Friday, December 17, 2010

Firing An Employee Bad Mouthing the Company on Social Media? Better Think Twice.

As more and more employees lose their jobs for reasons related to social media, more and more social media-related lawsuits fill dockets across America’s courts. Individual, class and union actions have employment law and technology experts paying close attention to these cases to determine the future landscape of social media within the workplace.

According to attorney John R. Lanham, in the January 2010 edition of Morrison Foerster’s (mofo.com) Employment Law Commentary, “employees’ online communications may gain legal protection based on either the privacy or the substance of the communications.” Mr. Lanham’s article brought to light two very real risks for organizations: 1) the growth of social media-related lawsuits; and, 2) current and developing legislation intended to protect employees from employment-related actions on the basis of things said on social media platforms.

In Pietrylo, et al. v. Hillstone Restaurant Group d/b/a Houston’s, two employees of a Hackensack, New Jersey Houston’s Restaurant successfully sued their former employer in an unlawful termination case that stemmed from the employees’ use of social media to disparage the restaurant and its management. In this case, the two employees were terminated for establishing an invitation-only MySpace page for the purpose of allowing employees to vent their dissatisfaction with their employer. Those invited to join the group were existing and former employees – none of which included management.

Management eventually became aware of the MySpace page through an employee that belonged to the MySpace group. The employee provided management with the login ID and password to access the invitation-only MySpace page. In response to the derogatory information posted on the MySpace page about Houston’s management and the company, the two employees that created the MySpace page were terminated for violating the restaurant’s “core values.” The two employees sued Houston’s in federal court and received a favorable ruling in June 2009 when the court found that management had violated the federal Stored Communications Act as well as a comparable state law. The violations were based on the manner in which management gained access to the site. According to the court, the employee that provided management with the user ID and password was perceived to be under duress and feared retaliatory action by management if the user ID and password were not provided.

In another case in October 2010, the National Labor Relations Board (“NLRB”) filed a complaint in Connecticut against American Medical Response of Connecticut, Inc (“AMRC”). The complaint alleges that AMRC violated the National Labor Relations Act (“NLRA”) when it terminated an employee for making disparaging comments on her Facebook page regarding a supervisor. The NLRB alleges that AMRC’s social media policy, which prohibits employees from depicting adversely AMRC in any way on Facebook or other social media sites where pictures of the employees can be posted, violates the NLRA.



The NLRA prohibits employers from punishing workers – whether or not they are union members – for discussing working conditions or unionization. The NLRB claims that this is a case of employees utilizing a social media platform for the purpose of discussing jointly matters related to working conditions, a permissible activity under the NLRA. The NLRB alleges that AMRC’s social media policy was overly broad and denied employees’ right to discuss working conditions among themselves.



These two examples illustrate the challenges that employers currently face in balancing social media risks with human resource risks. According to survey results contained in Proofpoint, Inc.’s (ProofPoint.com) report, “Outbound Email and Data Loss Prevention in Today’s Enterprise, 2010,” the number of firms that reported social media-related terminations in 2010 remained consistent at seven percent compared to eight percent reported in the 2009 survey. However, this figure is nearly double the rate of four percent cited in the 2008 survey. This data suggests that there is definitely a need for organizations to consider the impact that social media will play in managing employees. The challenge for organizations is establishing the appropriate environment in which an organization can justifiably terminate an employee with the confidence of knowing that it will not likely experience a legal backlash.

Another issue related to employee terminations is the topic of reference letters. While many organizations look favorably upon reference letters for terminated employees, some organizations struggle with the issue. Based upon the popularity of social media platforms such as LinkedIn, it is important for organizations to address instances in which reference letters are permitted. In today’s environment it is very likely that a terminated employee will seek an online reference from a past manager or co-worker. In developing a policy statement regarding reference letters, it is important for the organization to convey to employees through training that online recommendations such as those provided through LinkedIn, are equivalent to reference letters. As such, guidance should be provided to employees to ensure that they comply with the organization’s policy.

