How Colgate Secures Its Social Media Accounts and Disconnected Apps
Hello, everyone. I'm Adrian Sonabria, host of the Enterprise Security Weekly podcast and founder of the Defenders Initiative. Welcome to this webcast sponsored by Cerby. I have two guests with me today, Alexander Shuckman, CISO of Colgate Palmolive. Welcome to the show. Welcome to the webcast, Alex. How's it going? Good. Good. Also with us, we have Matt Chiodi, chief strategy officer at Cerby. How are doing, Matt? Hey. It's good to see you, Adrian. Good to see you, Alex. Today, we are talking about how Colgate secured their social media accounts and the challenge of managing shared business accounts in general. And I'm really excited about this because this is gonna be a different format from what you're used to if you've come to other Cyber Risk Alliance webcasts. So it's not often that we get a customer talking about how they've succeeded using a vendor's product, which I'm very excited about. I love, case studies like this. And also we're gonna kick off with a, a video here in just a moment. And and then Matt's gonna lead most of the discussion, most of the questions. I might jump in from time to time, but it's mostly gonna be, Matt and Alex show, and and I'll get out of the way. As always, check the blue buttons down at the bottom of your screen there. The first blue button down there, that is your chat button. You can chat with each other. You can share where you're dialing in from. You can ask what those, what all the honking and the noises are in the in the background. And most importantly, you can ask questions there. So if you have any questions as we go through, please ask them, and we'll try to, Matt will try and pull them in, or I'll try and pull them in in the context of the conversation. So don't save your questions for the end, though we will try and take some questions at the end if we have extra time, as well. The other button, you'll wanna check out down there is the handouts button. That's the third button from the left, And we do have one PDF in there, and you're free to grab that, that PDF at any time. And I'll try and remind you as we go through the outro at the end, to grab it if you haven't already. Alright. So most CISOs don't own the social stack, but they own the blast radius when it's hijacked. Social accounts guard brand trust, ad budgets, and campaign pipelines, but they sit outside SSO, SCIM, and your normal governance. That's the last mile of identity. And today, we'll show how Colgate closed it, first for social, then for other disconnected apps. As soon as you lose access to your social media account, you're gonna start losing followers. This really is one of the most stressful situations. My name is Alexander Schuckman. I'm the chief information security officer for Colgate Palmolive Company, and I've been here twenty seven years. Security incidents always seem to revolve around compromising one identity in one specific location, and that really leads to a large overall cybersecurity incident. As I started working in the information security organization, we really put a lot of focus on getting identity right as one of the first key pillars. One of the key differentiators when we evaluated Okta was the scalability of the solution. Having many different solutions in place and having them all have to interact with each other is always a nightmare. Being able to say I have one source of truth, everything goes through Okta, all IDs are in Okta, all applications are managed by Okta, makes the employees life a lot easier, but also on the cyber security side, it makes it much easier for us to defend. Launching Okta at our company was a success because users saw the benefit of having one single place to get access to applications as well as launch those applications. When we try to apply that same identity management strategy towards social media platforms, that's where we started running into a problem. We're talking hundreds and hundreds of accounts. In the past at other corporations, I've seen passwords being managed in Excel. I've seen passwords being managed by agencies at a much higher cost. And I've also seen, you know, brand safety risk as blatant as having a password written on a post it note that's taped to someone's computer. Cerby gives us the ability to manage the credentials and manage the login of anything on the Internet. They are making it very easy for you to click one button within Okta and launch whatever application you're trying to get to regardless of where it is and what it does. We are able to enforce multi factor authentication for our users, as well as we have the audit trail of who logged in, who changed the account. Our security team is much happier. We know that we have the safety through Cerby to ensure that no matter what access is granted globally, that it will be safe. The challenge is big, but the solution is very simple. I found Cerby to be very intuitive very easy to use, very easy to understand. Change management is always a struggle when rolling out a global solution. However, with Cerby, tight integration with Okta and seamless user experience was a key. The tool itself really is a revelation in terms of housing all that information in one secure place. Having a solution implemented with Okta and Cerby helps eliminate risk, and we really don't have the concern anymore, and it's a much easier way to govern these social media accounts. Well, I love that, I love that video. Thank you for, putting that together with your team. And, Alex, where are you today, by the way? You've is that an AI background? Yeah. I'm in New York City today at our corporate headquarters, right on fiftieth and, Park, right across from the Waldorf Astoria for all the people who are trying to figure out where where I am. I love it. I love it. So it's a real background just like this is a real plant behind me on this side. So, the one thing that stood out to me about that video was that, there were a couple things that you you guys called out. But I'm curious from your perspective, like, when did it first click for you that social accounts are identity assets, not just marketing tools? Yeah. No. It's a great question, Matt. You know, I I I think like most security programs, like most security practitioners, you know, we are responding to incidents. We're looking at things from our our SIM, our SOAR, whatever ticketing system you're using. And that's typically what what you're used to. You're not getting involved in marketing. You're not getting involved in