documented, if it’s intentional, if it makes sense for the organization. So a hundred I would say is not the goal. You can always reset a baseline in-house check so that it makes sense so that you can reach that 100 state. But I would definitely use it more as a signal to review what’s going on and to provide awareness of your configurations rather than the end goal. And don’t ever think like I’ve reached a hundred, I’m perfect, I’m going home and I’m never looking at this again. A system is always changing, it’s always evolving. And so a regular review is really critical. So that would be my advice there as it relates to a score.
Mike:
Yeah. Well, I got to ask, often admins will have governance. They’ll hold monthly governance meetings or quarterly. You can refresh Security Center Essentials a lot. What is the pattern that you would suggest admins do a data refresh on that? And then part two of that, because I’ll just make the question harder, how would they work that into a governance meeting?
Sabrina Simeroth:
Oh gosh. So now see, you’re putting me in a corner because I always give a soft answer on this one, but let me try to be really practical because I want our customers to really have a clear idea of how to manage this. The cadence that we’ve set for in the background running these metrics is once a week. So use that as the baseline. Once a week gives you plenty of time to see actual changes in the environment, but that’s not to say that you shouldn’t do these manual refreshes so you can manually update these and do more targeted. What I would say is avoid just every hour, update, update, update. That’s excessive. And if it doesn’t align with your actual business cadences. So it’s going to be different for every customer, but try to align it with known milestones or known practices. So these are things like your development life cycle. When are your planned releases? When do you traditionally install new packages? Are there large onboarding events? Do you have regularly scheduled security reviews? And this is why it’s a fuzzy answer where it’s like it’s going to be different for every customer.
But as an admin, if you know that you also have an internal regular cadence … Maybe you’re doing a security review at the first of the week every week, maybe then you do deployments on Thursday every week. I would actually align the update cadence to those known activities because then you have context. It’s a starting point where you say, “This was an expected activity and here’s the changes that I saw.” I also saw changes outside of that activity. And so that’s a really good point when you talk about bringing it into a governance meeting.
When you are speaking with security folks, when you’re speaking with compliance folks, it’s incredible context to be able to say, “Hey, I was expecting this activity. I was not expecting anything on this date. Is there anything in your world that would indicate that this is actually an appropriate action that was taken? Should we investigate this further?” And that’s a really clear starting point given the context of I’m an admin, I have a lot of the operational context of how we’re operating our business and here’s that context. And this from my perspective sits outside. It’s a little bit anomalous to what we would expect in terms of our own personal cadences. So I can’t tell you it should be every day, it should be every five hours. That’s really challenging. But it should try to align with some known milestones, some known events that you have going on in the business.
Mike:
That makes sense. You don’t want to refresh it every day if once a month you make your changes and you’re getting the same number day after day like, okay, well obviously it’s expected.
Sabrina Simeroth:
Right. And then you become numb to it a little bit. You’re just like, yeah, okay.
Mike:
You do. And then a number of changes, you’re like, wait a minute, should that have been up or down? And you forget. So I get that. Let’s talk about Security Center as a whole, because Essentials is the starting point. And I think for a lot of the admin work that I’ve done, it sounds like it more than fills the bill. But Security Center, you’ve got multi-org, you’ve got advanced capabilities. At what point would an admin look at Security Center Essentials and say, “Not enough. We need more.”
Sabrina Simeroth:
Yeah. Yeah. It’s a great question. I think everybody leans towards it’s when it’s multi-org. I think that’s the default. Everybody says, “Okay, well the premium products, that’s for multi-org, that’s for these massive organizations.” I would avoid thinking that way. For me, it’s more around, let’s call it organizational or operational complexity, and this can mean many things. So if you are starting to have more frequent changes like adding users, your company is growing drastically and you have a lot more users that are needing access to things, the hierarchy is changing. You’re having a little bit more complex structure where there’s management teams and then there’s people under there. Regionally, you’re expanding. If you are adding a lot of applications, you are doing a lot of customization within the environments. You are incorporating more custom code or more custom applications that are third party. Anytime that the system becomes slightly more complex, that is when I would think that it is very critical to evaluate the full product where you’re going to get that more advanced management, advanced monitoring, broader security controls that are in the purview.
So I would base it more on when you start to feel like your org is maturing enough to a point where there is enough complexity, the full product is where you’re going to see a lot of value. And it’s not just about how many orgs you’re managing because sandboxes are important to manage security in as well because that’s the feeding point into your production orgs, but it’s about the data that you’re looking at, how complex are your regulations becoming in your industry, what are the standards, what are the types of controls that you actually need to manage now as an admin? And I think basing it off of that gut feeling of this is becoming more complex, that’s when it’s a good time to start evaluating the tool.
