Skip to content Skip to main navigation Report an accessibility issue
Information Security

Article Archive #2


Service navigation


Security Learning Icon One

Importance of Security

Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.

  • It’s the Simple Things

    The vast majority of cyberattacks, 98%, start with phishing attacks that contain NO zero-days and NO malware. They simply trick us into clicking on a link or opening an attachment, thereby turning over our passwords to the bad guys. Zero-days are bugs in software that the software company does not know exist. That’s why they’re…

    Read article…

  • Don’t Become a victim!

    Here are a few facts that illustrate the dramatic increase in cybercrime; 2,244 cyberattacks happen daily, according to the University of Maryland! Cyberattacks have increased 37% month-to-month due to the COVID-19 pandemic! An estimated $108M in losses are due to scams in a recent 6-month period. Cybercrime is big business—and happens more often than you…

    Read article…

  • No! Really! You are a target!

    Cybercriminals are very effective at getting what they want. They have learned that the easiest way around the university’s defenses isn’t hacking and cracking; it’s tricking you into letting them in. They will use everything in their toolbox to implement their attacks. Social engineering is the art of manipulating, influencing, or deceiving you into taking some…

    Read article…


Scam Types

Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.

  • When Bad News Travels, Attackers Are Listening 

    Malicious actors monitor news outlets and social media for signs of confirmed or suspected security events that they can exploit to their advantage. A campus outage that generates public discussion is, to them, an opportunity with a shelf life. The psychology is simple: during a disruption, people expect to hear from IT, so a call…

    Read article…

  • ClickFix: Don’t Be Tricked by a Fake “Fix”

    Cybercriminals are using a tactic called ClickFix to trick people into compromising their own devices. These scams use fake error messages, security warnings, or fake CAPTCHA verification prompts that tell users to take steps to “fix” a problem. One common trick is instructing users to press Windows + R to open the Run box, then press Ctrl + V to paste…

    Read article…

  • Triggers Hackers Use to Trick You: Urgency, Authority, and Curiosity

    Hackers don’t rely on technology alone—they rely on human psychology. Most attacks rely on three simple triggers to get people to act quickly without thinking. The first trigger is a sense of urgency, with messages like “act now or lose access” or “your account will be locked,” creating pressure that pushes users to respond immediately…

    Read article…

  • Understanding QR Code Phishing

    In the dynamic world of cybersecurity, threat actors continue to innovate using methods like QR code phishing. This technique, which seemed emergent just a few years ago, has now become more refined and widespread. QR code phishing, also known as “Quishing,” remains a threat as these codes are now ubiquitously used for convenience in many…

    Read article…


Benefits & Tips for You

In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.

  • Physical Security Tips While Traveling

    Traveling is an exciting experience, but it also comes with risks to your physical security. Whether you’re exploring a new city or attending a business conference, safeguarding your belongings and personal safety is essential. Here are some practical tips to enhance your physical security while traveling. 1. Secure Your Luggage Always use TSA-approved locks for…

    Read article…

  • Can You Identify a Phishing Website?

    A phishing website is a malicious site designed to steal sensitive information such as login credentials, credit card numbers, and other personal data. These websites often mimic legitimate sites to trick users into interacting with the website. Recognizing the signs of a phishing website and knowing how to protect yourself can help prevent identity theft…

    Read article…

  • Spring Cleaning Your Digital Life 

    Spring is often a time when people begin thinking about cleaning up their personal living space and getting rid of old belongings. It is also a good time to tighten your data security. Here are some places you might find some cyber dust bunnies!  These are only a few examples of where you may practice…

    Read article…


Protecting University Data

Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.

  • Safeguarding Your Remote Work

    Remote work in higher education is now the norm. To keep your online work safe using university-provided tools like OneDrive and Microsoft Teams, follow these straightforward steps: Working remotely in higher education is convenient and secure when you use the university-provided tools while taking these precautionary steps.

    Read article…

  • Privacy Concerns with Onboard AI: Microsoft Copilot

    Continuing with privacy concerns with onboard AI, Microsoft Copilot, which uses the hardware on any system with Windows 11 Copilot+ to run the native AI of Copilot, has been seen as a potential issue for user privacy. We’ve highlighted a few privacy concerns associated with Microsoft Copilot: You can opt out of data collection for…

    Read article…

  • Managing Permissions on Mobile Phones

    Application permissions are settings that control what an app can access and do on your device. Here are some common types of permissions: These permissions can be needed for the application to function, but sometimes, the application takes more permissions than necessary. In the cybersecurity world, we would call that a violation of “Least Privilege” or…

    Read article…