maybe some of the digital projects unless maybe they have a tie back to some of the corporate systems. So in our case and probably like many other organizations, the time we first got involved with social media is when there is an incident. And and then they start reacting and say, okay. How can we get back into the account? How do we get how do we deal with this account compromise? Let's involve the the CSO and the security org. Right? So then it follows more of your traditional IR playbook. Like, okay. We have an a system compromise, except in this case, it's not a system managed in your cloud. It's not a system managed in your infrastructure. It's a social media platform. Now you mentioned when we were talking before the call, and and you just kinda hinted at it now that there was there was an incident. Without going into specific details, I'm curious. Like, you mentioned there were a few incidents. Like, what what broke first? What was obvious maybe to you? What what happened? Yeah. I I think this is a good lesson for the audience, and it was a good lesson for me, which is why I I wanna share it. You know, like every large scale corporation, like every even medium sized corporation, everyone's got social media accounts for all of their brands, for their corporate page, even if you're not selling something. Right? You're you're you're selling your company as as a corporate brand. You know, for us, obviously, we have a a large portfolio of products. One of those products' social media accounts got compromised, the content got, removed, and then the attackers started putting posts on there. Well, of course, like every good social media follower, as soon as you start seeing posts that you don't like, you unfollow the account. Right? There's there's no secret sauce here. As soon as you and and think the thing that's really clear to understand is as soon as you lose followers on a social media account, it's very hard to get them back. So, you know, you can maybe get access to that account back, and now you now but how do you retell those followers that you got the account back when they're no longer following your social account? And this could be Facebook. This could be Instagram. This could be and then fill in the blank on, like, the dozen or so social media platforms that are out there. Right? Yeah. It's it's I was looking at some of the research around this, and I've read that about just over half, fifty three percent of account takeovers in general are social media takeovers. And when I've talked to some cyber teams and I bring up, you know, social media, oftentimes, I heard this is one I heard just last week. Someone said I asked them about their corporate socials, and they said to me, yeah. We only have, you know, in house, like like, five people on our social team, so it's it's pretty easy to manage access. And I said, did you have you asked about, like, the agencies that they use? And he was like, what do you mean? And I know that that is often a a huge part Yeah. Of managing that access because agency turnover is so common. Yeah. No. That's a great point. Right? So every company is gonna have corporate communications, investor relations sites, especially if they're public. And and there's a few employees in every company that are responsible for those areas. But then outside of that, like you you like you mentioned, you have maybe subsidiaries or you have other business entities that are contracting with marketing agencies. And those marketing agencies can log on and in less than sixty seconds spin up a Facebook page that says the company name slash country or may even just say the company name, not even identify the country. And that can be across all the social media platforms. So there's no barrier to entry. It's not like even where we're talking phishing an email where they have to register a domain. You don't even need to do that. You don't even need to spend five ninety nine on a domain. You can register anything anywhere you want. And and I think the reality is marketing agencies are doing that. They're doing it supported by some, person at the company, but at the same time, you know, there's no governance there. I was at a dinner the other evening, actually, in not that far from where you are right now in Manhattan. And I was speaking with someone who used to do this work for an agency, and they told me a story that they logged in to Meta Business Manager using their personal credentials, and they saw that they still had access to a former client's account from five years ago. Five years. And they actually had to send an email to their to their friend who still works there saying, hey. Could you please remove this access? Because it's been five years since I've worked there. And this is a this is not, like, just an anecdote. We hear this all the time. And when we look at the research, we know that just about twenty four percent of companies said that they just admitted, like, we don't even have a process for removing agency access when when a contract ends. Yeah. And and it's crazy to think about it. Right? In in a in typical security program, you have a corporate IDP. You have an onboarding and offboarding process that's tied to HR, most likely. And, you know, you're provisioning laptops, you're deprovisioning them. There's that's a pretty standard formula at any type of company. But then you you say, okay. Well, what's that same process for social media? And you get, like, a a blank stare. So and then sometimes maybe you'll get the answer, oh, the agency is managing that. But remember that the agency is is managing the creative, creating content for the social channel. There's probably very little investment on the security side to actually make sure that that's being done in a secure manner. So perfect example that you see all the time in in the agency, it'll be like, oh, there's three people on on the the account. So let's turn off MFA because it's too hard for us to pass that MFA token between the three people. So we'll just secure the social media account with a password, and and that should be good enough until that password either gets leaked or cracked, and then all of a sudden you've lost access to your social media account. Now I know that you got it mentioned in the video, you guys are Okta customers. And so you've you know, for it sounded like at up to that point, you had rolled out Okta for everything in your organization with the exception of social media. Maybe talk a little bit more about why you couldn't manage your you