Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Oversharing Can Disclose More Than You Think
Articles

Oversharing Can Disclose More Than You Think

ISBuzz TeamBy ISBuzz TeamMay 23, 2017Updated:May 23, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Mark Zuckerberg made headlines last year when a photo he posted on Facebook showed tape over his webcam on his laptop in the background. And an image of Steve Bannon recently made the rounds after a third-party posted a photo on his social accounts with Bannon’s whiteboard in the background. While Zuckerberg was exhibiting strong security practices and most of what people pulled from Bannon’s whiteboard were points that have already been discussed publicly, it shows that oversharing can uncover private information that you didn’t want to go public. Oversharing can also enable cyber security risks depending on the information exposed.

While it may not seem like an obvious part of security awareness and education, it’s important for infosec teams to discuss best practices on taking photos in the office, posting appropriate content on social accounts, using screen shots in presentations, and even displaying sensitive information in the office. Without intending to, items such as employee badges, product roadmaps, new hire data, sales and revenue figures, confidential client names, salaries and trade secrets can be quickly exposed. And once these details are made public, there is no making them private again.

When speaking with teams, here are some of the primary things to highlight:

Background matters

Highlighting office culture on social media has become an important component of many organizations’ recruiting efforts. Security teams don’t need to discourage this practice, but rather educate employees about why it’s important to consider the content and the background in these shots. It may seem like a good idea to highlight a team brainstorm or presentation, but chances are there are some sensitive details hidden in those photos. It’s important to be diligent about protecting your customer’s confidential data as well as your own. As the popularity of social media continues to rise and more data is at our fingertips, it’s important to realize the variety of ways your information could be exposed.

Smile for the camera

According to Pew Research Center, “seven-in-ten Americans use social media to connect with one another, engage with news content, share information and entertain themselves.” This is in stark contrast to 2005, when they found only 5 percent of American adults used at least one social media platform. So you can assume at least 70 percent of your organization actively uses at least one social media account. Most of this is likely for personal use. However, the lines between our personal and professional lives continue to blur. It’s important to remind employees of what information is appropriate to share on social media about your company. Communicate these guidelines clearly and regularly so there is no confusion about what can and cannot be shared.

 For your eyes only

Using whiteboards for brainstorming and planning is very common. And it’s understandable why. It provides a large space to create a visual representation of your thought process. These whiteboards are typically in common areas like conference rooms, and ultimately are visible to passing individuals. In open office environments, it can be very easy for someone to take a quick peak at information that isn’t meant for them. What’s more, with visitors cycling in and out, it can be very easy for someone to uncover confidential information without even searching for it. How many times have you walked into a meeting with leftover notes scribbled on the whiteboard from a previous group? It’s important to remind employees that a level of confidentiality exists both internally and externally. Therefore, it’s important to ensure confidential plans and schematics are not displayed in a way that leaves them open to a passing glance, and that sensitive material is erased from white boards in conference rooms when meetings conclude.

Making these items a part of your company’s standard best practices will help instill it as part of your overall culture of security. As with any security education topic, it’s important to communicate to teams on a regular basis, and to train new team members to keep the standards high for security compliance across the organization.

[su_box title=”About Joe Ferrara” style=”noise” box_color=”#336588″][short_info id=’67764′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Enhance Your Digital Crime and Security Practices Today

March 28, 20249 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}