Mike:
It’s almost like when you need more information behind the warning light.
Sabrina Simeroth:
Exactly. Exactly.
Mike:
We’re running out of gas, but how much do we really have?
Sabrina Simeroth:
Yes.
Mike:
Can’t go another 10 miles.
Sabrina Simeroth:
When you start to feel like security is your only focus, that is a really good time to start looking at the automation for the premium features.
Mike:
Absolutely. So I think thinking about that, I always love giving admins something very practical to do. And I think connecting with … Depending on the size org that they have, it could be a security officer, it could be a person in IT. If they were to sit down with somebody at their organization and show them Security Center Essentials, in your mind, who should that person be and what should they point out to them?
Sabrina Simeroth:
Yeah. So every organization’s going to be different. Some people do have a dedicated security team. Some of them just have a center of excellence that ensures all things related to administration and security for an environment. I would say one, if you have someone who owns internal InfoSec policies. So whether that is your compliance policies, your data governance policies, any InfoSec team, I would build a relationship with one of those connections because they’re going to have context that you need in terms of what are the right policies that we need to be aligning with, but that will be a really critical relationship. If there is just a platform owner for your team, that’s what I would say. The admin needs to work with a platform owner and just really establish themselves like, “Here is where we’re at with the system. Does this align with your expectations? Is this where we want to head? And is there anything that you want me to focus on?” So I would say those.
If there isn’t a dedicated security setup in your organization, then definitely whoever is the platform owner you want to connect with. Otherwise, a security personnel building a relationship with one person in security who really understands from a business perspective what the security concerns are, that would be the right relationship to say, “And here for this system, this is what we have in terms of our security controls and configurations.”
Mike:
Yeah. I remember how humbling it is sometimes to sit down and show them dashboards, be like, “Look at all we have.” And they’re like, “But what about …” And you’re like, “Let me get back to you on that.” That’s a really good question. And inevitably, you always learn and there’s always one more thing to pay attention to.
Sabrina Simeroth:
Absolutely. So that’s a great point. What I would love for our admins to know as well is we’re learning right along with you. So we are making decisions about what we feel admins should be paying attention to, but if there’s feedback, feedback is such a gift. That’s what we always say at Salesforce, feedback is a gift. So if there are really large gaps or there are really problems that you are trying to solve where the tool doesn’t quite hit the mark, please let us know. Send it in to your account reps, send it in to your connections at Salesforce and feed it back to the product team because we would love to start seeing how our admins are using our security tools and really becoming security professionals for their companies. And we do take that feedback to heart and we are trying to incorporate what our customers truly need.
Mike:
When this episode airs, it’ll be 11 days, hard to believe, until Dreamforce. But you said that there’s new stuff coming.
Sabrina Simeroth:
Yes.
Mike:
Without spilling all of the news, can you give us a preview of what admins can expect?
Sabrina Simeroth:
Yeah. Absolutely.
Mike:
We’ll say later in September. How’s that?
Sabrina Simeroth:
Yeah. Yeah. Yeah. So it should actually be able to be demoed at Dreamforce, and we will even actually have some additional materials. So we’re working on a quick look in Trailhead for Essential specifically. But we mentioned this, I think, on our last episode as well, but we are going to be introducing a few of those critical user permissions that are going to now be a part of the required MFA enforcement and the increased restrictions on who actually requires tighter controls as a user. So those permission metrics will actually give really good insight on who are your highly privileged users in this environment? Who do you need to really focus on in terms of making sure that they have the right level of access to the right data and that there’s the right controls in place, that their user credentials are protected?
Mike:
Wow. This is neat. This is so cool. This is all the stuff that I wish I had a hundred years ago when I was an admin just clicking around like, “I wish I could run this report now.” Now, not only do you get the report, but you probably have set up with Agentforce that can help you re-permission somebody. It’s an exciting time. Sabrina, thanks for coming back on the podcast and helping us out.
Sabrina Simeroth:
Of course. It was my pleasure. Thank you for having me.
Mike:
Thanks again to Sabrina for joining us. My big takeaway is that security isn’t about choosing a perfect score, it’s about knowing what normal looks like in your org so you can spot it when something just doesn’t fit. Take a look at the Security Center Essentials, establish that baseline, and then bring what you find into the conversations you’re already having about releases, governance, and access. And until next time, we’ll see you in the cloud.