Picture a mid-market B2B team that spent the better part of 2025 rolling out AI-powered automations across their sales pipeline – lead scoring, deal prioritisation, automated follow-ups. Velocity went up. So did their attack surface. According to a report published last week by Help Net Security, Salesforce and ServiceNow customer portals were left exposed for 17 months before the vulnerability was identified and addressed. Seventeen months. That’s long enough for most sales teams to run two full annual planning cycles without ever knowing their CRM data was accessible.
This isn’t a reason to slow down AI adoption. It is a reason to think harder about where the real risks sit when you automate go-to-market execution at scale.
The Automation Boom Is Real – and So Is the Exposure
Sales teams have never moved faster on AI tooling than they have in the past 18 months. RevOps functions that once spent weeks building manual qualification workflows are now deploying AI agents that surface intent signals, flag at-risk accounts, and draft outbound sequences before a rep has finished their morning coffee. The efficiency gains are measurable and, in competitive markets, they’re becoming a baseline expectation rather than a differentiator.
But the same integrations that make AI automation powerful – CRM-to-portal connections, third-party enrichment tools, webhook-driven data flows – create more points of potential exposure. The Salesforce and ServiceNow case illustrates exactly this tension. These weren’t obscure back-end systems. Customer portals are front-facing, carrying contact records, support history, deal data, and in many cases the kind of account intelligence that directly informs your Ideal Customer Profile (ICP) modelling.
When that data sits exposed for 17 months, the downstream risk isn’t just regulatory. It’s competitive.
What This Means for AI-Driven GTM Teams
Most go-to-market teams approach AI implementation as a revenue problem. Which is correct – but it’s only half the picture. The data that powers AI models – the contact histories, the engagement signals, the closed-lost reasons that train your next sales forecast model – needs to be treated as infrastructure, not just inputs.
Here’s where it gets specific. AI automation in CRM environments typically touches several sensitive data categories:
- Account enrichment data pulled from third-party providers and written back into CRM records
- Conversation intelligence outputs from call recording tools, often stored alongside deal notes
- Lead scoring model inputs that include firmographic and behavioural data
- Portal activity logs that reveal which prospects or customers are actively researching your product
Each of these data streams represents both an AI asset and a potential liability. The teams winning with AI right now are the ones treating data governance as part of the sales cycle infrastructure, not a separate IT concern.
The Security Audit Your RevOps Team Probably Hasn’t Done
Most RevOps functions have detailed documentation on their CRM field mappings, their lead routing logic, and their attribution models. Far fewer have a current, accurate map of which external systems have active access to CRM data – and under what permissions. That gap is where exposures like the one reported last week actually happen. It’s not usually a sophisticated attack. It’s a misconfigured portal, a stale integration credential, or a third-party connector that was set up during an implementation and never reviewed.
If you’re running AI automations that rely on real-time CRM data, a practical starting point is auditing your connected applications. Which tools have read access to your contact and account objects? Which have write access? When were those permissions last reviewed? The answers are surprising more often than you’d expect – and that’s before you get to the question of what data those tools are storing on their own servers.
For teams using Salesforce specifically, the platform’s Connected Apps and OAuth token management settings are the right place to start. ServiceNow environments warrant a similar review of integration user permissions and external-facing portal configurations. This isn’t glamorous work. It’s also the work that prevents a 17-month exposure window from quietly becoming your problem.
Balancing AI Speed with Smarter Risk Management
The commercial case for AI in sales automation is strong. Teams that have tightened up their win rate with AI-assisted deal coaching, or reduced churn rate through predictive account health scoring, aren’t going to walk those capabilities back because of security concerns. Nor should they. The right response is integrating security thinking into the same operational cadence that governs everything else in a modern GTM stack.
That means a few concrete changes to how most teams operate. Security reviews should be part of the evaluation process when adopting new CRM tools and AI sales platforms – not an afterthought post-implementation. Data minimisation – giving AI tools access to only what they need – reduces blast radius if something goes wrong. Regular access audits, at least quarterly, should sit in the RevOps team’s remit alongside pipeline reviews and forecast calls.
The AI capabilities themselves aren’t the vulnerability. The integration layer around them usually is.
For teams still building out their operational foundations, the CRM Guides section covers both AI automation setup and the governance practices that keep those automations trustworthy. And if you want to stay current as this space develops – the intersection of AI sales tooling and enterprise security is going to generate a lot of news in the months ahead – the CRM Daily Newsletter covers it weekly.
The open question worth sitting with: as AI agents in CRM environments become more autonomous – writing to records, triggering workflows, communicating with customers without rep involvement – who actually owns the security posture of those agents? Is it RevOps, IT, the AI vendor, or someone who doesn’t exist yet in most org charts? There’s no clean answer today, and the industry’s response to it will matter more than any individual tool choice.
