WithSecure launches native malware and phishing protection for Salesforce Agentforce
Press Release | September 2025

AI agents open new attack vectors in Salesforce — WithSecure moves fast to keep AI agents secure to use.
Helsinki, Finland – September 2025: Enterprises are racing to adopt Salesforce Agentforce. In doing so, they are opening their platforms to customers, partners and other third parties using AI agents to automate customer conversations, workflows, and data processing at unprecedented speed.
But that speed also creates a new risk: attackers could use agentic AI to push malicious files and links through Salesforce without malware protection.
Traditional email or endpoint tools don’t protect Salesforce. Since Salesforce doesn’t scan files and links for cyber threats, organizations face a blind spot in one of their most business-critical platforms — and must prepare for new types of AI-driven attacks.
“AI adoption has accelerated faster than most security controls,” said Juhana Autio, General Manager and VP at WithSecure Cloud Protection for Salesforce. “The question now is: how do you secure and manage your AI agents? That’s what enterprises are asking us — and what we have set out to answer.”
Securing agentic AI at scale
Today, WithSecure announced a security extension to its Cloud Protection for Salesforce solution, delivering native real-time malware and phishing protection for Agentforce. The extension works inside Salesforce to stop malicious files, links, and agent actions, thereby securing the Salesforce environment and preventing breaches.
The new solution provides the enterprise level protection needed to Agentforce:
- Securing Agentforce workflows: Automatically scans and protects all files and URLs in Agentforce workflows.
- Compliance: An enterprise-grade solution built for the most demanding environments across industries.
- Native integration: Ensures protection without interrupting or slowing down Agentforce workflows.
Closing the security gap
As Agentforce processes more files, links, and actions through Salesforce, phishing and malware risks increase. “Salesforce is both a valuable target and a powerful channel for attackers,” Autio added. “If you’re not inspecting what your AI agents touch, you’re effectively blind to an entirely new attack surface.”
WithSecure's native protection stops threats at the source without slowing AI operations.
Availability
The Agentforce extension is now available on Salesforce AgentExchange and AppExchange to all WithSecure Cloud Protection customers as part of existing licenses.
For more information, visit: https://cloudprotection.withsecure.com/protection-for-agentforce/
About WithSecure™ Cloud Protection for Salesforce
WithSecure Cloud Protection for Salesforce safeguards your cloud environment against advanced cyber threats. You can run your digital business without disruption – free from ransomware, zero-day malware, viruses, trojans and phishing links. The bespoke solution is designed in close collaboration with Salesforce and managed directly from your Salesforce portal.
Media contact
Elisa Mustonen
About WithSecure™
WithSecure™, formerly F-Secure Business, is Europe's cyber security partner of choice. Trusted by IT service providers, MSSPs, and businesses worldwide, we deliver outcome-based cyber security solutions that protect mid-market companies. Committed to the European Way of data protection, WithSecure prioritizes privacy, data sovereignty, and regulatory compliance.
Boasting more than 35 years of industry experience, WithSecure™ has designed its portfolio to navigate the paradigm shift from reactive to proactive cyber security. In alignment with its commitment to collaborative growth, WithSecure™ offers partners flexible commercial models, ensuring mutual success across the dynamic cyber security landscape.
Central to WithSecure's™ cutting-edge offering is Elements Cloud, which seamlessly integrates AI-powered technologies, human expertise, and co-security services. Further, it empowers mid-market customers with modular capabilities spanning endpoint and cloud protection, threat detection and response, and exposure management.
WithSecure™ Corporation was founded in 1988, and is listed on the NASDAQ OMX Helsinki Ltd.