Half of UK companies hit by social media security scares

Web Exclusive

Thursday, 10 January 2013

Lax company policies are spawning naïve mistakes and leaving firms vulnerable to cyber breaches, writes Dave Fawbert

Social Media

Despite regular scare stories about Facebook’s prospects, it seems that social media is here to stay.

However, a recent KPMG survey revealed not only that companies are still unsure about how to harness social media’s power, but that it has left them increasingly vulnerable to security threats.

According to the leading auditing firm’s findings, a staggering 45% of UK companies had experienced a security scare as a direct result of corporate social media use. This follows its discovery that the private sector is lagging behind public organisations in implementing rigorous social media policies – both externally, in how companies project themselves; and internally, in how employees actually use social networks.

KPMG revealed that almost nine out of 10 organisations within the private sector claim to have a social media strategy – but the extent to which security is compromised suggests that those strategies are failing. The scares range from customers’ use of social media to wage “complaint campaigns”, which negatively impacts corporate reputation – a problem compounded by subsequent failures to deal with the fallout – to individual actions such as leaking sensitive information via ill-considered online comments, or hacking of employees social media passwords that happen to replicate their company passwords.

Martin Jordan, head of incident response in KPMG’s Risk Consulting branch, has recommended a series of steps to help companies improve. These include:

  1. Staff training – either face-to-face or via remotely-accessible videos – to remind them of their responsibilities online;
  2. Reduction of companies’ online profiles, with clear demarcation between personal and work accounts – “There is no reason for staff to link their Twitter accounts to their employer,” he says;
  3. Habitual use of multiple and complex passwords (particularly in light of last year’s significant password leak on LinkedIn), and
  4. Advocating and creating purpose-built, internal social media sites that are company controlled – such as intranets – rather than relying on external sites, which are less secure.

In addition, Jordan stresses the need to “tune your policies” according to country and culture.

Social media is clearly not a passing fad – and Jordan rightly states that “adopting an ‘ostrich approach’ is not advisable”. At its best, social media can be a useful tool that links workers together and improves their productivity. At its worst, it can present a host of nightmarish opportunities for leaks and breaches. Prudent managers would heed Jordan’s advice and tighten their policies without delay.

Facebook homepage image courtesy of Annette Shaff / Shutterstock.com