Employment law is an extremely complex and evolving area of law. As such, this article cannot adequately address all of the issues that organizations may face when it comes to social media. This post is intended to provide examples of actual cases in an effort to demonstrate the importance of developing a human resources policy that addresses social media use by employees. Unfortunately, employment law relative to social media usage is currently taking shape. As such, it is somewhat difficult to fully define best practices. Regardless, a well thought out approach that incorporates existing best practices with evolving case law will provide for the best protection. Incorporating these practices into the formal written social media policy will provide the best possible protection against claims for unlawful termination.

[This post was edited on December 30, 2010 to add the YouTube videos embedded within.]

Wednesday, December 15, 2010

Social Media and Information Security

Wikipedia defines information security as the process by which information is protected from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction. When it comes to the Internet, information is generally secured through mechanisms such as login ID and password. Social media presents significant challenges to ensuring adequate information security not because of the technology but because of the habits of social media users. As described below, social media does not introduce threats that are social media-specific. Instead, social media makes the existing threats more effective because users are less vigilant.

If there is one overall benefit that social media has brought to bear, it is that social media has made us all more open and willing to share. There is much to be said about a society that values trust, openness and sharing. Through social media, users are increasingly sharing more and more of themselves. From family photos to what they’re buying, reading or eating to where they’re currently located as well as what exactly they’re doing there. Prior to social media the world was a place made of personal silos where people were more than satisfied keeping their private lives private. Once social media became broadly adopted the world generally became a more open society. In the grand scheme of human relations, this is surely a positive outcome.

Unfortunately, no good deed goes unpunished. And social media’s effect on society is no exception. While society has become more transparent in its online interactions, social media users have also become too trusting. Since most social media interactions are conducted with trusted parties such as friends, classmates, co-workers and other known persons, social media users tend to lower their guard when interacting on social media platforms. As such, social media platforms have become extremely attractive to criminals that seek to exploit the trusting nature of social media users. Further, the fact that millions of users congregate on these sites daily, provides an attractive return on investment for the criminal element. As a result, social media users are at a greater risk of exposure to the exploits of criminals. Internet security experts at Kaspersky Lab (http://usa.kaspersky.com) believe that malicious code distributed through social media is up to ten times more effective than similar attacks using e-mail.

A social media user’s confidential personal information includes everything from passwords to social security numbers to birth dates to items such as mother’s maiden name. This information is regarded as the Holy Grail to criminals who seek to takeover a user’s identity or account. In today’s digital age, this information is maintained by many organizations, including social media platforms. Through the use of sophisticated software programs such as keyloggers and techniques such as phishing attacks, criminals can easily gain access to the social media credentials (ID and password) of their victims. Once they gain access to a social media account, the criminals may deploy various strategies to carry out their plans. For example, it is commonly known that people use the same password for multiple computer systems. As such, once a criminal has access to a single social media account, the criminal may use the same credentials to attempt to access other social media accounts, online banking accounts, corporate computer systems, etc.

Another approach that may be taken by criminals is to use a hijacked social media account to gain access to other users’ accounts by sending a message from the hijacked account to the accounts of people within the hijacked user’s social network with the intent of tricking those individuals into visiting Web sites that install malicious software utilized to steal the login IDs and passwords. These information security breaches are generally successful for two main reasons – users assuming that messages sent within the social media platforms are legitimate and users not understanding how their actions can be exploited by criminals. While the techniques may differ, the goal is generally the same – to gain access to social media accounts that contain valuable information that the criminals can use for financial gain.

A complete discussion of information security is beyond the scope of this book. What is important to note from the perspective of developing an effective social media policy is that social media poses information security risk just as any other Internet-based application. The ultimate question regarding information security is whether organizations with large workforces can reasonably expect to protect themselves from the criminal element that seeks to exploit social media. The short answer is, “it depends.” Organizations can best protect themselves by not becoming the “low hanging fruit.” Ultimately it comes down to assessing the risk, mitigating the risk, training the staff and monitoring the results. All of which should be described in a formal written social media policy.

Sunday, December 5, 2010

Expectation of Privacy and the Social Media Policy

According to the Fourth Amendment of the United States Constitution, citizens have the right to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures. Therefore, the obvious question that arises with social media is, does the Fourth Amendment provide employees using social media in the workplace with an expectation of privacy? This question is at the center of many legal battles that have recently filled court dockets across the Country – and early reports from the field indicate that social media users should not be expect Fourth Amendment protection.

