Security Awareness
The Office of Information Security and Privacy (OISP) in the Office of Technology Services (OTS) provides Cybersecurity Awareness resources for Towson University.
Protect yourself and TU
Security Best Practices
- Stay informed with the cybersecurity advisory list (login required), which describes current threats affecting the general population and see examples of recent scams at TU through the Phish Tank.
- Trust your instincts. If something feels suspicious, or too good to be true, it probably is.
- Take your time. Think before responding to urgent requests.
- When in doubt, consult. Talk with your supervisor or contact the Office of Information Security and Privacy through TechHelp.
- Report it. Forward suspicious email to phishing AT_TOWSON, then delete. If you think your account has been compromised, let us know immediately through TechHelp. Learn more.
Recognize and report phishing
- The Threat: phishing is a cyberscam executed through email, text and social media.
- Red Flags: urgent alerts about hacked accounts, unbelievable or fake job offers, or requests for gift cards and cryptocurrency.
- Action: never click suspicious links. Go directly to official websites to confirm. If received in your university account, check against current scams in TU’s Phish Tank and forward it to phishing@towson.edu. Bookmark towson.edu/phishing for easy access to the Phish Tank link and find quick reporting how-to's.
Update software
TU manages university-owned and campus computers, but always run prompted updates asap. On personal devices enable auto-updates for your operating system and apps, and restart your device regularly to ensure security patches install properly. Learn more.
Use secure passwords
Cybercriminals have developed sophisticated programs to guess your passwords. To protect yourself, it is important to create a strong password that cannot be easily hacked. Refer to TU's password guidelines when creating a Towson University NetID or other online password. Be sure to use a unique password for each of your personal accounts.
Explore cybersecurity careers
Looking to get started on a cybersecurity career path? Check out TU’s Department of Computer & Information Sciences for info and opportunities.
Use Multi-Factor Authentication
Everyone with a NetID uses Duo MFA to protect their TU account. Learn about MFA and using it on your personal accounts in this National Cybersecurity Alliance article.
Getting Duo prompts you didn’t request? These are called MFA Bombing/Fatigue Attacks. Follow these best practices:
- Never approve Duo MFA prompts you didn’t initiate.
- Report repeated, unsolicited MFA notifications immediately through TechHelp.
- If you continue to receive unexpected authentication requests, contact the OTS Tech Support Desk.
Host secure online meetings
See and follow the Webex and Zoom security guidelines, which include specifics for hosting meetings, and settings to consider before, when scheduling, and during meetings. For confidential/sensitive online meetings:
- Follow the above security guidelines.
- Be extra diligent about protecting TU confidential data.
- Understand TU's definition and classifications of confidential data.
- Ensure the meeting is password protected, which requires participants to enter a password to join.
- Confirm meeting topics or calendar invites do not include any sensitive information.
- Make sure sensitive meetings are not recorded. Instructional meetings may be recorded with prior consent.
Security Checks
Use these resources and tips from the National Cybersecurity Alliance to better secure your online accounts and digital devices and keep your data safe.