Malware top risk of employee social networking
The threat of external malware heads up ISACA's list of top five threats, but the rest of the list shows the need for better education rather than better protection.

Malware has topped the list of a new white paper from IT governance group ISACA, listing the top five risks involved in employees accessing social networking tools in the workplace.
The report, entitled Social Media: Business Benefits With Security, Governance and Assurance Perspectives, pointed to the huge popularity of sites like Facebook and Twitter proving increasingly attractive to online criminals.
Next on the list came brand hijacking, followed by lack of content control, non-compliance with rules over record keeping, and unrealistic expectations of internet performance.
Whilst it is generally acknowledged that allowing access to social networks in the workplace increases the risk to the company's systems, the picture is becoming more complicated by the number of employees using their own hardware to access the company network, and the increasing practice of using social networks for business purposes.
For this reason, ISACA urges that the traditional line adopted by many companies of simply blocking access is no longer a viable solution. Instead, it says sensible levels of access should be allowed, and companies should take responsibility for better educating employees as to the risks involved.
"Historically, organisations tried to control risk by denying access to cyberspace, but that won't work with social media," said ISACA vice president Robert Stroud, in a statement.
"Companies should embrace it, not block it. But they also need to empower their employees with knowledge to implement sound social media governance."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The document also highlighted that whilst the biggest risk to companies malware is an external threat, the rest of the list are all factors relating to employee behaviour and their understanding of what actually constitutes "risky behaviour".
"The greatest risks posed by social media are all tied to violation of trust," said ISACA Certification Committee member John Pironti.
"Social media is built on the assumption of a network of trusted friends and colleagues, which is exploited by social engineering at great cost to companies and everyday users. That is why ongoing education is critical."
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
What is your digital footprint?
In-depth Your digital footprint is always growing – so we explore how you can keep it under control
By Maggie Holland Last updated
-
Nine top GDPR tips for email marketing strategies
In-depth It's not all doom and gloom – here's how you can make GDPR work for you
By Zach Cooper Last updated
-
Why GDPR creates a "vicious circle" for marketers
News Customers will control the forthcoming trust economy, predicts Aprimo
By Rene Millman Published
-
Facebook will allow adverts to target users based on beliefs
News The company will also give users opt-ins to use facial recognition to prevent impersonation
By Rabbil Sikdar Published
-
Tim Berners-Lee: How we can win back the web
News The public must reject misinformation and keep control of their own data
By Clare Hopping Published
-
Social network users play fast and loose with data privacy
News Over-sharing puts users at risk of identity theft and fraud
By Jane McCallion Published
-
UK government Facebook data requests grow 71%
News Only US and India ask for more user details from the social network
By Adam Shepherd Published
-
Virginia shooting - don't open that link!
Opinion Scammers and cyber criminals love to capitalise on tragedy, and we can't help but click
By Jane McCallion Published