|
|
|
Every October, Cybersecurity Awareness Month brings organizations and individuals together to highlight the importance of staying safe online. As cyber threats continue to evolve, everyone at your university has a role to play in keeping your campus secure. From phishing and social engineering to compromised credentials and vulnerable systems, attackers often look for opportunities in our everyday actions.
This year's theme, "Don't Make it Easy for Them," is all about making it harder for threat actors to succeed. While we can't eliminate every cyber risk, we can reduce our risk by practicing good security habits, recognizing suspicious activity, and knowing when to act.
|
|
| |
|
Your Password is 'Password'? Let's Have a Quick Chat.
Strong password practices are an important part of protecting your campus community. The longer, more unique, and more unpredictable your password is, the harder it is for cybercriminals to crack. And if you're thinking, "There is no way I'm remembering all those passwords," a password manager may be an option, depending on your school's available tools and policies.
A few password practices to promote:
| • |
Go long. Make your password at least 12 characters long. Longer passwords and passphrases are harder for threat actors to compromise.
|
| • |
Make it unique. Use a different password for every account.
|
| • |
Keep it unpredictable. Avoid common words, phrases, or patterns, and use a mix of letters and numbers.
|
| • |
Skip the personal stuff. Names, birthdays, pets, and favorite sports teams can make passwords easier to guess.
|
| • |
Encourage secure storage. Help students, faculty, and staff understand the importance of keeping passwords private and using campus-approved tools or methods for managing them.
|
|
|
| |
Sorry Hackers, There's Another Step.
Passwords are important, but they shouldn't have to do all the heavy lifting. For institutions of higher education, making strong multifactor authentication (MFA) practices accessible and easy to use can help protect the many accounts connected to campus systems, applications, and data.
Give accounts a little extra backup:
|
| |
• |
Review your MFA coverage. Regularly assess which systems and applications have MFA enabled and where additional coverage may be needed.
|
|
| |
• |
Prioritize stronger methods. Encourage authenticator apps when available, rather than relying solely on text messages.
|
|
| |
• |
Educate students, faculty, and staff about MFA fatigue. Unexpected or repeated authentication prompts can be a sign that someone is attempting to access an account.
|
|
|
| |
|
Your Boss Wants You to Buy Gift Cards. Again?
A "You've Won a Prize!" email was once an easy giveaway. Today's phishing attempts aren't always so obvious. Sometimes, they look like a message from a supervisor making an unusual request, or a familiar vendor asking you to verify an account. These messages are designed to blend into everyday work, making it easier to act before stopping to take a closer look.
Tips for Strengthening Phishing Awareness:
| • |
Use scenarios your campus community will recognize. Build simulations around realistic situations, such as messages from leadership, IT support, financial offices, vendors, or familiar campus services.
|
| • |
Make reporting easy. Give students, faculty, and staff a simple, clearly communicated way to report suspicious messages.
|
| • |
Measure the response, not just the click. Look beyond click rates to see how users interact with simulated phishing emails. Tracking whether users open, delete, or report a message can help IT teams gauge how effectively their school responds to potential threats.
|
|
|
| |
|
Keep Ignoring that Update. Hackers Won't Mind.
You have 47 tabs open, and somehow, you need every single one. Naturally, your computer decides now is the perfect time for an update. We get it—having to close all those tabs feels personal. But those updates often include security fixes for specific vulnerabilities that hackers could use to access your device or data. For higher education IT teams, keeping software current across a campus requires more than individual users staying on top of notifications—it takes consistent processes and visibility across the environment.
Patch it before they can catch it:
| • |
Automate where possible. Establish a process for identifying and addressing critical vulnerabilities quickly.
|
| • |
Keep track of vendor updates. Monitor security advisories and patches from software and technology vendors.
|
| • |
Know what's on your network. Maintain an accurate inventory of devices, applications, and systems to easily identify what needs updating.
|
| • |
Don't overlook less-visible systems. Printers, browsers, applications, and other connected devices can also require security updates.
|
|
|
| |
 |
Previously, we sent emails from noreply@studentaid.gov. Going forward, we may also send emails from noreply@login.studentaid.gov, noreply@mail.studentaid.gov, and noreply@info.studentaid.gov. These email addresses are legitimate and authorized to send official communications from Federal Student Aid.
|
|
| |
|
This email was sent by: Office of Federal Student Aid
U.S. Department of Education
400 Maryland Ave SW,
Washington, DC 20002
|
| |
|
Please do not reply to this email. Messages sent to this email address are not monitored. If you wish to contact us, please use the StudentAid.gov contact page. For more information about financial aid, visit StudentAid.gov. If you do not want to receive future FSA partner emails, unsubscribe.
|
|