October is here and, as has become the custom here at Royal Roads University over the past 7 years, that means it’s time for “Cyber Month.” If you’re not familiar, Cyber Month is an internationally recognised campaign held each October to help people learn more about the importance of cyber security and how to stay safe online.
Why do we engage in Cyber Month activities at RRU? Well, for a few reasons. Consider:
- Ransomware attacks are increasing at an alarming rate, with the average cost of remediating a ransomware attack now over $6 million CAD.
- Education, along with municipalities, continue to be the most popular targets for cyber criminals.
- According to Canada’s Communications Security Establishment, education is facing an increased challenge from the threat of ransomware as cyber criminals go after what they perceive to be an easy but potentially lucrative target.
Bottom line: we need to find ways to protect ourselves from these very real risks, any one of which could have a serious impact on our University.
Does the Cyber Month program work? I’d like to believe it does. Through education programs like the Cyber Month activities, your continued vigilance and the support of our Cybersecurity Ambassadors, RRU is (so far) free of cyber security incidents this year, and continues to maintain an amazingly low “click” rate on the phishing email assessments that we run occasionally.
The risks are higher than ever, and the evidence show us that programs like Cyber Month help keep the RRU Community safe from cyber criminals. It’s for this reason that I’m asking that you take a few minutes each day and look through the information that the IT Security team will be circulating. The program this year is fresh, engaging and is focused on the main cyber risks that RRU faces. You’ll also find a few challenges you can take to test your knowledge, and information you can use to help keep your home and family cyber safe.
Welcome to Week 1 of Cyber Month! We’re starting off our annual Cyber Month activities with Phishing Security.
What? Phish… again??? Why?
Phishing is our # 1 Cybersecurity Risk.
Consider:
- All but 1 of RRU’s cyber incidents have involved phishing emails.
- Virtually all cyber attacks start with a phishing email.
- Phishing emails work because they’re an easy way for cyber criminals to bypass our technical security controls.
Before we go on… Let’s do a quick review of what a phishing email is, and how we can protect ourselves against them: https://www.youtube.com/watch?v=BnmneAjVrM4. (2 minute video)
Now, let’s dig a bit deeper…
| Phishing emails are a form of social engineering. I’m sure you know how it works, it’s based on emotional triggers. If you have time to watch a 2 minute video on how Social Engineering works, check this out: https://www.youtube.com/shorts/g8Rq9p2js5IBut not all emotional trigger phishing is in emails. Vishing calls are on the rise – check this out: |
|
|
So, what’s this vishing we’ve been hearing about?
|
|
| What am I supposed to do about phishing emails?
Received a suspicious email?
Responded to a phishing email?
|
|
| Time for a little practice….
The nice people at Google have put together a site with a range of phishing emails… some simple, some pretty sneaky. Here’s the link:
https://phishingquiz.withgoogle.com
We’d love to hear how you did! Send your results to: securityawareness@royalroads.ca |
|
REMEMBER: STOP! THINK! CONNECT.
Leave a Reply