Infosec: Workplace Facebook bans are a waste of time
Web security vendor Barracuda Networks claims banning staff from using social networking sites still exposes firms to risks.
IT departments that try to ban employees from accessing social networking sites for security reasons are fighting a losing battle, claims security vendor Barracuda Networks.
Speaking to IT Pro at Infosecurity Europe, the firm's chief research officer, Dr. Paul Judge, said most end users find a way round blanket bans on Facebook and Twitter use in the workplace.
Your average company's website is just sat out on the internet with nothing protecting it
And, with newer sites such as Pinterest and Instagram emerging and growing in popularity, it is an evolving situation that is hard for IT departments to keep tabs on.
"If you look at the time people spend online, the biggest time drain is social networks. So, if you're an attacker trying to get in front of more eyeballs, it's the place to be," said Judge.
"[These attackers] are making millions of fake accounts to interact with legitimate people and, potentially, your company's employees are exposing you to risk."
However, rather than stop people using them completely, there are steps companies can take to mitigate these risks.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"A lot of companies try to tell people they can't use Facebook or Twitter, but it is easier to let them access the sites in a controlled way," he explained.
"For instance, they can use application control rules or policies to protect themselves against malware, viruses and data loss by controlling the amount of risk social networks expose them to."
He said businesses should make use of "read-only web" tools, which allow employees to visit sites, but prohibits them from downloading and uploading content.
"You can compromise in other ways by letting employees access Facebook, but use tools that stop them from accessing user profiles and limits access to company-related pages," he added.
"There are tools that scan Facebook and Twitter profiles, looking for suspicious content, malware and spam, which gives employees access to a wider range of pages in a controlled way."
Aside from social networking sites, he claimed businesses are also leaving themselves open to attack by failing to secure their corporate sites properly.
"Large financial institutions have been doing [a great job of this] for years, but your average company's website is just sat out on the internet with nothing protecting it," he claimed.
"It is changing. The Anonymous era has increased awareness of network and website breaches and increasingly the board is saying to the IT department, how can we stop that happening to us?"
Caroline Donnelly was the news and analysis editor of IT Pro. Previously, she worked as a reporter at several B2B publications, including UK channel magazine CRN, and as features writer for local weekly newspaper, The Slough and Windsor Observer. She studied Medical Biochemistry at the University of Leicester and completed a Postgraduate Diploma in Magazine Journalism at PMA Training in 2006.
-
Oracle integrates Google's Gemini AI models into enterprise appsThe deal aims to give broader access to Gemini models that can support AI agents and accelerate development
-
Applications open for EU AI gigafactoriesThe European Commission wants to build sovereign AI infrastructure, with €10 billion of public funding
-
The truth about cyber security trainingWhitepaper Stop ticking boxes. Start delivering real change.
-
Employees behaving badly?Whitepaper Why awareness training matters
-
Teaching good cyber security behaviors with SeinfeldWhitepaper Overcoming the employee engagement challenge in security awareness training
-
Latest Meta GDPR fine brings 12-month total to more than €1 billionNews Meta was issued with two hefty GDPR fines for “forcing” users to consent to data processing
-
"Unacceptable" data scraping lands Meta a £228m data protection fineNews The much-awaited decision follows the scraping of half a billion users' data and received unanimous approval from EU regulators
-
Meta notifies around 1 million Facebook users of potential compromise through malicious appsNews The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics
-
Facebook business accounts hijacked by infostealer malware campaignNews Threat actors are using LinkedIn phishing to seize business, ad accounts for financial gain
-
Meta begins encrypting Facebook URLs, nullifying tracking countermeasuresNews The move has made URL stripping impossible but will improve analytics