{"id":53685,"date":"2023-01-24T07:35:00","date_gmt":"2023-01-23T23:35:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=53685"},"modified":"2023-01-23T13:55:29","modified_gmt":"2023-01-23T05:55:29","slug":"seven-tips-on-mitigating-cyber-risks-to-your-corporate-social-media-in-2023","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/01\/24\/seven-tips-on-mitigating-cyber-risks-to-your-corporate-social-media-in-2023\/","title":{"rendered":"Seven tips on mitigating cyber risks to your corporate social media in 2023"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>Anna Larkina, Web content analysis expert at Kaspersky; Roman Dedenok, Spam Analysis Expert at Kaspersky&nbsp;<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Threats to corporate social media are evolving along with perpetrators\u2019 social engineering skills at a blistering pace. Sometimes their techniques reach such a high level that even the tech-savvy administrator of a corporate network can\u2019t tell the difference between a scam and the truth.\u00a0 <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As many businesses use social media to promote their products and services, these threats are relevant to an extremely large number of companies. To help them stay safe, Kaspersky experts are offering the following advice to mitigate the cyber risks associated with social media in 2023.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh6.googleusercontent.com%2FBkc1EXqf2WGeqOpgtnCgWY2Oc-uC66pOS8quIDs5cf_9rAmxB86MW_enw3amHJ2wOgCeM_Rtyc-E5lFEDnW4605jFgwFq_Rb8pYpYWVgUQnbApF5OATqe2i1Y70Ft75fSjgbn0lu871_7DOyYYkUaQLhKzr1CbfyjWNpthEm1BoLdCImPxsmprXlGGPZzw&amp;t=1674452134&amp;ymreqid=27f3344f-c727-c29c-1cb6-5d00e701ac00&amp;sig=RADtirI9_Ia3t6eqe16caw--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Use caution with direct messages and drafts folder, delete old irrelevant information&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies should be careful about keeping sensitive information in direct messages \u2013 it can pose cyber risks.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">People often use corporate social media to write directly to brands, asking for help, using the account holder\u2019s product or service. Also, some partnerships, such as those with bloggers, can be negotiated in direct messages. Sometimes personal or financial information is shared during these conversations, which could remain in the messages folder long after the interaction. If there is a breach allowing cyber criminals to gain unauthorized access to the account, sensitive data may be leaked or used to organize an attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To avoid this risk, make it a useful habit to delete irrelevant messages when the dialog is finished and the information it contains is no longer relevant. The same applies to posts \u2013 It is worth carefully reviewing what is saved in the drafts folder from time to time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Review old posts to minimize reputational risks&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The power of reputation is growing: every word, action, and decision can either help or harm the company\u2019s image.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Everything published online is of great importance in terms of cyber security as well: when sensitive information (re)appears in public, it almost always ends up hurting a company\u2019s reputation and could incur financial losses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To be on the safe side, spend some time reviewing already published posts, as they might contain information that doesn\u2019t fit into the current reality \u2013 that might be anything from inappropriate jokes to controversial advertising campaigns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What was normal yesterday, can cause a negative public reaction today. A review of publications made over the past few years largely reduces related reputational risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Be careful posting your success stories&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Having signed a lucrative contract or reached a deal, we want to post it on social media to tell as many people as possible about our success. But we really need to be aware of unwanted cybercriminals\u2019 attention. If a potential attacker knows who your suppliers or contractors are, they could try to conduct an attack impersonating them or breaching their accounts and acting on their behalf.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Moreover, the clearer you reflect your company\u2019s structure and working methods on social media, the easier it is for perpetrators to organize an attack. For example, if it is possible to trace who is responsible for finance, an attacker can pretend to be this person\u2019s supervisor and try to lure them into urgently transferring a large sum of money to a fake account to \u201cclose a deal\u201d or \u201cpurchase necessary equipment\u201d. Exercising various social engineering techniques, a perpetrator can convincingly impersonate another person, and a victim would hardly notice the fraud.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Warn newcomers about risks associated with \u201cnew job\u201d posts on social media<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After getting a new job, newcomers usually share the news on social media, but they do not yet understand how cybersecurity processes are built in this company: for example, how identification works or with whom they can share sensitive information. Therefore, a newcomer is more vulnerable to cyberattacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine: a perpetrator tracks this person in social media and collects information about them. Then the criminal writes the new employee a malicious letter on behalf of the company\u2019s IT administrator asking to share the password to set up a technical account.&nbsp; It is highly likely that a newcomer will share the password because they do not know that the administrators would never write such a letter. Moreover, new employees are usually shy, and they might hesitate to ask their colleagues if the letter is authentic. A tiny little post on social media might turn the employee into an entry point for cybercriminals.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To mitigate the risk, offer newcomers a course on information security immediately, and tell them to be extremely careful when posting about a new job.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Control account access (and don\u2019t forget to change the password when an employee leaves)&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Logins, passwords, and access to the email address used to create a social media account are just as valuable as other internal corporate documents.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an employee who has access to accounts and authentication data leaves the company, it is useful to apply the same rules as when blocking their access to the corporate network.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To begin with, change the password for the e-mail account linked to the corporate social network; then unlink the ex-employee\u2019s mobile phone number and check other authentication methods \u2013 for example, a spare mailbox.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Do not ignore two-factor authentication&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Any account on a social network, not to mention a corporate one, must be securely protected. Two-factor authentication is an absolutely necessary setting for any type of account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The email address linked to the account should be as protected as the social media account itself. Often the attack begins with an initial access to email. After breaching an account, an attacker can configure filters in the mailbox settings to delete all support emails from the social network. Therefore, a user will not be able to restore access to their account, because all emails will be deleted automatically. Not to mention that in a stressful situation we won\u2019t be checking which filters are currently configured in our mailbox.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is best to register a social media account using a corporate email address. To begin with, it is better protected (assuming the company cares about cybersecurity). Furthermore, in-house security specialists can block access to this mailbox along with all access to the corporate network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Provide your employees with anti-phishing training&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To mitigate cyber risks in social media networks, it is not enough to protect your company\u2019s account technically, it is equally important to conduct special training for employees on information security, various types of phishing, and other threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to user statistics on the <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/security-awareness\">Kaspersky Gamified Assessment Tool<\/a>, designed to educate workers and to assist managers in measuring their cyber skills, just 11% of nearly 4000 employees demonstrated a high level of cybersecurity awareness in 2022, while 28% could not prove sufficient cybersecurity proficiency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers use sophisticated methods of social engineering. Even the most advanced representatives of Gen Z can succumb to them. The human factor cannot be reduced to zero, but it can be minimized as much as possible with the help of dedicated training.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As many businesses use social media to promote their products and services, these threats are relevant to an extremely large number of companies. To help them stay safe, Kaspersky experts are offering the following advice to mitigate the cyber risks associated with social media in 2023.\u00a0<\/p>\n","protected":false},"author":7,"featured_media":53524,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[],"class_list":["post-53685","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/53685","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=53685"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/53685\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/53524"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=53685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=53685"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=53685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}