[Paper Review] Countering Social Engineering through Social Media: An Enterprise Security Perspective
This paper examines social engineering threats via social media in enterprise environments and proposes a framework for mitigating these risks through improved security policies and awareness. It analyzes existing policies in public and private sectors, identifies gaps, and offers actionable countermeasures to strengthen organizational resilience against social engineering attacks leveraging social media platforms.
The increasing threat of social engineers targeting social media channels to advance their attack effectiveness on company data has seen many organizations introducing initiatives to better understand these vulnerabilities. This paper examines concerns of social engineering through social media within the enterprise and explores countermeasures undertaken to stem ensuing risk. Also included is an analysis of existing social media security policies and guidelines within the public and private sectors.
Motivation & Objective
- To investigate how social media platforms are exploited by social engineers to target enterprise data.
- To analyze existing social media security policies and guidelines in public and private sector organizations.
- To identify gaps and weaknesses in current policies related to social engineering threats.
- To propose a comprehensive framework for countering social engineering through improved security policies and employee awareness.
- To support enterprises in developing proactive, policy-based defenses against social engineering attacks on social media.
Proposed method
- Conducts a comparative analysis of social media security policies across public and private sector organizations.
- Identifies common vulnerabilities and attack vectors used in social engineering via social media.
- Proposes a structured framework integrating policy development, employee training, and technical controls.
- Draws on existing literature and real-world case studies to inform policy recommendations.
- Emphasizes the role of organizational culture and continuous awareness programs in reducing risk.
- Integrates insights from computer science and societal security to address human-centric attack vectors.
Experimental results
Research questions
- RQ1How are social media platforms being exploited by social engineers to compromise enterprise data?
- RQ2What are the key weaknesses in current social media security policies across public and private sectors?
- RQ3What policy and procedural improvements can effectively reduce the risk of social engineering attacks?
- RQ4How can organizations balance openness on social media with robust security controls?
- RQ5What role does employee awareness play in mitigating social engineering threats on social media?
Key findings
- Many organizations lack comprehensive social media security policies tailored to social engineering risks.
- Existing policies often fail to address the evolving tactics used by social engineers on platforms like LinkedIn and Twitter.
- A significant gap exists between policy formulation and practical implementation in enterprise environments.
- Organizations that combine policy enforcement with continuous employee training show reduced susceptibility to social engineering.
- The study identifies a need for standardized, enterprise-wide frameworks to govern social media use and threat response.
- The proposed framework enhances organizational resilience by integrating policy, training, and technical safeguards.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.