Social media by name and design is a “social” media. It is not called “private media” for a very specific reason – there is nothing private about it. Regardless of privacy settings and other controls, increasingly courts around the Country are sending the following message to American workers: “employees using social media should not be under the false impression of a right and expectation of privacy in the workplace.” These court cases are concluding that social media in the workplace is not protected by the Fourth Amendment and as such, information contained within social media platforms may be subject to discovery during the legal process as well as part of other procedures such as audits, background checks and similar activities that benefit from the use of information contained on social networks.

The Fourth Amendment provides a “reasonable” expectation of privacy. However, the standard upon which reasonableness is judged depends upon the current standards of society. In today’s open and social media-enabled society, we live our lives more openly and transparently than ever before, sharing everything from our choice of breakfast cereal in the morning to photos of our children to our location in real-time. For the most part, there are fewer and fewer secrets being kept as more and more of us become increasingly comfortable giving up more of our information than ever before. While the evidence does not suggest that every life should be an open book, judicial decisions appear to take a practical approach when it comes to information contained on social media platforms. In other words, employees are not going to be allowed to act to the detriment of an organization and then hide behind a form of social media immunity.

From the organization’s point of view, the assumption of the lack of privacy plays a key role in managing employees’ use of social media within the workplace. Based upon the current direction of case law, it is in every organization’s best interest to disclose the organization’s right to inspect social media-based records to the extent such records originated through the use of the organizational assets, including computers, network infrastructure and company-controlled/owned social media accounts. The social media policy should be clear about its right to monitor social media interactions in real-time (network monitoring), in stored files (caches, temporary files, etc), while on “company time” and using the organization’s equipment. Such a policy statement will assist the organization in defeating opposition to demands for information during the legal process and will provide protection against claims of invasion of privacy. Once the formal written policy is in place, the organization must ensure that employees are informed of the policy and comply with its requirements. Deviation from the written policy may result in questioning whether or not the employee had an expectation of privacy due to “practices” that are inconsistent with the written policy.

In City of Ontario v. Quon, a California police officer had his case ultimately reach the United States Supreme Court when the police officer was verbally told by a supervisor that he indeed did have an expectation of privacy when using for personal use a department-issued digital device – a statement that contradicted the written policy. While a lower court supported Officer Quon’s assertion that his personal electronic messages were protected based upon the verbal assurance, the U.S. Supreme Court eventually determined that the officer did not have an expectation of privacy on the basis that 1) a formal written policy existed, 2) the device used was provided by the police department and as such, the police department had certain rights to monitor appropriate usage of its assets, and, 3) there was no less invasive practical manner of monitoring general activity on the device.

In Romano v. Steelcase, Inc., a New York trial concluded that an employee had no reasonable expectation of privacy regarding information posted on social networks – despite the restricted privacy settings established by the user.

Another important piece of federal legislation that affects organizations’ access to employee information is the Stored Communications Act (“SCA”). The SCA prohibits employers from, among other things, accessing employee accounts maintained by third-party hosts such as social networks. The SCA generally allows organizations to access stored communications such as emails and other information stored within its own computer network. The SCA, however, limits an organization’s ability to access such information (without the employee’s authorization) if it is stored by a third party service provider. A further complication is that even in instances where an employee has granted an employer access to third-party sites, such access may be deemed to be done under duress and as such, a violation of the SCA. As such, experts generally recommend that employers not extend their reach beyond information contained within their systems in order to prevent violations of the SCA.

In drafting this section of the social media policy, organizations should check with their legal departments in order to determine how to best describe an organization’s policy regarding monitoring of social media activities. Further, each organization should work with its legal department to determine the various local, state and federal laws that may be applicable.

Wednesday, December 1, 2010

Social Media and the Recruiting Process

All organizations would like to believe that employees and new hires are smart, capable and masters of common sense. While at times this may be the case, in all cases this is the goal. As such, it is no surprise that so many human resources departments and recruiters, including banks, are considering how to leverage social media to successfully mine it for nuggets of information that will ensure hiring decisions are sound and will result in strong, productive team members.