know, using Okta. Why couldn't you extend that access to social media? Like, what what made it different? Yeah. Sure. So, you know, I I think we have a really nice success story. We consolidated many different IDPs and drew it went with one corporate identity provider, which was Okta, and said, okay. Now let that's a simple way for employees to know their their one username and their one password where we enforce MFA. Then we went and said, okay. Let's look at our applications. Majority of our applications were SaaS based applications in the cloud. They supported, modern day authentication like SAML, and, you know, you could easily set them up in Okta. And now you you have a a very simple way for all the employees to access all those, you know, Internet based applications which are using modern day auth protocols. The the problem on the social media side, it would be nice if they supported SAML, but they don't because they were not made for corporations. They were made for consumers, and they were made for individual people to use them. They weren't made for large scale companies even though every large scale company has a Facebook page or has an Instagram page or has a TikTok. Right? You you hinted at it earlier around one of the challenges with with it. So we know from looking at the research, you know, Microsoft said probably two years ago at this point that ninety nine percent of identity tax can be mitigated by having two factor authentication enabled. Right? You mentioned that oftentimes these accounts have two factor authentication disabled. Talk to a little bit about maybe the practical impact of trying to enforce MFA for shared accounts. Maybe talk about some of the challenges you guys had around that. Yeah. So, obviously, none of the marketing agencies or any of the people involved here are doing anything maliciously. Right? They're trying to post content. They're trying to create content on the go typically from a mobile platform because that's the easiest way to create and upload content for social media. No debate there. But then it's very easy to turn on MFA for a person, a mobile device. There's no there's no real way to do that in any social platform to share that one account with five people or six people or one person at a different time. So and then a lot of these ad agencies are also then employing content creators or influencers who then also want to do a channel takeover, an account takeover, and post legitimate content, obviously. But, again, they need to be able to log in from their phone to do that. So the easiest way to enable all these different scenarios is put a super easy password in on the account and then just share it over an unsecure method. They're probably SMS messaging it, which we know is insecure, or maybe they're emailing it, which, again, we know is insecure, and then all and then never changing it. Remember, these social media platforms are not saying rotate your password every ninety days. They're they're making it very easy for passwords to be saved and passwords to stay consistent. So even if maybe you didn't do anything to compromise it initially, Maybe you had an, phishing attack and you had an email compromise, and that's how they got the social media password that was in an email from a year ago. And all of a sudden, that's how they got into the account. It's interesting you say that because that's something that we hear extremely, extremely common. Right? There these these social media accounts are just so often treated as being something that's outside of the IT and security purview. And I'm curious, like, when you guys, you guys have been a Cerby customer now for, I think, close to three years, something like that, two and a half, three years, somewhere in that range. How did you look at it from an ROI perspective? And I know sometimes ROI around cybersecurity products can be, sometimes difficult to measure, but maybe from a soft ROI perspective, from a margin marketing and agency user feel, like, what what did that look like, whether it was faster account switching, fewer lockouts? I mean, I know from our research that we've looked at that social media managers often say they lose ten hours plus a week having to navigate access issues across platforms. So even that's you know, even a small usability wins add up first. How did how did you look at that? Yeah. So, I mean, obviously, we took a security mindset when we went and got involved in how to secure social media accounts. So from a security mindset perspective, we said, hey. We wanna secure the the authentication, and and that that was our goal. So that's how we justified Cerby from from a security perspective, plus it was tightly coupled with our Okta, like you guys saw in the video. So it made simp, easy sense. That that that's a tough ROI because, really, everything we do is cost of business. It's security. Right? It it's not it's not generating revenue. It's not selling more toothpaste. But then flip the the script onto the other side of our business, which are the people actually running our business in the marketing sales and and and go to market areas. Right? They we have we have many different brands that the that individuals are are managing, and they are constantly switching between accounts. So you're in a digital marketing space. You may be responsible for three or four different brands, and you may be responsible for maybe ten different social media accounts across Facebook, TikTok, Twitter, you you name it. Right? Any of the socials. So for them, it it was a very difficult user interface. You logged in from a browser or from your phone, and everything was fine until you need to then log out of that, switch to brand two, then do that again to brand three. And each one of those, you had different passwords, you had different MFA if you wanted the the native social account to be secure. So now what what did they do? Then, of course, the easiest way to to do all that is put it into a spreadsheet or some other insecure method and or turn off MFA like we mentioned before. So it it's a it's a hard thing, and they're just trying to do their job. They're just trying to post content and respond to to posts. Right? So once we put Cerby in, then we showed them, okay. You log in to Cerby using your Okta credentials, so no new credential, the same credentials you're using to get to every other corporate application you're using every single day like email. So no behavior change for them. They go to Okta to e access email. Now they go to Okta to access Cerby. That's