Staff Leak Military Secrets on Facebook and Twitter

Posted by William McBorrough, MSIA, CISSP, CISA, CRISC, CEH | Social Networking,Users | Wednesday 27 January 2010 2:10 pm

Are your employees ( or you ) leaking sensitive data over the social networks? This report from the UK should give you pause.

The Ministry of Defence has admitted that staff leaked secret information 16 times on social networking sites such as and over an 18-month period.

The admission comes in response to a Freedom of Information request by Lewis PR, which handles public relations for firm F-Secure.

Lewis said the Ministry of Defence had disciplined 10 personnel, although was unable to specify individual cases.

Are your employees leaking your sensitive data via social networks? This report from the UK should give anyone pause.

Ministry of Defence staff aren’t banned from using social networks, but Lewis pointed out that the department’s code tells employees: “Remember you are a member of HM Forces/MOD civil servant. Observe the same high standard of conduct and behaviour online as would be expected of you in your professional or personal life.”

However, F-Secure said the Ministry of Defence should do more to ensure the guidelines are adhered to.

“It’s worrying that employees in sensitive positions have been sharing confidential information via Twitter and other means,” said F-Secure’s security expert Mikko Hypponen

“They might think they are confiding in friends or family when they go on Facebook. However, the recent changes in Facebook’s settings might make them disclose information to the world. This is a potential security risk.”

Source: http://www.csoonline.com/article/525613/MoD_Staff_Leak_Military_Secrets_on_Facebook_and_Twitter

About: William McBorrough, MSIA, CISSP, CISA, CRISC, CEH:
William J McBorrough is a Security Expert with many years of success Managing, Designing, and Implementing medium and large enterprise Physical and Information Technology Security Solutions. His experience spans the spectrum from small e-commerce start-ups to multi-campus state and federal agencies to global financial sector organizations. He is on the faculty of various universities including University of Maryland University College, EC-Council University, George Mason University and Northern Virginia Community College where he conducts research and teach graduate and undergraduate courses relating to cybersecurity, cybercrime, cyberterrorism, and information security and assurance. He holds a Bachelors of Science in Computing Engineering with a concentration in digital networks and a Masters of Science in Information Security and Assurance. He is a Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk Information System Control (CRISC), and Certified Ethical Hacker (CEH).He is well versed in personnel, systems and network security risk management. His core competencies include Developing cost effective solutions to enable mission assurance in the following areas: Enterprise Risk Management, IT Governance, Security Organization Development, Information Security and Assurance
Website:http://www.linkedin.com/in/mcborrough
If you enjoyed this post, subscribe to my RSS feed!

Related posts:

  1. How to limit Twitter risks
    Twitter is now used by over 350 million people worldwide. However, Twitter is also gaining a reputation as security risk for individuals and organizations. Every business or organization which uses...
  2. What is the values proposition for allowing users access to social networks?
    What is the values proposition for allowing employees access to web 2.0 resources such as social networks? Every other day, we hear about the risks. Compromised Twitter accounts, phishing via...
  3. Facebook, Twitter, ….Buzz?
    Update: Power to the people!! In response to the concerns raised over the privacy of status updates (see below), Google has revamped the buzz interface  to give users more (obvious?)...
  4. Did Facebook CEO play fast and loose with user login data?
    Did you Facebook CEO play fast and loose with user login data?...
Comments
Get Adobe Flash player

Switch to our mobile site