Yes, social media is a great tool to identify and interact with potential applicants. Yes, social media is a great tool to learn more about applicant’s professional backgrounds, experiences, and goals. And yes, social media provides access to applicant information that is generally not available through the traditional interview process. However, as we have come to learn throughout this book, nothing with social media comes without a cost.

The general consensus among HR professionals is that the extraneous information accessible through social media should not be considered as part of the recruiting process in order to avoid complications in the hiring process that may run afoul of human resources laws. Generally, to the extent that organizations scour social media for recruiting purposes, employers and recruiters should stay focused on capturing and evaluating the information that addresses the applicant’s qualifications and expertise. Reliance on unrelated information can lead to false impressions of applicants, resulting in lost opportunities at hiring qualified candidates as well as possible judgments based on prohibited information. Unless the information suggests highly inappropriate or illegal activity, the information should be dismissed. Everyone is different. Some people have unique and quirky interests and activities that they participate in outside of work. There is nothing wrong with that and it certainly should not be the basis for passing up on an otherwise strong candidate.

To the extent an organization decides to utilize social media as part of the employment process it is wise to provide applicants with written notice that the background check may involve a review of any publicly-available social media sites. Once the disclosure is made it is important to keep any inquiry limited to information that is “publicly available.” In other words, the process should not require that applicants provide passwords to social media sites nor should it require that applicants “friend,” “like” or otherwise grant the organization access to information that would not otherwise be readily accessible. Such demands, besides being extraordinarily invasive, may violate federal and state privacy statutes as well as may lead to violations of “legal activities” laws that may prohibit employers from taking certain actions based on the “personal time” activities of employees and applicants.

The February 2010 issue of Practical Law: The Journal lists the following risks associated with social media usage as part of the recruiting process:

• Discrimination violations due to adverse employment decisions based on protected class information learned through social media.

• National Labor Relations Act ("NLRA") violations due to employment actions inconsistent with the NLRA.

• Violation of the Fair Credit Reporting Act (“FCRA”) and its state equivalents as a result of the use of consumer reports in conducting background checks without providing the required adverse action disclosure.

Based upon the potential legal pitfalls it is essential that bank HR departments establish a formal written social media policy that specifically addresses how social media may be utilized. Further, human resources personnel should be well trained to understand not only the social media policy but also the applicable laws such as the NLRA, FCRA and any other applicable laws, rules and regulations.

Sunday, November 28, 2010

Monitor Your Brand

In the Introduction chapter to the book, Brands and Branding, Rita Clifton (editor) recounts a story involving investor Warren Buffett as he tells a group of German investors that brand is the most important factor in deciding where to invest.  According to Ms. Clifton, “even in hard times, brand is the key to protection and growth.”



If it is true that brand is of paramount importance – and I believe, like Mr. Buffett, that it is, then organizations need to do everything within their power to protect the brand they have created.  Brands in the general sense include logos, slogans, colors, sounds, shapes and other physical or visual characteristics.  However, when dealing with social media, brands are mostly identified through their brand name – though the other aspects, as will be described below, may play a role as well.

Regardless of an organization’s decision to become active in social media, some firms – particularly those with strong brands - will be subjected to some form of social media risk.  The most common risk comes from internal sources – employees.  Whether or not an organization implements a social media strategy and related policy, there still exists the risk that might be created by employees through their personal social media activities.  Other risks originate externally.  In both cases, the fact that the organization does not maintain a social media strategy is irrelevant.  The social media risks still exist and as such, the need for a social media policy that addresses these risks is required.

An example of an externally-generated social media crisis occurred to the brand of the hit television show Mad Men.  Tiphereth Gloria tells in a Digital Tip blog posting (Brand Hijacking, Brand Advocacy and Social Media Identities) the story of how fans of the show hijacked the Mad Men brand through the creation of Twitter accounts in the names of the Mad Men characters.  The Twitter accounts generated a tremendous following.  The problem was that fans of the show assumed that the Twitter accounts in the names of the show’s fictional characters where created and maintained by someone associated with the production of the show.  The fact was that this part of the Mad Men brand was being controlled by a third party unassociated with the show.   While in this case the brand was hijacked by friendly fans seeking to expand the fictional characters into reality, the fans could have been criminals or others seeking to take advantage of or damage the brand.

