New Ponemon Report: The Hidden Security Threat of Disconnected Apps | Download Now

How Colgate Secures Its Social Media Accounts and Disconnected Apps

When a global brand's social media accounts get compromised, it's a security incident, not just a marketing problem. Social accounts hold brand trust, ad budgets, and campaign pipelines, but they sit outside SSO and SCIM, so they fall to the security team without the identity controls other apps get. In this webcast, Colgate-Palmolive CISO Alexander Schuchman explains how Colgate secured its social media accounts with Cerby on top of Okta, then extended the same governance to more than 100 other disconnected apps.

Why are social media accounts a security problem, not just a marketing one? Social accounts carry brand trust and ad spend, and a takeover becomes public fast. But most CISOs don't own the social stack, and social accounts sit outside SSO and SCIM, so they miss the identity controls applied everywhere else. That makes them one of the most exposed assets a brand has.

Why are social accounts so easy to take over?

  • They're shared across employees and outside marketing agencies, often with one password.
  • The platforms don't enforce credential rotation, so passwords linger for years.
  • Access rarely gets removed when a person or agency moves on.
  • A large share of account takeovers target social media specifically. 

How did Colgate secure its social media accounts? Colgate put Cerby on top of Okta. Marketing users log in through Okta, then open each social account from a tile in Cerby without ever seeing the password. Cerby rotates credentials automatically, removes shared passwords, and ties every account to the corporate identity provider, so offboarding a person or agency removes their access with no extra steps.

How does this extend beyond social to other disconnected apps? Once social was under control, Colgate found more than 100 other disconnected apps, the apps that don't support SSO or SCIM, that had the same problem. Cerby governs those accounts the same way: automated joiner, mover, leaver workflows, credential control, and audit-ready records, all on top of the identity stack Colgate already runs rather than replacing it.

What's the lesson for other security leaders? Treat social accounts as identity assets and bring them into your security program. Inventory every account, put them behind your IdP, and automate offboarding, before a takeover turns into a public brand-reputation hit.

Presenters

Alexander Schuchman

Alexander Schuchman

CISO

Colgate-Palmolive

Matt Chiodi

Matt Chiodi

Chief Strategy Officer

Cerby

Ready to extend your identity perimeter
further than ever before?