Social Media Policy
Learn what not to post on corporate accounts.
What Is Social Media Policy?
A single careless post can leak a deal, expose a client list or hand an attacker their reconnaissance. You review posts drawn from real incident patterns: a hint about a deal closing next week, an office photo with a monitor in frame, a public vent that breaches communications guidelines. For each one you name the specific risk and rewrite the content so the message survives and the exposure does not. Then you audit your own profile for the details that make a targeted phish work.
What You'll Learn in Social Media Policy
- Identify types of corporate information that should not appear on personal or professional social media profiles
- Evaluate social media posts for operational security risks including location data, org charts, and technology details
- Rewrite social media content to remove sensitive information while preserving the original message's purpose
- Recognize how attackers mine public social media profiles to build pretexting scenarios for targeted attacks
- Apply your organization's social media policy to ambiguous situations where personal expression and corporate risk overlap
Social Media Policy — Training Steps
-
Welcome to Catalyst Innovations
It's a regular Wednesday morning. You've settled into your home office and are about to check your messages.
-
A Message from Mark
Alice's phone buzzes with a Telegram notification from her colleague Mark Chen, a senior developer on the team.
-
Mark's LinkedOut Post
Curious about what Mark shared, Alice opens LinkedOut on her desktop to find his post.
-
What Mark Shared
Mark's post is enthusiastic, but take a closer look at what information he has publicly revealed.
-
An Email from TechForge
Five days have passed. Alice receives an email apparently from TechForge Solutions about the Project Helios collaboration.
-
Clicking the Link
The email looks legitimate - it references Project Helios, mentions Mark by name, and knows about the Q2 deadline. Alice clicks the link to access the partner portal.
-
Logging Into the Portal
The partner portal asks Alice to log in with her work credentials.
-
Authentication Error
The page shows an authentication error. That's strange - Alice is sure she typed her password correctly. A knot forms in her stomach. Why isn't it working? She decides to wait and try again later, but the uneasy feeling lingers.
-
Something Is Wrong
Two hours later, Alice receives an urgent email from the Catalyst Innovations Security Operations Center.
-
The Sender Domain
Alice realizes what happened. Let's go back to the original email and examine the red flags she missed. First - the sender's email address.
Security Framework Coverage
CIS Controls
- CIS 14.1 Establish and Maintain a Security Awareness Program
- CIS 14.5 Train Workforce Members on Causes of Unintentional Data Exposure
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind