Online Security Basics
Protecting yourself online does not have to be complicated. A few everyday security practices can make it harder for someone to gain access to your accounts, devices or information. Follow these basic recommendations to help protect yourself and University data.
1. Keep Your Devices and Software Updated
Install operating system, browser and application updates when they become available. Updates often address security vulnerabilities in addition to providing new features and performance improvements. Enable automatic updates when possible.
2. Use Endpoint Protection
Keep endpoint protection, such as Microsoft Defender, enabled and up to date on your devices. These security tools help detect and protect against malware and other threats. Avoid disabling security features or bypassing warnings unless you know the activity is legitimate.
3. Recognize Phishing and Social Engineering
Avoid phishing (email), smishing (text message), vishing (phone call) and other scams intended to steal your identity, money or account information. Cybercriminals may impersonate people, organizations or services you trust to convince you to reveal sensitive information or take an action that compromises your security.
Be cautious of unexpected requests, especially those that create urgency or pressure you to act quickly. Verify unusual requests through a trusted method before providing information, selecting a link or approving access.
4. Protect Your Passwords
Use strong, unique passwords for your accounts and never share them with anyone. A password manager can help you create and securely store different passwords rather than reusing the same credentials across multiple services.
When multi-factor authentication is available, use it for additional account protection. Never approve an authentication request you did not initiate.
5. Think Before You Click
Do not open links, attachments or downloads simply because a message appears to come from someone you know. Review the sender's complete address and check where a link leads before selecting it.
If you receive an unexpected request involving your account, personal information or University data, verify it through a trusted method before responding.
6. Secure Your Devices
Lock your computer whenever you step away, even for a short period. Protect mobile devices with a PIN or passcode and use biometric authentication, such as a fingerprint or facial recognition, when available.
Keep devices with you or stored securely whenever possible. Lost or stolen University equipment should be reported promptly according to University procedures.
7. Protect Sensitive Information
Consider what information you are sharing, who needs it and how it is being transmitted. University information should be stored and shared using approved services, with access limited to those who need it.
Be equally cautious with personal information. Details such as your birthday, location or other information shared online can sometimes be used to impersonate you or make scams more convincing.
8. Back Up Important Files
Store University files in approved services such as Microsoft OneDrive. Cloud storage can help protect your work if a device is lost, damaged or otherwise unavailable while allowing you to access files from supported devices.
9. Be Mindful on Social Media
Review the privacy settings on your social media accounts and consider what information is publicly visible. Posts, photos and profile details can reveal more information than intended.
Be cautious of unexpected connection requests and avoid publicly sharing information that could be used to answer security questions or impersonate you.
10. Monitor Your Accounts
Review financial, social media and other important accounts regularly for activity you do not recognize. Pay attention to unexpected password reset messages, authentication requests or notifications about changes to your account.
If you believe a University account or device may have been compromised, report the issue promptly so it can be investigated.

