InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

Revisiting CIA: Developing Your Security Strategy in the SaaS Shared Reality

Presented by

Matthew O'Neill, Field CTO, Salesforce

About this talk

While traditional Infosec focuses on infrastructure responsibility, SaaS introduces a shared security model. The platform provider (like Salesforce) secures the apartment building and shared utilities, but the customer controls who has the 'front door key' and what happens inside—meaning they own the data and access controls. This is critical for availability and integrity. Standard Recovery Time Objective (RTO) and Recovery Point Objective (RPO) metrics don't capture the customer's burden of granular data recovery (e.g., fixing a single field value across millions of records). More importantly, in interconnected SaaS ecosystems, rolling back a flawed change is insufficient. As demonstrated by scenarios like manufacturing errors, the integrity of downstream processes is lost. Therefore, senior security leaders must embrace a remediate-to-fail-forward strategy instead of relying on traditional failure mitigation. Join this session to: • Understand why traditional RTO and RPO are insufficient for SaaS data resilience and learn practical steps needed to bridge the gap between platform-level uptime and application-level data integrity • Learn why rolling back changes in SaaS often makes things worse and how adopting a “fail-forward” approach ensures faster recovery and preserves data integrity across interconnected systems Gain clarity on where SaaS provider responsibility ends and your ownership begins, plus practical steps for managing access, user provisioning, and data backup to strengthen compliance and reduce risk
Infosecurity Magazine

Infosecurity Magazine

45907 subscribers704 talks
Strategy - Insight - Technology
Dedicated to serving the information security community, in person, in print and online.

Related topics