← All log entries

Security Should Make Marketing and Sales More Careful, Not More Comfortable

LOG // 2026-07-28

The wrong way to talk about security is as a universal scare tactic. The right way is more specific: marketing and sales should be much more afraid of what they are asking for.

That sounds harsh because it is. But it is also realistic. The people asking for faster campaigns, broader access, lighter approvals, and more automated workflows are often the same people least exposed to the consequences when something goes wrong. Security exists to close that gap.

The problem is not ambition

Marketing and sales are supposed to push. They want reach, speed, conversion, and convenience. That is their job.

The issue is what happens when those requests are treated as harmless by default:

  • a CRM integration gets broader access than it should
  • a new automation has no approval gate
  • a customer dataset gets copied into too many tools
  • an AI workflow is allowed to act before it is understood
  • a shortcut becomes the normal path because it ships faster

Every one of those choices looks reasonable from the inside of a campaign. From the outside, they are how incidents start.

Security should make the ask feel real

If a team wants more speed, R&D should ask what they are willing to risk to get it. If they want more automation, R&D should ask who is accountable when the automation is wrong. If they want wider access, R&D should ask why the current boundary is not enough.

That is not obstruction. That is governance.

Good security forces the requester to confront the cost of the ask. Not in a theatrical way. In a practical way.

Why marketing and sales deserve the pressure

Marketing and sales sit close to customer data, external systems, and revenue-facing workflows. That means their requests have outsized blast radius. A sloppy integration there is not a local mistake. It can become a brand problem, a privacy problem, or a fraud problem.

So yes, they should be a little afraid. Not paralyzed. Just honest about the stakes.

If a request touches customer data, messaging systems, pipelines, permissions, or AI agents that can act on behalf of the business, it should feel expensive enough to slow down and think.

What security should do instead of just saying no

Security should not be a department of vague warnings. It should make tradeoffs explicit:

  • what this request exposes
  • what the likely failure mode is
  • who owns the risk
  • what control reduces the risk enough
  • whether the business still wants the feature after that

That changes the conversation from "can we do it?" to "should we do it this way?" That is the point.

The business version of fear

Fear is useful when it changes behavior. Marketing and sales do not need to be scared of security. They need to be scared of careless requests that create future cleanup, reputational damage, or preventable incidents.

Security is the function that keeps those costs visible before they become real.

Get in touch if you want help putting guardrails around growth instead of cleaning up after it.