1 Managing IT and security Risks from Social Media in Your business By Boris Agranovich Copyright © 2011 Global Risk Consult
2 Who am I? Boris Agranovich: Founder at GlobalRisk community helping clients master risk, adviser, Building Bridges Globally Copyright © 2011 Global Risk Consult more than 25 years of global experience in working with large & medium corporations in West & East Europe, Middle East, Asia Pacific across multiple sectors including Financial Services, IT, Consulting, Manufacturers and Distributors. Recently founded GlobalRisk Community – one of the world’s premier risk community Founder at GlobalRiskConsult, Providing services in the area of risk management, business social networking and marketing
3 Agenda Copyright © 2011 Global Risk Consult Risks of social media IT/security risks Social media compliance policies, and some case studies. The need for effective strategies and policies Regulatory requirements on the use of social media. Where to start?
4 Social media means: Copyright © 2011 Global Risk Consult Loss of brand ownership. Can you cope? Technology available – but figure out strategy than pick right tools Educate internally, encourage behavioural shifts before going external Threads can create opportunities and new ways of engaging with people
5 Legal liability: Copyright © 2011 Global Risk Consult Third Party Statements Defamation and False Light False Advertising and Online Disclosures Privacy and Publicity Cyberstalking Intellectual Property Trade Secrets Recommendations and References
6 IT/Security related risks Copyright © 2011 Global Risk Consult 1.Viruses/malware Phishing Click-jacking 2.Data Loss 3.Bandwidth Consumption 4.Productivity Loss 5.Non-compliance with record management regulations. 6.Brand hijacking and lack of control over content
7 Employee monitoring and pre- employment screening Copyright © 2011 Global Risk Consult Employers must strike a careful balance to avoid violating privacy rights What you know can also hurt you. Companies should obtain employee acknowledgment of policies dictating the extent to which activities may be monitored
8 Reputation risk Copyright © 2011 Global Risk Consult
9 Reputation risk Copyright © 2011 Global Risk Consult
10 Copyright © 2011 Global Risk Consult Case study. How private is your ? Based on the recent cases, your corporate policies including your employee manual, should include the following language: communication is not private; is to be used only for company business; communication is randomly and periodically monitored to ensure compliance;
11 Copyright © 2011 Global Risk Consult Case study continued. The policy should inform the employee that the company policy: Specifically covers the use of cloud based providers; Specifically covers social media companied that have internal ; Informs the employee that such communications may be monitored by the company
12 Copyright © 2011 Global Risk Consult The need for strategies and policies Don’t prohibit but mitigate: Security risks; Risk of misrepresentation; Infringement of intellectual property; Unauthorized disclosure of confidential information; Data privacy; Data leakage and identity theft.
13 Copyright © 2011 Global Risk Consult Compliance requirements
14 Copyright © 2011 Global Risk Consult Regulatory requirements on the use of social media Supervisory policies, procedures, systems and internal controls to monitor all electronic communications technology used by the party and its associated persons to conduct the business. Regulated parties are required to make and keep records of such use and consequently of all content sent or received regardless of the tools that are used to send it. There is no reason to exclude archiving of posts to social networking sites from this requirement.
15 Copyright © 2011 Global Risk Consult What to do next? A real-time Web Defence Selective Social networking Controls Caching Policy Flexibility
16 Where to start (2). Collaborate & Share knowledge Copyright © 2011 Global Risk Consult
17 Social media compliance policies, some samples. Copyright © 2011 Global Risk Consult ● British Telecom - ● Int. Fed. of Red Cross (IFRC) - ● The Coca Cola Company - ● UK CIPR - ● WOMMA - ● US FTC - Principles for Online Behavioral Advertising - ● US CIO Council - SN Use by Federal Departments Isaca Social Media: Business Benefits and Security, Governance and Assurance Perspectives Media-Wh-Paper-26-May10-Research.pdf Media-Wh-Paper-26-May10-Research.pdf
18 Copyright © 2011 Global Risk Consult Regulatory requirements on the use of social media ● Osterman - The Impact of New Communications Tools - ● Osterman - The Need to Archive SN Content - ● US - FINRA - Supervision of Electronic Communications - ● US - FINRA - Guidance on Social Media Web Sites - ● US - FINRA - Communications with the Public
19 Copyright © 2011 Global Risk Consult Questions?? Resources: RIMS magazine Rob van Alphen’s presentation Blue Coat. Solution brief: The Top Four Business Risks of Social media How private is your by Lawyers RMKB