Skip to content Skip to main navigation Report an accessibility issue
Information Security

Article Archive #2


Service navigation


Security Learning Icon One

Importance of Security

Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.

  • Digital Privacy—What is a Data Broker?

    In today’s digital age, personal information has become a valuable commodity. Data brokers have emerged as key players in this data-driven economy. Data brokers operate behind the scenes, gathering vast amounts of personal information from various sources. They compile detailed profiles on individuals and sell this data to businesses, marketers, and even government agencies. Understanding…

    Read article…

  • What is a Pentester?

    In the realm of cybersecurity, penetration testers, commonly known as pentesters, play a vital role in safeguarding digital assets. These professionals are tasked with identifying and ethically exploiting vulnerabilities in an organization’s IT infrastructure to help strengthen its security posture. By simulating real-world attacks, pentesters help organizations understand their vulnerabilities and take corrective actions before…

    Read article…

  • Spring Cleaning Your Digital Life 

    Spring is often a time when people begin thinking about cleaning up their personal living space and getting rid of old belongings. It is also a good time to tighten your data security. Here are some places you might find some cyber dust bunnies!  These are only a few examples of where you may practice…

    Read article…


Scam Types

Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.

  • When Bad News Travels, Attackers Are Listening 

    Malicious actors monitor news outlets and social media for signs of confirmed or suspected security events that they can exploit to their advantage. A campus outage that generates public discussion is, to them, an opportunity with a shelf life. The psychology is simple: during a disruption, people expect to hear from IT, so a call…

    Read article…

  • ClickFix: Don’t Be Tricked by a Fake “Fix”

    Cybercriminals are using a tactic called ClickFix to trick people into compromising their own devices. These scams use fake error messages, security warnings, or fake CAPTCHA verification prompts that tell users to take steps to “fix” a problem. One common trick is instructing users to press Windows + R to open the Run box, then press Ctrl + V to paste…

    Read article…

  • Triggers Hackers Use to Trick You: Urgency, Authority, and Curiosity

    Hackers don’t rely on technology alone—they rely on human psychology. Most attacks rely on three simple triggers to get people to act quickly without thinking. The first trigger is a sense of urgency, with messages like “act now or lose access” or “your account will be locked,” creating pressure that pushes users to respond immediately…

    Read article…

  • Understanding QR Code Phishing

    In the dynamic world of cybersecurity, threat actors continue to innovate using methods like QR code phishing. This technique, which seemed emergent just a few years ago, has now become more refined and widespread. QR code phishing, also known as “Quishing,” remains a threat as these codes are now ubiquitously used for convenience in many…

    Read article…


Benefits & Tips for You

In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.

  • Secure Data Management: A Keystone of Cybersecurity

    In today’s interconnected world, managing data securely is not just a responsibility of the IT department; it’s a mission for every individual in an organization. Whether you’re at the helm of decision-making or ensuring day-to-day operations, your approach to handling data can make or break our collective cybersecurity efforts. Why Is Secure Data Management Important?…

    Read article…

  • Understanding Zero-Day Vulnerabilities

    In the ever-evolving landscape of cybersecurity, staying informed about emerging threats is crucial. One such threat that deserves your attention is the zero-day vulnerability. Let’s break it down in simple terms and explore how it impacts you. What Is a Zero-Day Vulnerability? A zero-day vulnerability is like a hidden trapdoor in your favorite app or operating…

    Read article…

  • Enhancing Cybersecurity: A Guide to Browser Extensions

    Browser extensions are a great way to enhance your browsing experience but can pose a significant security risk. Cybercriminals frequently use browser extensions to gain access to your personal information, such as login credentials, browsing history, and other sensitive data. In fact, according to a report by Kaspersky, more than 1.3 million users were affected by…

    Read article…


Protecting University Data

Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.

  • Look, No Hands—Let OIT Continuously Monitor Your Systems

    One of the responsibilities of every user of UT’s IT resources is to continuously monitor their UT Owned workstations, laptops, and servers. What does that even mean? HOW? WHO? Who does ANYTHING continuously? These two words, continuous monitoring,” would imply that you (or somebody) should be looking at a computer(s) 24 hours a day, 365 days per year. Thankfully, this…

    Read article…

  • Plans and Programs and Controls, Oh My!

    Information security conversations often include words like “IT security plans,” “systems,” and “program plans.” What do these terms mean in the context of cyber security, and why should we care? Three reasons WHY we are talking about cyber security: Human Resource (HR) or Fiscal (FI) policies provide a governance structure for conducting university business, the…

    Read article…

  • File Sharing Options for Sensitive Information

    We regularly receive questions about sharing or storing sensitive information.  While we have several recommendations, first, let’s talk about why you should be concerned about how you share or store sensitive information. ALL users are responsible for ensuring that their use of sensitive information services complies with laws, regulations, and policies where applicable; it is EVERYONE’s responsibility.…

    Read article…