Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Securing Social Media – A Critical Step For Robust CNI
Articles

Securing Social Media – A Critical Step For Robust CNI

Shay NahariBy Shay NahariSeptember 27, 2018Updated:December 30, 20214 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

An IBM research team recently warned that a hacker could easily manipulate emergency systems to get rid of protections or dissemble alerts to warn people of catastrophic events. This has huge implications for the security of our critical national infrastructure (CNI) such as traffic monitoring systems, flood defences and radiation detection.

The security threat to our critical national infrastructure (CNI) is becoming a worrying reality. Take the recent erroneous alerts regarding potential missile strikes that caused mass concern in Hawaii and Japan. These should serve as a reminder to immediately evaluate the cyber security procedures used to protect these emergency warning systems.

Forgotten passwords causing chaos

In the case of the fake Japanese and Hawaiian missile strikes, both alerts can be traced back to employee error. In the Hawaii case specifically, the false alarm was sent out via Twitter. This case was compounded by the fact that the governor forgot his Twitter username and password and could not log on to fast enough to provide the public with accurate information. As social media becomes an increasingly more popular way to disseminate information with the general public, and as CNI attacks potentially start to grow in frequency, all government officials who use social media must re-asses how they are managing these accounts to  ensure that a forgotten password does not delay crucial communications .

Social media platforms such as Twitter, for example, must be hardened to prevent hackers from hacking into these accounts to spread false information – a clear possibility in today’s threat landscape.

Clever attackers realise the power of communication platforms and have targeted social media accounts to plant false information over the years. Take the case of the false tweet sent from the US’s Associated Press Twitter handle. This resulted in a $136.5 billion drop in the S&P 500 index’s value in minutes.

Re-thinking social media security

When we think of CNI we think of power stations, traffic lights and water mains. But it must go one step further than that. Government-related social media accounts used for current or sensitive communications should be considered as CNI, held to the same cybersecurity best practices as the energy, transportation and chemical sectors.

Government social media accounts — like Twitter, Facebook, YouTube, LinkedIn and more – are often  shared accounts. This means that teams of people within an agency have access to and can post information to them. The passwords for these accounts are commonly shared internally among team different team members.

This makes social media  a very easy target for attackers or malicious insiders. The shared nature of these accounts also means there is no record kept of who posted what when – this is where we can quickly run into trouble. To add to the issue, passwords used to “secure” these accounts are rarely changed and typically used across multiple accounts.

By bolstering the security measures for these accounts, organisations can be safe in the knowledge that a simple forgotten password doesn’t hold up critical communications, while also strengthening these platforms against external hacks.

To thoroughly secure and protect social media accounts, agencies must undertake best practices for privileged account security, including:

Eliminate shared credentials: Storing passwords in a digital vault requires users to login individually for access, eliminating the accountability challenges of shared credentials

Ensure transparent access: Authorised users must be able to seamlessly authenticate to an account without knowing their passwords, making it harder for hackers to uncover and steal credentials. This kind of access would have given Hawaii’s governor immediate access to his account to confirm that the missile alerts were false.

Audit account activity: By creating a record of activity on social media accounts, all posts can be traced back directly to an individual authorised user, making it easy to identify employees who may be posting harmful content.

Automate credential changes: Changing privileged credentials ensures attackers can’t use old passwords across systems. Automating password changes regularly also updates access privileges, reducing the chance of an outsider stealing and using a valid credential.

The false alarms in Japan and Hawaii highlight the huge amount of trust that the government, organisations and civilians place in social media as a reliable and trustworthy means of public communication. They’re also prime examples of what can go awry when these trusted social sites aren’t managed properly and securely.

The incident in Hawaii needs to motivate agencies to safeguard against these same avoidable mistakes. Crucially, it’s a call to action to proactively protect social media against threats both nefarious and accidental. This will be of the upmost importance  in the age of rising CNI attacks and as the public ‘catch on’ to their worrying consequences. This is only the beginning.

Shay Nahari

Head of Red Team Services

  • Shay Nahari
    Anatomy Of A Red Team Exercise

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}