Id look internal at who has access to your data before hiring a SF architect to audit. Id imagine theres a much higher chance someone on your team is stealing from you vs someone hacked your Salesforce.