one click for them. Once they're in Cerby, they had a little tile to click for each of their social media accounts. So, again, we made it very similar to what they already knew. When they go into Okta, they click the tile to open up their expense report. They click the tile to open up their HR. When they logged in to Cerby, they just click the tile to go to this country's Instagram account or this country's Facebook account or this country's TikTok. So they didn't need to know anything. All they needed to know was click on the tile associated to where you wanna go. And then when you need to go to the next account, just click on the next tile. So it was a very big time saver when people have to switch between social media platforms or switch between brands on social media platforms. It was a huge time saver, and I think that's the ROI. You're you're really having a marketing person more focused on digital marketing, not on how to log in securely. So it sounds like there's two pieces to that. There's there's a business continuity part of it, but there's also the user experience, which is something that oftentimes in cyber, we're not primarily focused on, but it sounds like that that these two pieces were in play. Right? Because I'd imagine that, you know, you got you mentioned that you guys had several hundred you have several hundred social accounts. You have a team internal in house, but you also have agencies that are also doing the same thing, like maybe managing multiple multiple of your brands. They're constantly having to switch. But then you're also changing agencies. Right? And then trying to manage, okay. This agency rolled off. We brought on this new agency. There must have also been just a level of complexity that your social teams were dealing with before Cerby that I would imagine some of a lot of that went away after deploying Cerby as well. Yeah. So, like, the the perfect example at each of your companies ask your your digital marketing team how many social media accounts they have. They'll most likely pull out a spreadsheet or they'll rattle off a a couple. You know? Fast forward to after you've and then you know that list is probably incomplete or outdated as soon as you you save the spreadsheet. You know? After you implement Cerby, you ask that same question. They'll just log in to Cerby and and look to see. Now you know instantly the last login for each of those accounts, who logged in to them. And then if if agency a had three people, you don't have to worry about, did we onboard or offboard those three people? You just follow your standard onboarding and offboarding that you've already created with your corporate IDP, and there's no new offboarding steps for social media. So you're never gonna lose access to a social media account as people change roles. Everything's managed by survey. Everything's in one place. You never worry about losing access to your HR system because you say, oh, it's managed by Okta or it's managed by some corporate IDP. But how how can you allow a social media account to to be lost? You know, that, I think, is one of the big ROIs is, you know, how much time are you gonna spend? Once you lose access to a social media account, there's no real help desk for getting it back. There's no, you know, there's no contract that you have with each of the social media platforms. You have to follow the same workflow that a consumer follows when they lose access to their account, which is frustrating. So now even though maybe you have millions of followers and you and your brand is very popular and you have tons of content on there, as soon as that account gets compromised or someone leaves from the agency and now you've lost access to that account, the the the ROI is really how much time is wasted to get back into that account so that you can own it again. You know, that's a that's a good solution that you probably wouldn't really have thought of initially when you're implementing Cerby to really protect social media. I appreciate that from a from a business continuity standpoint. We again, I think post COVID, social media became just such a critical part and during COVID became such a critical part of how businesses communicate with their consumers. And I think it's easy to to to get lost on that point just realizing the complexity of managing all that. So there's that there's that business continuity component. The one thing that also stood out to me in the video was there was there was two individuals that were not in IT. As far as I could tell, they weren't in on IT. I think they were part of your marketing, your social team. And you and I were talking, probably a couple weeks ago just about how, you know, oftentimes when when security deploys a new tool, a lot of times it's met with a lot of resistance. Like, hey. I already have a way of doing this, and now you're wanting me to change essentially my workflow. Maybe talk a little bit about, like, the turnaround story, like, you know, the skeptic who became the power user. Like, what flipped that switch for them? Yeah. And so, like, a perfect example of that and and most of the audience are are most likely cybersecurity or identity people. You're you're rolling out a solution. And if it works, the the business user never sees it, or there's very little interaction with the business team, beside maybe logging into the system or or getting an alert from the system. In this case, Cerby's the exact opposite. Right? The the the business team is heavily involved and heavily using the tool because it's also their inventory of social media. It's their usage. If they want to if your digital marketing person in global wants to know who is using the Italy account, they can see that in Cerby. You you know, that that gives them more of the accountability of who's using the accounts in their company, and it really helps them understand it. It's also you have skeptics like you mentioned, Matt. Hey. I've been doing this for a long time. We haven't gotten hacked yet, so we must be okay. That's a that's a one of my favorites. Right? But then you show them, okay. This is how Cerby works, and look how easy it is to jump between account a, account b, and account c. For someone who's a power user and has been doing it their own way and basically sees how easy it is to do it in Cerby, they're like, oh my god. That's such a great time saver. Also, it gives me visibility into what everyone's doing. So when we rolled out Cerby, we didn't roll it out as an IT tool. We sent out a communication from our digital team, not from IT, and said self-service enroll your social media account. You know, the kinda the opposite of IT. IT is always like, hey. We're gonna deploy software to your machine and and, you know must. And and you must use it. Yeah. This was, hey. If you wanna make it easier to manage your social media, enroll your account here. Obviously, they had the credentials to the social account, which is why we needed, them to enroll it for all the existing ones. But then for all the net new, we made it very easy for them to enroll Cerby from day one of a social media account creation going forward. And that really made it a very smooth rollout because it was really business driven and business led, and the business teams could see the progress, log in to Cerby and see how many accounts are there. And there were a hundred yesterday, and there's a hundred and five today, and then you can easily watch the progress. You can really get away from your static spreadsheet and say, hey. I know all the social media accounts, and I also know who's logging into them from which agencies and which social media accounts have not had any logins for a long time. So Cerby helps you really easily govern all that and do it in a very secure manner. Maybe that agency person you only use for two weeks. You giving in the old world, you would give them the password, and then no one's remembering to change that password. That person leaves from the agency. Like your example, he's still he or she still has the password to that social account. In Cerby, as soon as Cerby's managing the account, the instant that agency person logs out of the account, Cerby auto rotates the password, and now the social account is protected. Well, security people are like, yeah. That's obvious. Our PAM solutions have been doing that for years. But ask a digital marketing person how many times they autorotate the password themselves manually. The answer is zero. Right? I don't think we would do it manually either. Right. Right. I appreciate that. So Robert asked a good question in the chat. His question was, like, what's what was the agents agency experience like in with respect to them, get connecting with Cerby and onboarding? You mentioned that for for Colgate employees, I think you were saying they were self registering these accounts. What was the what was the feedback you heard around the agency experience with respect to Cerby? Yeah. So for for our organization, you know, a lot of our interaction with the agency is sharing a lot of documents, sharing a lot of creative, interacting very closely with them. So we have a lot of corporate systems that we use on on that side of the house, like a digital asset repository or something to that effect. So they already had access to our systems because we were working with them as an extension of our own organization. By by implementing Cerby and tying it to your corporate IDP, Okta in this case, it was the same experience for the agency as it was for the employees. Oh, it's just one other square in Okta that you click and launch Cerby, and here's all the social there. Oh, okay. That's fine. Like, that was the whole training. There was no more training. It's not like you had to to explain to an agency person how to use the tool different than how the employee like, even our own employees could teach our agency teams how to use it because it was the same tool they were using. So I I do think that was really powerful is we're giving a really seamless experience, not here is how you do something as an employee, and it's completely different with a third party marketing agency. I love that. I love that. Now one of the things that we, we talked about in the, in the preshow part of this was just about how you guys started with social media. That was kind of your original use case. But at some point, you realize that this, you know, what we're call a disconnected applications, they're disconnected from your from your Okta, from a SailPoint or whatever someone might be using for IAM and IGA. You realize that this challenge wasn't just limited to social. There were other disconnected apps that surfaced. Maybe talk a little bit more about Yep. You know, what did that look like for you guys? What was that process like? Sure. So it was a hundred percent like you heard. We we brought Cerby in to solve a problem for social media, and that was our key use case for what we needed to solve. But then once we understood the technology and once we understood the platform, we saw, hey. There are other applications that are used within our company, many of which are not modern day apps. They're not SAML based. And we said, how do we manage those? We don't wanna keep a username and password associated to that individual application. The answer is really, well, Cerby can manage those accounts as well and the access to those corporate applications that are not using modern day auth. And that's another great way to say, well, we already have a corporate identity. Can we extend that to systems that are not supporting corporate IDP or SAML? And then you can also close audit findings associated to, are you managing credentials? Are you managing onboarding? Are you managing offboarding? Are you implementing MFA? All the modern day authentication security measures automatically come along for the ride because Cerby is tied to your corporate IDP. That's really powerful. I think, you know, when you think about this kind of this this broader world of disconnected applications, you know, based on our research, we looked at the top ten thousand applications that were used in the enterprise, and there are way more than ten thousand. I think last time I checked, there was, like, thirty plus thousand. But just looking at that top third of apps that are using the enterprise, we know that it's only about fifty two percent that support the SAML standard. Right? So the vast, you know, forty eight percent or so of applications do not. And we know that the average organization has somewhere in excess of a hundred disconnected apps. And, you know, depending on where someone sits on the on the size of the organization, if some if an organization's been around for a while, that number of disconnected apps is larger. Although we have some customers that have, you know, been in business for only ten years, and they've got hundreds of these. You know, maybe, Alex, from your perspective, one of the questions that I often get is, you know, if someone is either either not in the identity space or, you know, maybe they just haven't really researched the disconnected app challenge, one of the questions I often get is just like, what are, like, what are some examples of of these applications outside of social that are disconnected? So maybe talk a little bit. You don't have to mention specific apps, but are there specific, you know, categories where you see that federation isn't always possible? Yeah. So I think it's a great point, and it's not something that intuitive. I mean, some of the solutions out there on the security vendor ecosystem help you find shadow IT or or, you know, unsanctioned app, whatever, you know, buzzword terminology they want, but they don't really tell you how to fix the problem. They tell you where your problem is. Right? I I think what's really interesting, and and the use cases we saw from Cerby perspective was, hey. Look. You have m and a. Every company has m and a going on on a merger or an acquisition, and you inherit the applications that that that company has. You can't, you know, day one after an m and a replace all their applications. Right. You know, that's a great use case for Cerby that that that company you're acquiring or merging with may have a a an HR or a finance or an order to cash or some type of marketing system that has been around for many years. It's most likely on premise, and and it may or may not support modern day auth. Cerby is a great example where you can say, hey. We can easily integrate that to our platform while we take the time to evaluate a replacement or or how to merge it with our existing systems. The the other one are, you know, you have a lot of global apps, but then there's always local apps. Every market needs some specific app. Maybe the the one that I'm thinking of is you have HR requirements in in a specific division that's different from your corporate. That that app probably has been contracted by a regional business owner, and they don't know to to integrate it to a corporate IDP. Or maybe because that's a regional application, they don't even support SAML. But it's a core business process. It's an HR system. It's a finance system. It's a payroll system. A lot of local payroll systems are mandatory for that country, and we can't just go in and say, hey. We can replace your payroll system in five minutes because there's legal reasons they need to use a local payroll. But at the same time, payroll is important. You wanna have secure authentication into that system, and Cerby can help do that. Yeah. We see this a lot with you know, one of the questions I often get just just yesterday, I was in New York talking to an audience about this. One of the questions I often get is, like, what are these apps? What do they look like? And you're right. They oftentimes, it might be a specific application that's used by maybe a part of your line of business. There's something specific to the vertical that you're in. Oftentimes, people, they get they think of, like, what I would call, like, a tier one SaaS app, like a three sixty five, and we're like, no. That's that's not what we're talking about here. We're not talking about Salesforce. We're not talking about those tier one SaaS apps. They support all the standards. They support SAML. They support SCIM for the joiner, mover, and lever workflows. We're talking about either applications that are they could be legacy. They could be on prem, or they could just be some third party app that, for whatever reason, does not support SAML for single sign on or SCIM for joiner mover and lever workflows. Those are the disconnected apps that we're that we're that we're talking about here, and that's squarely where, Cerby plays. In fact, the other question I often get too is just like, hey. Are you guys, like, I already have an Okta investment or I already have a Saviant or SailPoint or an Entre. Are you competing with them? And what I say is like, no. No. In fact, we actually have we're partners with each one of those companies because we help them extend their core capabilities to this whole group of applications that out of the box they they can't support. So for a customer that's coming to Cerby, what we usually say is like, hey. This is an investment in Cerby helps you realize a better and higher ROI on your existing identity investments because now you're getting complete coverage as opposed to just covering maybe sixty, seventy percent of your environment. Yeah. A great example that probably people are not thinking of and are not managing, but I guarantee exist in any multinational corporation. You have individual local country government websites where you have to do submissions. Maybe it's a tax submission. Maybe it's a sales submission. Maybe it's some audit submission. Obviously, those are regulatory requirements of that country, but at the same time, there's some login associated to that. It's obviously not a modern day, SAML based application, and you can't ask a government entity to integrate with your corporate IDP. Good luck with that. Yeah. So you can put Cerby on top of that. You can secure it so you're onboarding, offboarding, move reliever, joiners is all good. And you really don't want someone who's not authorized from your company to be doing submissions. You know, that those are not use cases we would have ever thought day one that we would use Cerby for. Nobody's telling us to solve that problem. But then after you understand, oh, Cerby can do a lot of different things, you go, maybe it can help me with that government tax submission I do once a year in some LatAm country. I can put Cerby in front of it and then give access to the tax department who already have access to Okta and now can jump into Cerby and then launch that portal in a secure manner. So for our for our audience, the hundred and thirty plus people that are listening right now, which I imagine is gonna be a mix of security practitioners, those that are hands on, some security executives. What would maybe be the first move you'd recommend? Like, what should what should security teams be asking their marketing, their comms teams today? How would you start that conversation? Yeah. So I think it's a good opportunity for security practitioners. It's probably not an easy conversation. It's probably not like, hey. I'm rolling out a new AV or rolling out email protection. Those are obvious ones. It's more go to your digital organization if you have a chief digital officer or you have a digital marketing lead and say, you know, how are you protecting social media account compromise? And