Another example of social media activities that can harm the brand is plain old-fashioned disgruntled customers.  If you Google “Microsoft sucks” you’ll get tons of responses.  If you Google “Apple sucks” you’ll get the same.  If you Google “Google sucks,” ditto.  And on and on.  As such, it is clear that no matter what a company does to keep its customers happy, sucks happens!

A third example is the internally-generated social media crisis in which two employees of a North Carolina Domino’s store recorded a video and posted it on YouTube.  The video turned viral and was viewed over one million times before it was taken down.  The result was a hit to Domino’s national brand as well as the brand of the North Carolina store. 


These examples illustrate how social media risks can manifest without the knowledge or involvement of the organization and regardless of an organization’s social media strategy.  Whether or not Domino’s or the producers of Mad Men had implemented a social media strategy, these outcomes would have still resulted due to the fact that they were driven by independent forces – rogue employees and frenzied fans.  In the case of Domino’s, the video came to the attention of management rather quickly as the video went viral.  According to reports, the Mad Men crisis appears to have been a different situation in the sense that those involved with the show did not become immediately aware of the brand hijacking.

In each case, the best way to identify, deter and defeat rogue employees, dangerous brand hijacking attempts or disgruntled customers is to monitor what is being said on social media.  While monitoring is a “detection” technique – as opposed to a prevention technique – it can be quite effective at identifying issues before they turn into crises.

According to Taariq Lewis and the Terametric Blog, there are over 145 social media brand monitoring and brand reporting tools on the market (“2 Reasons Why 145+ Social Media Brand Monitoring and Brand Reporting Tools Are Still Not Enough”).  Some of these tools are free and quite effective, others are not.  Based upon the complexity of each brand and the organization’s social media strategy, it is entirely possible to monitor the brand with free tools such as Google Alerts (google.com/alerts), Twitter Feeds (search.twitter.com) and SocialMention (socialmention.com).  In other cases, however, a more robust solution may be preferred. 

Since brand monitoring solutions are constantly evolving, it is always a good idea to search the Internet for information on “brand monitoring” and “social media.”  This will provide access to the latest and greatest brand monitoring tools – both free and premium-based.  Based on the large number of effective and affordable brand monitoring tools, there is no excuse for not monitoring an organization’s brand.  Use of these tools provides organizations with an early warning system that will assist organizations in preventing small issues from escalating to brand-damaging events.

Wednesday, November 24, 2010

Social Media Policies Are Not An Option

According to Wikipedia, a policy is “typically described as a principle or rule to guide decisions and achieve rational outcome(s). The term is not normally used to denote what is actually done, this is normally referred to as either procedure or protocol. Whereas a policy will contain the 'what' and the 'why', procedures or protocols contain the 'what', the 'how', the 'where', and the 'when'. Policies are generally adopted by the Board of or senior governance body within an organization where as procedures or protocols would be developed and adopted by senior executive officers.”


Organizations, regardless of their involvement in social media activities, should implement a social media policy to protect against the internal and external risks posed by social media.  Regardless of the strong case for social media policies, there are a lot of opinions against their use in the workplace. Try Google-ing “social media policy” and you will get around 32,900,000 opinions! If you read what is being said you will find good arguments on both sides. But the bottom line is this: any organization interested in protecting its brand and reputation must ensure that it has in place some form of social media policy to protect against the many risks that are posed by social media. Social media risks originate both internally and externally and exist regardless of an organization’s decision to participate in social media activities.

Critics of social media policies say “you can’t control what is uncontrollable!” Agreed. And that’s exactly why a social media policy is necessary. Contrary to critics’ beliefs, a social media policy is not intended to “control” anything. Its purpose is to give employees guidance, keep them from making severe errors in judgment and allow the organization to identify potential issues before they elevate to the status of a crisis. No policy, regardless how well written, can “control” the risks. The best a policy can do is mitigate the risks. Policies work for organizations that understand that risk happens.

