Salesforce iconSalesforceSep 14, 2026 ~7 min source read

Introducing Security Mesh: Unify Your Security Data for Greater Visibility

Salesforce’s Security Mesh centralizes and normalizes security signals across Salesforce and external sources so admins and security teams can detect multi-system threats with consistent, queryable data.

Introducing Security Mesh: Unify Your Security Data for Greater Visibility

Share this story

Send the public story page.

Useful takeaways from this story.

Security Mesh connects internal Salesforce signals and external security feeds, bringing them into a single model using the OCSF standard.

Normalized attributes (Username, IP, Last Login, Location, Role) make cross-source detections queryable and support detections like Impossible Travel and Data Exfiltration.

Security Mesh is delivered inside Security Center, requires Data 360, and ships with GA connectors for Real-Time Event Monitoring, Okta ISPM, CrowdStrike, and DigitSec.

# Mesh is and the problem it solves Security teams collect a lot of signals, but those signals often live in separate tools and formats. When activity spans multiple systems—an identity compromise that touches Salesforce and an external identity provider or an endpoint alert followed by bulk data exports—teams struggle to connect the dots. Security Mesh is a Salesforce-native solution designed to unify disparate security data so teams can see a clearer, actionable picture of risk.

# Mesh works Security Mesh approaches the problem in two concrete steps:

  • Map incoming signals to a single schema using the Open Cybersecurity Schema Framework (OCSF). Normalized fields include Username, IP Address, Last Login, Location, and Role regardless of original source. The result is a simple, queryable data model that removes format friction when correlating events.

# Detections you can build today With correlated, normalized data, Security Mesh enables detections that combine signals across domains. Salesforce lists ready patterns you can use or adapt:

  • Data Exfiltration: Spot a pattern where an anomalous authentication (new location or odd hours) is followed by bulk API calls or large report exports exceeding the user's baseline.
  • Active Sessions During Endpoint Compromise: Combine endpoint compromise indicators with active, high-activity Salesforce sessions and then use Real-Time Event Monitoring to inspect exactly what happened while the session was active.

# Availability and integration details Security Mesh is available as part of Security Center and requires Data 360. The initial Generally Available (GA) data sources include:

  • Real-Time Event Monitoring (Salesforce internal telemetry)
  • Okta ISPM user data
  • CrowdStrike endpoint security data
  • DigitSec code and pipeline scanning data

Those GA connectors mean you can start unifying identity, endpoint, and developer pipeline signals with Salesforce event data immediately, provided you have the required products enabled.

# Why normalization matters in practice Normalization reduces the time and errors involved in correlating events across tools. Instead of building per-tool parsers and mapping logic, teams query a single model for attributes like IP and username. That lowers the barrier to creating custom detections and speeds incident investigations because the relevant attributes are aligned across sources.

# Practical next steps for teams

  • Verify you have Security Center and Data 360 in your Salesforce estate.
  • Enable Real-Time Event Monitoring and connect GA external sources (Okta ISPM, CrowdStrike, DigitSec) as needed.
  • Start with out-of-the-box detections such as Impossible Travel, then create tailored detections that reflect your organization's normal baselines and sensitive data patterns.

# Short conclusion Security Mesh centralizes and standardizes security telemetry into a single model inside Salesforce, making cross-system detections and investigations faster and more reliable. The initial GA connectors focus on identity, endpoint, and developer pipeline signals plus Salesforce's own event data, giving teams immediate building blocks for multi-source threat detection.

More context around this story.

Introducing the Frontier AI Security Readiness Program
Vmware iconVmwareAug 31, 2026

Introducing the Frontier AI Security Readiness Program

<div><img width="300" height="170" src="https://blogs.vmware.com/wp-content/uploads/2026/08/Shield.jpg" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/08/Shield.jpg

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app