Social media needs “social” security measures


By Marco Rottigni

Overall, social media is not a hugely dangerous security threat to organizations. There is no need to ban Facebook at your workplace for IT security reasons. For PR or brand reasons, you can control what people are saying about your company. Sure there are some pitfalls, but those are being circumvented with security and education. Corporations, from small to large, are leveraging the full potential of social media platforms, after they have become aware of, recognized and minimized the risks. Companies are taking both social and IT security measures to protect their brand, IP resources and information. As long as the company is aware of all the risks involved and is doing network monitoring, social media can be a huge marketing enabler. Setting the guidelines for social media is a task that all companies face sooner or later, and many already have. Remember the Dominos Pizza  case, where two employees got fired for posting harmful content to Youtube? Or Ivell Marketing and Logistics, who fired an employee for writing about the company  in Facebook? There is no way this kind of events could have been avoided with better IT security. They could have been avoided by better agreements with the employees regarding what is proper and what is not, when it comes to social media and workplace. After all, you trust your employees will not write anything ill about your company in the local newspaper either. (And if they do write bad things about you in the local paper, you have a totally different issue on your hands.)

On the technical side, if you monitor and control your network traffic with a modern Intrusion Protection System and a firewall, you probably already have all the equipment to meet this new challenge. After all, you are monitoring all network traffic, including the traffic to and from social media platforms. With the right tools, picking malicious packages from the traffic stream is just as easy as from any traffic.

Today SSL VPN technology is used to transparently authenticate users towards cloud services like SalesForce.com which are closer to business than social media.However, social media are starting to offer business oriented services such as the MarketPlace in Facebook. SSL VPN can help in enabling interaction, assessment and authentication with these “business aspects” of social media. .

*    *   *

Our own social media initiative, StoneBlog, celebrated its first anniversary the 1st of December 2010. In a nutshell, Stoneblog started because of my own passion to communication. It has evolved from a “personal steam valve” to a truly collaborative customer dialog platform. From the need to communicate, to a desire to share. Feel free to comment. You will find my posts under the nick “RoarinPenguin”.

The author is working for Stonesoft as StoneGate SSL VPN Product Manager. The focus of his expertise is in network security, SSL VPN, StoneGate architecture and virtualization technologies. StoneBlog can be found at http://stoneblog.stonesoft.com/.