Summary
While there are many techniques that you can use to protect your users and insulate your data from attacks, the final and most important thing you can do to protect your sites and your Salesforce instance is to test, test, and test some more. If you can automate your regression testing or leverage tools that examine downstream impacts that might compromise your site’s security, do it. Often, releases will focus on a specific feature add or element of your site and neglect to check it against existing architecture – therefore, it is on you to ensure that your applications are behaving as expected.
Additionally, keep track of software updates as they come out – and not just ones from Salesforce if you’re calling third parties. Keep your eyes open for data leaks, novel technology, or new attacks you might need to protect against. Since hackers are getting cleverer and most “hacking” is social engineering, teaching your users to be mindful...