In a perfect world organizations hire individuals that are smart, capable and masters of common sense. Unfortunately we don’t live in that world. In our world, smart, capable and generally common sensical employees make dumb decisions from time-to-time. Further, for many companies, the youngest employees, while smart and capable, many times lack the experience and maturity needed to make all the right decisions all the time. And unfortunately it is these employees that are likely the most experienced and active users of social media. In these situations, formal written social media policies provide employees with the guidance to navigate difficult or unknown situations.

In a perfect world, every organization provides world class products, services and gives each customer the attention they demand to keep them happy. In the real world, no matter how hard organizations try, mistakes are made, customers are disgruntled and dissatisfaction is voiced. Historically such dissent was limited to irate phone calls and letters and possibly the loss of business of the unhappy customer. Today with the use of social media, customers have the ability to reach and influence current and potential customers on a scale that can invoke real pain and suffering.

Businesses are not only in the business of making or servicing widgets. Businesses are also in the business of making and servicing the organization’s brand. The stronger the brand, the greater the revenues. Organizations can enhance their brand and competitive advantage and potentially generate greater revenues and profits with a well crafted social media strategy. However, before unleashing a social media strategy, organizations should craft a social media policy that provides the necessary guidance to ensure that social media risks are properly mitigated. The social media policy is the key to ensuring that social media risks area kept under control and to acceptable levels.

Lack of attention to social media risks can have the opposite effect. Companies that take a laissez faire approach to social media risks stand a greater likelihood of experiencing major embarrassments, reputational harm and the need for a major incident response. As such, it is in every company’s best interest to establish guidelines for social media usage through the implementation of a social media policy.

Social media poorly managed has the potential to adversely affect the organization, its brand, reputation and revenues. The upside to participating in social media is an enhanced brand and increased revenues and profitability. While social media does pose risks, if well managed, social media provides benefits that far outweigh the costs. The key to managing the risks is a well-crafted formal written social media policy and training program that is understood and adhered to by employees. A social media policy will not eliminate all of the risk but it goes a long way in allowing everyone to sleep at night. Ultimately, whether an organization undertakes a social media strategy will depend on its appetite for risk. Since many social media risks exist regardless of an organization’s decision to participate in social media, it is in the best interest of organizations to implement some form of social media policy.

Thoughts?

Tuesday, December 1, 2009

Yes, Press Releases Are Now Part of Social Media and VERY Viral

About a week ago, after issuing a press release about my company's use of social media, I saw a tweet come up from someone questioning the use of a press release to promote Web 2.0. What I got from the tweet's 140 characters was essentially doubt about the use of press releases (traditional old school technique) in promoting use of Web 2.0. The tweet said something along the lines of "Why would a company that is rolling out social media use a press release. Social media is about being viral. Press releases are not viral."

This post has been created to make you aware that, yes, press releases ARE social media and ARE definitely viral. I'm not a publicist by schooling but I have had years of experience using press releases in the pre- and post-Web 2.0 world. Something I noticed about a year ago was how the press release outlets, including the majors such as BusinessWire, started Web 2.0-enabling their releases. The following is an example of the social media functionality added to press releases to enable their VIRAL distribution.




As you can see under the "Sharing" section on the left side of the page, the press release outlet (in this case BusinessWire) added a series of common social media platforms with which this press release could very easily be shared. This is only one outlet, but I've seen most outlets incorporate this "viral accelerator" to their pages.

As a result of a recent press release, I achieved immediate and broad distribution on Twitter illustrated by the sampling below:



As you can see, just on Twitter alone there were nearly 100 retweets of the press release. Multiply that number by the number of followers that read each retweet and you can see how a traditional press release can achieve viral distribution.

Now consider how these traditional press releases are distributed to hundreds of online media outlets by the wire services, resulting in greater viral potential. Below is a snapshot of a small number of the media outlets that received the press release from the wire service and began serving up copies of the press release - again, each with a similar "sharing" feature.



Now, keep in mind that simply having a "viral accelerator" does not mean a press relaese will achieve viral results. The material has to possess certain qualities. Press releases in of themselves are not great for creating viral buzz. But press releases tied to good viral content will do the job. I recommend reading the chapter of Viral Marketing in The Community Banker's Guide to Social Network Marketing for more details.

In any case, to answer the question posed by the tweet mentioned above, the fact that press releases have Web 2.0 funtionality means that, YES, press releases ARE about viral distribution.