Social media needs “social” security measures
By Marco Rottigni
Overall, social media is not a hugely dangerous security threat to organizations. There is no
need to ban Facebook at your workplace for IT security reasons. For PR or brand reasons, you can
control what people are saying about your company. Sure there are some pitfalls, but those are
being circumvented with security and education. Corporations, from small to large, are leveraging
the full potential of social media platforms, after they have become aware of, recognized and
minimized the risks. Companies are taking both social and IT security measures to protect their
brand, IP resources and information. As long as the company is aware of all the risks involved and
is doing network monitoring, social media can be a huge marketing enabler. Setting the guidelines
for social media is a task that all companies face sooner or later, and many already have. Remember
the Dominos Pizza case, where two employees got fired for posting harmful content to Youtube?
Or Ivell Marketing and Logistics, who fired an employee for writing about the company in
Facebook? There is no way this kind of events could have been avoided with better IT security. They
could have been avoided by better agreements with the employees regarding what is proper and what
is not, when it comes to social media and workplace. After all, you trust your employees will not
write anything ill about your company in the local newspaper either. (And if they do write bad
things about you in the local paper, you have a totally different issue on your hands.)
On the technical side, if you monitor and control your network traffic with a modern
Intrusion Protection System and a firewall, you probably already have all the equipment to meet
this new challenge. After all, you are monitoring all network traffic, including the traffic to and
from social media platforms. With the right tools, picking malicious packages from the traffic
stream is just as easy as from any traffic.
Today SSL VPN technology is used to transparently authenticate users towards cloud services
like SalesForce.com which are closer to business than social media.However, social media are
starting to offer business oriented services such as the MarketPlace in Facebook. SSL VPN can help
in enabling interaction, assessment and authentication with these “business aspects” of social
media. .
* * *
Our own social media initiative, StoneBlog, celebrated its first anniversary the 1st of
December 2010. In a nutshell, Stoneblog started because of my own passion to communication. It has
evolved from a “personal steam valve” to a truly collaborative customer dialog platform. From the
need to communicate, to a desire to share. Feel free to comment. You will find my posts under the
nick “RoarinPenguin”.
The author is working for Stonesoft as StoneGate SSL VPN Product
Manager. The focus of his expertise is in network security, SSL VPN, StoneGate architecture and
virtualization technologies. StoneBlog can be found at
http://stoneblog.stonesoft.com/.