The Social Minefield: Mapping OSN Risks in the Modern Enterprise

Online social networks risks to organisations: a literature review

2018-12-03
Talitakuum A. T. Ekandjo, Hussin Jazri, Anicia Peters, Anicia N. Peters
Summary
Problem
Method
Results
Takeaways
Abstract

This paper presents a comprehensive literature review and taxonomy of information security risks posed by Online Social Networks (OSNs) to organisations. It categorizes threats into five distinct domains—Brand, Legal, Financial, Publicity, and Technological—identifying employees as the primary "weakest link" in corporate security.

TL;DR

As Online Social Networks (OSNs) become indispensable for marketing and collaboration, they simultaneously open a "Pandora’s Box" of organisational vulnerabilities. This research provides a structured taxonomy of these risks, categorizing them into Brand, Legal, Financial, Publicity, and Technological domains, while highlighting that traditional firewalls are no match for human-centric social engineering.

The Human-Centric Vulnerability

The digital transformation era has forced a paradoxical shift: companies must be "social" to survive, yet every employee with a LinkedIn or Facebook profile represents an entry point for malicious actors. The paper identifies a critical gap—while technical controls (firewalls, anti-malware) are standard, they cannot prevent an employee from inadvertently leaking sensitive projects or falling victim to a sophisticated spear-phishing attack.

The core problem is the Information Repository nature of OSNs. Attackers don't need to "hack" the system; they simply "harvest" the data freely provided by users to build high-success attack vectors.

Methodology: The Risk Taxonomy

The authors synthesized a taxonomy that serves as a diagnostic tool for CSOs (Chief Security Officers). By categorizing risks, organisations can better allocate resources for mitigation.

Risk Taxonomy Table

1. Brand & Reputation Risks

In the age of viral content, a single unprofessional post or a "brand hijacking" incident (where an attacker impersonates the company) can lead to a permanent loss of consumer trust.

2. Legal & Regulatory Risks

From defamation lawsuits to intellectual property (IP) theft, the legal ramifications of OSN use are vast. The paper highlights the "chilling effect" of monitoring employees versus the necessity of preventing industrial espionage.

3. Financial Consequences

The stakes are no longer theoretical. With 53% of attacks resulting in losses over $500,000, OSN-related threats like phishing and productivity loss represent a direct hit to the bottom line.

Critical Insight: The "Weakest Link"

The research underscores a grim reality: Employees are the weakest security link. Malicious actors utilize mechanisms like "clickjacking" and "shortened links" to exploit the habituated clicking behavior of social media users.

Concept Image

Conclusion and Future Outlook

The paper concludes that simply banning social media is not a viable strategy. Instead, the future of corporate security lies in:

  • Defined Guidelines: Moving beyond vague policies to specific warnings against social engineering.
  • Behavioral Modification: Shifting the focus from technical firewalls to "human firewalls" through continuous awareness.
  • Balancing Act: Managing the fine line between an employee's right to privacy and the organisation's need for data integrity.

The authors suggest that future research should focus on Critical Success Factors (CSFs)—finding the sweet spot where OSN benefits are maximized without compromising the security perimeter.

Find Similar Papers

Try Our Examples

  • Find recent studies or SOTA frameworks that specifically quantify the ROI of employee social media security awareness training in reducing financial loss from spear-phishing.
  • Which foundational papers first established the "human as the weakest link" theory in information security, and how has the rise of OSNs evolved this theory?
  • Research current AI-driven tools used by organisations for real-time monitoring of brand hijacking and sensitive data leakage on decentralized social platforms.
Contents
The Social Minefield: Mapping OSN Risks in the Modern Enterprise
1. TL;DR
2. The Human-Centric Vulnerability
3. Methodology: The Risk Taxonomy
3.1. 1. Brand & Reputation Risks
3.2. 2. Legal & Regulatory Risks
3.3. 3. Financial Consequences
4. Critical Insight: The "Weakest Link"
5. Conclusion and Future Outlook