Field notes
Your marketing stack is a security problem. Here’s the protocol.
Enforced 2FA, tight access, a real onboarding and offboarding. That work sits with RevOps. Your data’s integrity and your customers’ trust run through it.
Data security is a RevOps job: enforced 2FA, least-privilege access, and a real onboarding and offboarding process. Your data’s integrity and your customers’ trust both run through it.
On this page
Your CRM, your ad accounts, your marketing automation platform, your analytics - that's your growth engine, and it's also a pile of customer data and live payment methods, held together by whoever happened to get access along the way. Most teams secure it about as carefully as a shared streaming password.
That makes it a RevOps problem. Here's the protocol that should exist and usually doesn't.
Enforce 2FA. No exceptions.
Microsoft found that multi-factor authentication blocks over 99.9% of automated account-compromise attacks - and Microsoft sees roughly 600 million identity attacks a day. Verizon's 2024 breach report puts stolen credentials as the way in for 38% of breaches, with a human element in 68% of them. So make 2FA mandatory across every marketing tool, and use hardware keys (YubiKeys) on anything that touches money or customer data, plus any admin login. A texted code is better than nothing, though a physical key is much harder to phish.
Give access where it matters - and nowhere else
Two failure modes, both common. Too many admins who can't administer anything - five people with the keys, none of whom can safely rebuild a workflow. And too many hands in the ad accounts - people who can't set up a campaign or read the data, one misclick from torching a budget. Access is a liability you hand out. Give it to people who can use it well, and take it back when they can't.
Lock down money and data movement
A short, named list of who can touch payment methods and billing - not "whoever set it up." And the boring hygiene that prevents most of the damage: don't paste passwords into chat or email card details, and keep customer data out of personal accounts and unmanaged spreadsheets. None of it is clever, and it's where most breaches start.
Why this is a growth issue, not a compliance chore
IBM puts the average data breach at $4.88 million. Worry less about that figure and more about the trust behind it. Higher security keeps the integrity of your services and your data intact, and it keeps you from letting down the customers who handed you their information on the assumption you'd look after it. Lose that once and no campaign wins it back.
Make it a protocol, not a vibe
This can't live in someone's head. It's a written marketing-operations security protocol that starts at onboarding, access provisioned deliberately, 2FA enforced on day one, runs through regular check-ins and training, and finishes properly at offboarding, with every account of a departed employee closed for good. The gap between "they left" and "their access left" is where a surprising number of incidents live.
Security is what lets you move fast without one bad afternoon undoing a year of trust.
If you don't have an IT department to hand this to, start here instead - the 2FA methods, the phishing that walks straight through an authenticator app, and the regulations that reach a small team.