Social network subversion and the consumerization of IT

happygeek 0 Tallied Votes 348 Views Share

According to reports the most serious forthcoming threats to IT security will be revealed during the Gartner Security Summit in Washington this coming week, and it looms like the consumerization of IT will be right there front of stage. Something that Gartner research fellow, John Pascatore, describes as the Gen X - Gen Y problem. In other words, the users who have grown up with a social networking model as the norm being expected to follow an old school approach to IT security which dictates what resources you can use and when and where you can use them. But with the social networking model spilling over into the enterprise, it is almost inevitable that a new generation of threats will emerge that demands a new generation of security thinking.

As Pescatore puts it “the old IT model that tells you what you can do and use is breaking.”

So what is being done to fix the problem, what are the threats that will emerge and how can you protect against them? Unsurprisingly Gartner is not revealing too much of the new security threat landscape ahead of that security summit next week, however Pescatore has given Dark Reading some clues. "Among the main threats on Gartner’s list: attacks on SaaS providers, social network subversion, and desktop utility application attacks" the security site .

SaaS seems to be the main focus from what I can read between the lines, with Gartner expecting attackers to "streamline their attacks on organizations" with Saas being a good example of shared application types that could be exploited in this way. “The attacker could go after Proctor & Gamble -- or salesforce.com, which P&G uses, as well as hundreds of others” Pascatore says.

Gartner is also likely to look at social network subversion, leveraging the trust angle of social networks to launch attacks while posing as a friend. Attackers have always exploited trust, so there is no real reason to assume they will exploit trust based networking mechanisms to the full after all.

Dani AI

Generated

Good call, — the consumerization-of-IT problem you describe is exactly why defenders need to stop thinking only in perimeter terms and start thinking identity- and service‑centric. Humans remain the primary “front door” for breaches (phishing/social engineering and mistakes), so whatever social model users bring into the enterprise flows directly into the risk picture. Verizon DBIR 2024 overview. (verizon.com)

What to watch for today: consent/OAuth‑style phishing that tricks users into granting attacker-owned apps access to mail/files; malicious third‑party social apps or bots that propagate links; API misconfigurations and exposed endpoints in SaaS that leak data; and compromise of a SaaS provider or shared tenant leading to broad impact. OWASP’s API Security Top 10 and multiple Microsoft incident writeups document those exact vectors. OWASP API Security Top 10 (2019) · Microsoft on consent‑phishing and malicious OAuth apps. (owasp.org)

Practical, immediate controls that scale with user freedom: require SSO + enterprise MFA for all SaaS; block or allow‑list third‑party OAuth apps and use conditional access for risky sign‑ins; adopt SCIM/automated provisioning so offboarding truly removes access; deploy a CASB or central telemetry to see shadow SaaS and revoke suspicious tokens quickly; run phishing simulations focused on consent prompts. Microsoft’s cloud security benchmark maps these identity‑centric controls to concrete steps. Azure security benchmark — identity guidance. (learn.microsoft.com)

Finally, treat SaaS like supply‑chain risk: require vendor security evidence, logging/audit access, incident response SLAs and attestations, and include SaaS in regular risk assessments and tabletop exercises. NIST’s supply‑chain guidance is a practical playbook for that work. NIST SP 800‑161 rev.1 (C‑SCRM). (csrc.nist.gov)

Short, tactical wins plus identity‑first architecture will let organizations keep social workflows without handing attackers an easy path.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.