The Social Minefield: Mapping OSN Risks in the Modern Enterprise
Online social networks risks to organisations: a literature review
This paper presents a comprehensive literature review and taxonomy of information security risks posed by Online Social Networks (OSNs) to organisations. It categorizes threats into five distinct domains—Brand, Legal, Financial, Publicity, and Technological—identifying employees as the primary "weakest link" in corporate security.
TL;DR
As Online Social Networks (OSNs) become indispensable for marketing and collaboration, they simultaneously open a "Pandora’s Box" of organisational vulnerabilities. This research provides a structured taxonomy of these risks, categorizing them into Brand, Legal, Financial, Publicity, and Technological domains, while highlighting that traditional firewalls are no match for human-centric social engineering.
The Human-Centric Vulnerability
The digital transformation era has forced a paradoxical shift: companies must be "social" to survive, yet every employee with a LinkedIn or Facebook profile represents an entry point for malicious actors. The paper identifies a critical gap—while technical controls (firewalls, anti-malware) are standard, they cannot prevent an employee from inadvertently leaking sensitive projects or falling victim to a sophisticated spear-phishing attack.
The core problem is the Information Repository nature of OSNs. Attackers don't need to "hack" the system; they simply "harvest" the data freely provided by users to build high-success attack vectors.
Methodology: The Risk Taxonomy
The authors synthesized a taxonomy that serves as a diagnostic tool for CSOs (Chief Security Officers). By categorizing risks, organisations can better allocate resources for mitigation.

1. Brand & Reputation Risks
In the age of viral content, a single unprofessional post or a "brand hijacking" incident (where an attacker impersonates the company) can lead to a permanent loss of consumer trust.
2. Legal & Regulatory Risks
From defamation lawsuits to intellectual property (IP) theft, the legal ramifications of OSN use are vast. The paper highlights the "chilling effect" of monitoring employees versus the necessity of preventing industrial espionage.
3. Financial Consequences
The stakes are no longer theoretical. With 53% of attacks resulting in losses over $500,000, OSN-related threats like phishing and productivity loss represent a direct hit to the bottom line.
Critical Insight: The "Weakest Link"
The research underscores a grim reality: Employees are the weakest security link. Malicious actors utilize mechanisms like "clickjacking" and "shortened links" to exploit the habituated clicking behavior of social media users.

Conclusion and Future Outlook
The paper concludes that simply banning social media is not a viable strategy. Instead, the future of corporate security lies in:
- Defined Guidelines: Moving beyond vague policies to specific warnings against social engineering.
- Behavioral Modification: Shifting the focus from technical firewalls to "human firewalls" through continuous awareness.
- Balancing Act: Managing the fine line between an employee's right to privacy and the organisation's need for data integrity.
The authors suggest that future research should focus on Critical Success Factors (CSFs)—finding the sweet spot where OSN benefits are maximized without compromising the security perimeter.