and, you know, I think in the news, lots of people have seen celebrities' accounts getting hacked and fake posts being put. So it's not an unknown from from a a happening perspective and say, well, is there an appetite for us, meaning the security team, to help you govern it? Not to take it over, not to manage it and put a bunch of bureaucratic red tape in front of it with a request process, but help you secure it, but still let you manage the day to day. We're not we're not trying to manage the day to day like we do in maybe other corporate systems. We we don't wanna be involved in that day to day process because it is very fluid and the marketing team own it. We don't know what agencies you're using. We don't know who is supposed to do that. Keep that responsibility where it lies today. Just make it done in a more organized fashion. If you ask that question and your digital lead says, yeah, that sounds like a good idea, then I think you you have an an appetite. Or even just ask an even more simple question. Do you know all the social media channels we have in the company? Appreciate that. I know one of the things that's we we alluded to this a little bit earlier. It's oftentimes in security and IT, we're trying to push something out. We get pushed back. And I think a lot of times it's not even necessarily the tool itself. I mean, it could be, but a lot of times it's it's how we do it. And, and like you said, like, if there's a way and it's always the best way to partner with the business with it where they're the one driving it. Like, I think you'd you're probably the same thing. Right? Like, the impact there is so much greater, the adoption of it as opposed to someone who's a, you know, quote, unquote, outsider pushing it in. I'm sure it sounds like you guys use that same approach. Yeah. And it's very visible if you lose access or your social media account gets hacked. Right? You're gonna get noticed. It's social media. You're gonna get press articles about it. This isn't like an internal issue that you can have within your four walls of your company. It's on the Internet. You're not gonna want the brand reputation hit. So for a very simple implementation, you can avoid having that very unpleasant brand reputation hit. So last question for you, Alex, is, like, if you had to you know, if you could go back in time or if you, you know, had to roll this out again, talk to me a little bit talk to the audience a little bit about what playbook would you would follow, like sequence, stakeholders, milestones. Maybe just sum that up for us. Yeah. I think we took a a very, simplistic approach. We we sent out global communications to say, hey. We want everybody to adopt Cerby, and here's the self-service process. And then we got good adoption. So, you know, if you have a good network already established on your digital marketing side, then it should be a very relatively easy process for rolling out. You know, if you don't have a and and maybe some of the security people haven't worked much with digital marketing, find the IT team who is supporting them. There's some IT team managing websites and content management most likely. Those are the people who can help you bridge the gap. I love that. I love that. This is super, super interesting conversation. And I think, from my perspective, this is there's a lot to learn here. We still have a couple minutes. If there's questions from the audience, I know that I've been answering some of them in in a form of a stream of consciousness while we've been kind of going through those. But if there's questions, we'd love to take those now if you want to drop them in the chat. Otherwise, we'll wrap things up, but would love to answer any questions right now. Alex, thanks. This has been super helpful. I know I learned a lot just hearing directly from you, but this is it's been fun. Any anything I should have asked you that I didn't? I guess I'll leave maybe that's the last question there. No. I'd say take take a look at it. At the very least, you can learn more if you're especially if you're a security practitioner, this is probably not an area you've investigated. I love that. I love that. Adrian, I I can't Yeah. I can't see you, but I can hear you. Yeah. Yeah. I was asking, I I said put me in, coach. Was trying to get Jerry's Jerry's attention. Yeah. It's, I I I've been listening behind the scenes and and commenting in the, in the chat as well. And, and, yeah, you you saw one question I had, it seems, Alex, like, kind of a like, maybe it's easy to justify the ROI since there is kind of a a painful problem that a lot of these teams have where they have to share these credentials and, you know, they're logging out and back in. You know, it is, in your experience, is is that enough to does that help to to sell this, to the team to you know, not only is this gonna make it more secure, you know, but but you're not gonna have to constantly sign in, sign out if you have multiple accounts on one platform, for example. You know, just the streamlining of it, does that does that help, sell the ROI on this? Yeah. So, I mean, I'll I'll give you a very honest answer. You know, I'm not a big ROI fan. I'm a big fan of doing what's right, and I think this is the right thing to do for your company. We're security practitioners. Our job is to protect all the company's assets, not just the ones that are corporate systems that we say that we manage. Like, these are part of our company. We should have them as part of our security program. Right. Right. But it couldn't hurt that you're you can also solve a workflow problem and make things less painful for people. Right? Yeah. There's a lot of there's a lot of icing on the cake. Yeah. Oh, god. Also, maybe you mentioned it and I missed it, but, you know, I'm curious, you know, because people come into products like this from different perspectives. Like, obviously, like, I could think as long back as the Obama administration, like we saw the Associated Press, lost control of their Twitter account and people posted, you know, there was an explosion at the White House and then the whole stock market dips. Right. You know, so we've been seeing this for a while. Is this something you had been looking for? You know, you've been at Colgate for a very long time. And then when you started to see companies providing this, you, you contacted surveyors. Is this one of these things where you're like, you know, talking to your peers and like, man, I wish there was something that would solve x for me. And somebody