<node id="456281">
  <nid>456281</nid>
  <type>news</type>
  <uid>
    <user id="27164"><![CDATA[27164]]></user>
  </uid>
  <created>1444133318</created>
  <changed>1653584976</changed>
  <title><![CDATA[Campuswide Phishing Training Begins This Month]]></title>
  <body><![CDATA[<p>Later this month, the group will conduct a campuswide phishing exercise to help educate students, faculty, and staff on cybersecurity risks and how to identify phishing threats in emails.</p><p>The exercise, which will take the form of a regular email, will contain a link to a non-Georgia Tech page that will ask you to enter your Georgia Tech login credentials. There will be apparent red flags in the email, though, that should raise suspicion and stop recipients from taking the proverbial bait. Anyone who enters a username and password on this fake page will be directed to an onscreen training page with tips on how to avoid a real threat.</p><p>“This is a non-punitive exercise, so information about individuals who provided their username and password will not be shared,” said Jason Belford, interim associate director for Georgia Tech Cyber Security. “We will review the results to help us refine our future training efforts. It is critical to conduct these continuous training exercises to help build and maintain awareness throughout the entire community.”</p><p>Georgia Tech Cyber Security has seen positive results when they have conducted similar exercises with individual departments and small groups of users on campus. In past exercises among those on campus who had not had phishing training, around 20 to 25 percent of people fell prey to the fake email. Following training, that percentage decreased to around 3 to 5. This month’s exercise, supported by the Office of the President, is the first campuswide phishing exercise and will be repeated every semester.</p><p>How big of a problem is phishing on campus? Last year, hundreds of accounts were compromised — a significant increase from previous years that has grown even larger this year. Belford notes that all notable hacks in recent years, such as those involving Target and The Home Depot, began with a phishing message.</p><p>While preventing all forms of phishing is not possible, one safeguard users can employ is to always check where the URL link in an email is pointing — before clicking. This can be done by hovering over the link before clicking, or by previewing the link if you use a smartphone. If the domain doesn’t match what you expect it to, that should be a giveaway. For more information, visit <a href="http://www.security.gatech.edu/phishing">www.security.gatech.edu/phishing</a>.</p><p>Those on campus who think they have received a phishing message should forward it to <a href="mailto:phishing@gatech.edu">phishing@gatech.edu</a>, or just delete it. Forwarding such messages to Cyber Security helps the team use them to increase operational effectiveness as well as better understand current phishing trends.</p>]]></body>
  <field_subtitle>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_subtitle>
  <field_dateline>
    <item>
      <value>2015-10-06T00:00:00-04:00</value>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_dateline>
  <field_summary_sentence>
    <item>
      <value><![CDATA[Later this month, the group will conduct a campuswide phishing exercise to help educate students, faculty, and staff on cybersecurity risks and how to identify phishing threats in emails.]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_summary>
  <field_media>
      </field_media>
  <field_contact_email>
    <item>
      <email><![CDATA[jason.belford@security.gatech.edu]]></email>
    </item>
  </field_contact_email>
  <field_location>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_location>
  <field_contact>
    <item>
      <value><![CDATA[<p>Interim Associate Director for Cyber Security - Office of Information Technology</p>]]></value>
    </item>
  </field_contact>
  <field_sidebar>
    <item>
      <value><![CDATA[<p>This month’s phishing exercise will hit inboxes in late October, which is National Cyber Security Awareness Month.&nbsp;</p>]]></value>
    </item>
  </field_sidebar>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <!--  TO DO: correct to not conflate categories and news room topics  -->
  <!--  Disquisition: it's funny how I write these TODOs and then never
         revisit them. It's as though the act of writing the thing down frees me
         from the responsibility to actually solve the problem. But what can I
         say? There are more problems than there's time to solve.  -->
  <links_related> </links_related>
  <files> </files>
  <og_groups>
          <item>1214</item>
      </og_groups>
  <og_groups_both>
          <item>
        <![CDATA[Institute and Campus]]>
      </item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>129</tid>
        <value><![CDATA[Institute and Campus]]></value>
      </item>
      </field_categories>
  <core_research_areas>
      </core_research_areas>
  <field_news_room_topics>
          <item>
        <tid>71871</tid>
        <value><![CDATA[Campus and Community]]></value>
      </item>
      </field_news_room_topics>
  <links_related>
          <link>
      <url>http://www.security.gatech.edu/resources/phishing</url>
      <title></title>
      </link>
          <link>
      <url>http://www.calendar.gatech.edu/event/445201</url>
      <title></title>
      </link>
          <link>
      <url>http://oit/</url>
      <title></title>
      </link>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>1214</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[News Room]]></item>
      </og_groups_both>
  <field_keywords>
          <item>
        <tid>345</tid>
        <value><![CDATA[cyber security]]></value>
      </item>
          <item>
        <tid>9299</tid>
        <value><![CDATA[Office of Information Technology]]></value>
      </item>
          <item>
        <tid>4112</tid>
        <value><![CDATA[oit]]></value>
      </item>
          <item>
        <tid>143911</tid>
        <value><![CDATA[phishing emails]]></value>
      </item>
      </field_keywords>
  <field_userdata>
      <![CDATA[]]>
  </field_userdata>
</node>
