Social Media Security - What You Need to Know
I get asked about social media security more than almost any other topic. People want to use Facebook, Twitter, LinkedIn, and Instagram, but they are increasingly worried about their privacy and safety. Here is the thing - you can use these platforms without exposing yourself to unnecessary risk. It just takes some awareness.
The basics everyone should follow
Before we get into platform-specific advice, there are a few universal rules that apply everywhere:
- Use a unique, strong password for each social media account. If your Facebook password is the same as your email password, you have a serious problem. Use a password manager.
- Enable two-factor authentication. Every major social media platform supports it now. There is no excuse not to use it.
- Review your privacy settings every few months. Platforms change their settings regularly, and defaults tend to favor sharing more, not less.
- Think before you post. Every photo, check-in, and status update is data that can be used by someone who wants to learn about you. This is not paranoia - it is how social engineering works.
What social engineers look for
When I talk about social media security in my training sessions, I show people how much information they are giving away. Here is what an attacker can learn from a typical social media profile:
- Your full name, birthday, and hometown (identity theft basics)
- Where you work and your job title (for targeted phishing)
- Your daily routine from check-ins (for physical security threats)
- Your pet's name, mother's maiden name, first car (security question answers)
- When you are on vacation (for burglary targeting)
- Your social connections (for impersonation attacks)
None of this information is harmful on its own. Combined, it gives an attacker everything they need to impersonate you, steal your identity, or craft a convincing phishing message that you will fall for because it references details only someone who "knows" you would mention.
Platform-specific recommendations
Review your privacy settings under Settings > Privacy. Set "Who can see your future posts" to "Friends" at minimum. Go through your old posts and limit past posts that may have been public. Disable facial recognition. Be extremely careful with third-party app permissions - review and revoke any you do not actively use.
LinkedIn is the most commonly overlooked platform from a security perspective. People share detailed information about their job responsibilities, the technologies their organization uses, and their professional network. This is a goldmine for attackers targeting your employer. Keep your profile professional but avoid listing specific security tools, network configurations, or internal project names.
Twitter / X
If your account is public, assume everything you post is permanent and searchable. Do not share your location in real-time. Be cautious about clicking shortened URLs - they are commonly used in phishing campaigns targeting Twitter users.
Teaching this to others
If you are responsible for security awareness at your organization, social media security is one of the most engaging topics you can cover. People care about their personal accounts, which means they pay attention. And the skills they learn for personal use transfer directly to protecting the organization.
I have found that live demonstrations are the most effective teaching tool. Show someone their own public information compiled into a profile, and they understand the risk immediately. It is much more powerful than a list of rules.
If you want help building a social media security awareness program for your organization, get in touch.