How SUNY Empire State University took control of its social media exposure

Contents

How Empire State University took control of its social media exposure

See how your brand is exposed on social media, and how Spikerz can keep you protected.

Book a demo

Let's set the scene...

SUNY Empire operates within the State University of New York system, one of the largest public university systems in the country. The marketing team recently assumed ownership of social media operations across Facebook, Instagram, LinkedIn, and YouTube, with a growing organic and paid strategy tied directly to enrollment.

At a public university, social media carries institutional weight. It’s the primary channel for reaching prospective students, engaging current students, communicating with alumni, and building donor relationships. The accounts aren’t promotional assets, they’re operational infrastructure.

[review]

What was the problem?

SUNY Empire's social media footprint was exposed in two distinct ways, each capable of generating an institutional incident on its own. Both existed because social media platforms provide no native tools for institutional-level governance or automated content moderation.h existed because social media platforms provide no native tools for institutional-level governance or automated content moderation.

1. Access governance had never been centralized.

Fifteen users held varying roles across accounts: administrators, analysts, editors, some active, some dormant for months. Former employees retained credentials. An external advertising agency held access to paid accounts through passwords that had never been rotated. On permission-based platforms like Facebook, access ran through personal accounts, meaning a compromise of any single personal profile could expose the university's pages, ad spend, and audience data. There was no consolidated view of this access landscape.

2. Comment sections were being used to target students.

SUNY Empire's social engagement strategy centers on authentic storytelling, featuring real students by name and likeness. As the university's paid and organic presence grew, comment sections under enrollment ads became a recurring source of hostile content: appearance-based attacks targeting the students featured, hate speech, and accounts posting what appeared to be spam or phishing links.

The team was moderating manually, but the volume was increasing and the content was evolving to evade standard keyword filters. Every hostile comment that remained visible under a student's image was visible to prospective applicants, their families, and institutional stakeholders reviewing the university's public presence.

How did they solve it?

Rather than wait for an access breach or a public incident to force the conversation, SUNY Empire's CMO Doug Gruse and the marketing leadership moved first. They made a deliberate decision to bring both risks under institutional control while the university still had the advantage of choosing how and when to act.

Spikerz connected all of SUNY Empire’s social accounts and conducted a full access audit, mapping every user, permission level, and third-party connection across the university's social media presence.

[block-blue]

For comment protection, AI-powered moderation was deployed across all accounts with custom topic filters calibrated to the specific patterns SUNY Empire's team had been encountering: appearance-based harassment, hate speech, and suspected spam. The system processes context and intent, distinguishing hostile content from legitimate student and alumni engagement. Content that previously remained visible for hours until a team member noticed it is now intercepted in real time, before it reaches the audience.

The operational model was designed around a marketing team's workflow. Monthly reporting, a dedicated account manager, and a shared communication channel keep the university's team informed without adding security operations to their responsibilities.

[review-2]

And what were the results?

[4-block]

Key Takeaway

Without centralized governance, every university social media account is one compromised personal password away from an institutional incident: unauthorized posts reaching prospective students, hijacked ad spend, or a public breach that lands on the president's desk.

Without automated moderation, every student who agrees to appear in an ad is exposed to public harassment the university cannot control at scale. These are not edge cases. They are the default state of social media when the platforms provide no native tools to manage either one.

SUNY Empire's leadership chose to resolve both before they became someone else's example of what goes wrong. For any institution where social media is tied to enrollment, fundraising, or public reputation, the question is straightforward: address the exposure on your terms, or respond to it on someone else's.

“Social media is one of our primary institutional channels. You can try to cut corners on protecting it, but you're just choosing when the problem finds you, not whether it does.”

Douglas Gruse, Chief Marketing Officer, Empire State University

“In our authentic storytelling, we get a lot of really negative comments where people are just bashing people based on their physical appearance. Now, that’s not something we ever have to be concerned about again.”

Douglas Gruse, Chief Marketing Officer, Empire State University
Douglas Gruse, Chief Marketing Officer Empire State University
On shared-credential platforms:

Individual employee credentials were replaced with anonymized, university-owned email addresses and phone numbers. Two-factor authentication codes were centralized, eliminating dependence on an employee’s personal device, and making login simple for all authorized users. Stale sessions were invalidated, closing potential security gaps.

On permission-based platforms

Permissions were reviewed against current roles: unnecessary admin privileges were downgraded, former staff and inactive agency accounts were removed. From that baseline, continuous monitoring was established. Any permission change, unrecognized login, or credential anomaly triggers an automated alert.

Centralized access governance across all social media accounts.

Fifteen users across four platforms mapped, monitored, and governed from a single view for the first time. Stale credentials, former employees, and unreviewed agency permissions eliminated during onboarding. University-owned credentials with two-factor authentication replaced individual employee logins on all shared-password platforms.

Automated protection of student-facing content.

Appearance-based attacks and hate speech targeting students featured in advertising are now filtered in real time. The students who agreed to represent the university publicly are no longer exposed to harassment in comment sections visible to prospective applicants and their families.


Fully automated, with zero additional headcount.

Access governance, comment moderation, login monitoring, and credential management all run continuously without requiring the marketing team to operate a security function. What previously depended on someone noticing a problem now runs whether anyone is looking or not.

Ready to secure your reputation before it’s too late?

SUNY Empire's leadership chose to resolve both before they became someone else's example of what goes wrong. For any institution where social media is tied to enrollment, fundraising, or public reputation, the question is straightforward: will you address the exposure on your terms, or respond to it on someone else's?

More success stories