Skip to content Skip to main navigation Report an accessibility issue
Information Security

Article Archive #2


Service navigation


Security Learning Icon One

Importance of Security

Information security is about addressing and reducing IT RISK. It’s easy to overlook risk as a topic when all you hear is talk about passwords, firewalls, encryption, policies, or two-factor authentication. In this section, you’ll read about how the university is at risk and what you can do to reduce the risk in your group, department, and college.

  • The Importance of Installing Approved Software

    As we navigate the ever-evolving landscape of cybersecurity, it’s crucial for each member of our university to play an active role in maintaining a secure computing environment. Today, we’ll shed light on the significance of only installing approved software on university-owned machines and the impact it has on our collective digital safety. 1. Protecting Sensitive…

    Read article…

  • Understanding Acceptable Use Policies (AUPs)

    As a user of our computer systems, you might have come across the term Acceptable Use Policy (AUP) in your workplace. But what exactly is an AUP, and why do we need one? Let’s dive into the essentials. What Is an Acceptable Use Policy? An Acceptable Use Policy is like a set of digital guardrails. It outlines the rules…

    Read article…

  • The Importance of Using Approved Anti-Malware Software on University Machines

    In the digital age, universities heavily rely on various software for administrative tasks, research, teaching, and learning. This reliance also opens potential vulnerabilities that could be exploited by malicious entities. Therefore, it is crucial to use only approved anti-malware software. The Risks of Unapproved Anti-Malware Software Unapproved anti-malware software can pose several risks: The Benefits…

    Read article…


Scam Types

Scams used to be easier to detect without worry. A Nigerian prince asks for a few hundred dollars to give you access to his fortune. But those days are gone, and scammers are in a constant arms race with cybersecurity for your sensitive information. Learn about the different types of scams and how to deal with them.

  • ClickFix: Don’t Be Tricked by a Fake “Fix”

    Cybercriminals are using a tactic called ClickFix to trick people into compromising their own devices. These scams use fake error messages, security warnings, or fake CAPTCHA verification prompts that tell users to take steps to “fix” a problem. One common trick is instructing users to press Windows + R to open the Run box, then press Ctrl + V to paste…

    Read article…

  • Triggers Hackers Use to Trick You: Urgency, Authority, and Curiosity

    Hackers don’t rely on technology alone—they rely on human psychology. Most attacks rely on three simple triggers to get people to act quickly without thinking. The first trigger is a sense of urgency, with messages like “act now or lose access” or “your account will be locked,” creating pressure that pushes users to respond immediately…

    Read article…

  • Understanding QR Code Phishing

    In the dynamic world of cybersecurity, threat actors continue to innovate using methods like QR code phishing. This technique, which seemed emergent just a few years ago, has now become more refined and widespread. QR code phishing, also known as “Quishing,” remains a threat as these codes are now ubiquitously used for convenience in many…

    Read article…

  • Typosquatting: When a Tiny Typo Leads to Big Trouble

    Have you ever mistyped a website address? Maybe you accidentally hit “goggle.com” instead of “google.com”? Well, that seemingly innocent slip-up can lead you down a treacherous path—one paved with cyber traps. What Is Typosquatting? Typosquatting is like a cunning chameleon. It preys on our human tendency to fumble our keystrokes. Here’s how it works: Why…

    Read article…


Benefits & Tips for You

In this section, you can learn about all the different tools available to you at UT, such as secure file sharing and monitoring your systems. We will also share best practices for staying secure at school and at home.

  • Tips for Securing macOS

    It’s no surprise that macOS is the second-biggest operating system worldwide. Apple has a well-regulated array of computers available for consumers that merge many strengths of the whole Apple ecosystem. However, this doesn’t mean that you should not take any steps to help secure your macOS computer. Securing your Apple computer involves several steps to…

    Read article…

  • MFA + Strong Passwords: Your Best Defense Against Account Attacks

    Multi-factor authentication (MFA) adds an extra layer of protection to your accounts by requiring more than just a password to sign in. Even if a password is stolen through phishing, malware, or a data breach, MFA can still prevent an attacker from accessing your account. This additional safeguard is especially important because passwords can be…

    Read article…

  • Find Out If Your Data Was Exposed in a Breach

    Data breaches continue to affect major organizations, and recent reporting has linked the ShinyHunters extortion group to incidents involving Charter Communications, a company with services branded as Spectrum. A simple way to check whether your email address appears in a known breach data is to use Have I Been Pwned at haveibeenpwned.com. This site lets you search your…

    Read article…


Protecting University Data

Discover essential articles on cybersecurity practices specifically tailored for the University of Tennessee. Learn effective strategies to safeguard sensitive information, defend against threats, and maintain data integrity. Equip yourself with knowledge to protect your university’s digital ecosystem.

  • I’ve been hacked!

    Determining whether or not your computer or mobile device has been hacked can be difficult. Nonetheless, there are a few common issues that will indicate your computer has been hacked. If your browser’s homepage has unexpectedly changed or is taking you to websites you have never visited, this could be an indication. Also, if your…

    Read article…

  • Phishing Ourselves

    In September of 2021, the UTK Administration asked that OIT develop and carry out a phishing campaign. The phishing will continue until the clicks improve, and they ARE improving! A couple of Frequently Asked Questions (FAQs) about the phishing campaign: OIT conducted a baseline phishing exercise in September 2021 used to compare all following campaigns.…

    Read article…