says, oh, there is. And like, how did you find out about it? When did you really start looking for something to solve this problem? Yeah. I mean, we we had we were aware of the issue, and we were not aware of a solution. And I think the corporate IDPs of the world, it's like the Okta, Intra, Pings. Right? This is not their wheelhouse, and they would agree there. So I work with a lot of venture capital firms, and one of those venture capital firms was Okta Ventures, and and they're the ones who who who mentioned this solution. And I'm like, oh, that sounds like a a good solution. Let me take a look. Awesome. I I wanna cede some of my time to Robert who had a good question in the chat there. Matt, if you wanna pull that pull that out. Yeah. Absolutely. Absolutely. So Robert's question is maybe talk a little bit about, has to do with, you know, it says, can you talk us through how you circle back with social media counters to make sure that unnecessary access has been removed? So that's the question. I think it's a question of, like, how do you if the if the marketing teams, your social teams are still managing access even though it's through Cerby, what's that process like to make sure that only the right people still have access? How did you tie that back to your normal access management process? Yeah. So I I think the key difference here, and it's slightly different than your corporate systems, your your your IGA based ERPs or, you know, HCMs or something like that. This is social media. The the people who are managing who has access to a channel or an account are the digital teams that own that channel or account. So we delegated that responsibility to them, and they manage who has access and who doesn't have access directly in Cerby. And the nice part about that is it's not like you're telling them use an AD group or use an email group or to come to IT and we'll set something up or put in a ServiceNow ticket, and we'll tell you in two weeks when it's done. Right? That that there's nothing more frustrating for a business person than going through IT and waiting for us to fulfill a request. The the best way to to really get rid of any of that bump in the road is let the people who know who should have access govern it, and and Cerby makes that really easy for both employees and and and third party agencies. So, you know, we didn't want to take that ownership. We we wanted the ownership to stay in the people who own the act in the responsibility for that area. The nice part from a security perspective is we have full visibility to all that, so we can also be a governance layer or a a secondary set of eyes there, but but we don't need to be the first line of administration there. Yeah. That's that that's awesome. And that's, you know, I I saw a survey a cup month or two ago where they're saying, the average I think I think it was, seventy, eighty percent of companies, can't get an employee the access they need in in less than, seven days. Right? You know? So almost a business week and a half, You know? So that that kind of governance process and how long it takes to to both, grant and revoke, you know, maybe that's part of it. You know? It makes a lot more sense to, decentralize some of that. Exactly. Yeah. Well, Matt and Alex, this was amazing. Loved this discussion today. A very neat format too. Loved kicking it off with the with the video. Covered a lot of good ground. I I didn't realize it was gonna go beyond social media accounts, that gave me a lot of ideas, you know, different ways that you can use a product like this. So, yeah, thank you so much for this. This is great. This is fun. This is fun. Thank you, Alex, as well. Thanks, Adrian. Take care, everyone. Thanks for the time. It was fun. Yeah. And thanks to our sponsor, Cerby, for making today's webcast possible. And then just a final thanks to the audience for joining us. Reminder that there is a handout in there. It's a quick two pager on what Cerby does. You know, very concise, very clear. And, thanks for all the great discussion and engagement and questions today. We'll see you next time. Alright. Thanks, everyone.
When a global brand's social media accounts get compromised, it's a security incident, not just a marketing problem. Social accounts hold brand trust, ad budgets, and campaign pipelines, but they sit outside SSO and SCIM, so they fall to the security team without the identity controls other apps get. In this webcast, Colgate-Palmolive CISO Alexander Schuchman explains how Colgate secured its social media accounts with Cerby on top of Okta, then extended the same governance to more than 100 other disconnected apps.
Why are social media accounts a security problem, not just a marketing one? Social accounts carry brand trust and ad spend, and a takeover becomes public fast. But most CISOs don't own the social stack, and social accounts sit outside SSO and SCIM, so they miss the identity controls applied everywhere else. That makes them one of the most exposed assets a brand has.
Why are social accounts so easy to take over?
- They're shared across employees and outside marketing agencies, often with one password.
- The platforms don't enforce credential rotation, so passwords linger for years.
- Access rarely gets removed when a person or agency moves on.
- A large share of account takeovers target social media specifically.
How did Colgate secure its social media accounts? Colgate put Cerby on top of Okta. Marketing users log in through Okta, then open each social account from a tile in Cerby without ever seeing the password. Cerby rotates credentials automatically, removes shared passwords, and ties every account to the corporate identity provider, so offboarding a person or agency removes their access with no extra steps.
How does this extend beyond social to other disconnected apps? Once social was under control, Colgate found more than 100 other disconnected apps, the apps that don't support SSO or SCIM, that had the same problem. Cerby governs those accounts the same way: automated joiner, mover, leaver workflows, credential control, and audit-ready records, all on top of the identity stack Colgate already runs rather than replacing it.
What's the lesson for other security leaders? Treat social accounts as identity assets and bring them into your security program. Inventory every account, put them behind your IdP, and automate offboarding, before a takeover turns into a public brand-reputation hit.
Presenters
Alexander Schuchman
CISO
Colgate-Palmolive
Matt Chiodi
Chief Strategy Officer
Cerby