Carnegie Mellon University
October 20, 2016

National Cyber Security Awareness Month: Our Shared Responsibility

Dear Students,

October is National Cyber Security Awareness Month.  This year’s theme is “Our Shared Responsibility”.  Nothing could be more true when it comes to cyber security.

We all play a role in keeping our electronic information, applications, computers, and networks secure and working effectively.   Recent events remind us of the importance of reporting concerns, backing up data, remaining vigilant to scams, and other good security practices.

1.       In recent months we’ve seen an increase in the frequency and sophistication of phishing scams that led to the release of Andrew credentials.   When we discover compromised Andrew credentials, the ISO temporarily suspends access to the account until the account owner contacts the Help Center to reset their password.  Learning how to detect and avoid phishing is a contribution you can make to reduce the possibility of losing access as a result of a successful phishing attack.  Visit the ISO’s website to access and play the Anti-Phishing Phil and Phyllis phishing awareness games.

2.        Ransomware is hitting campus at an increasing rate.  Ransomware is one the fastest growing security threats.  Files stored on or accessible from the infected computer are encrypted and ‘held hostage’ until a ransom is paid.  Ransoms range over several hundreds of dollars.   Having a good backup is often the only way to recover but we’ve also had success recovering if the user was not logged in with administrator privileges.  Ransomware is typically delivered via email scams and malicious websites so take care while surfing, clicking, and opening attachments.

3.         In recent weeks Yahoo reported a breach to 500 million user accounts and passwords.  Yahoo’s breach is a good reminder to periodically change your passwords (the breach actually occurred in 2014), never reuse your Andrew ID or password, and avoid setting the same password recovery questions and answers across multiple systems.  Password managers can make this task much easier.  Visit the ISO’s website to learn more about them.  If you receive a breach notice or request to reset your password from a third party and you used your AndrewID and/or password to create the third party account, change your Andrew password immediately.

Finally, if you would like to learn more about these and other topics and initiatives, visit the ISO’s NCSAM web page and plan to join a discussion in Rangos 3, CUC on Monday, October 24, 2016 from 12:00-1:30 (pizza served at 11:30!). We’ll discuss how you can take even more responsibility by considering a career in cybersecurity and how to secure your Google Apps and personal accounts. Details are available at  Space is limited, so please register for “National Cyber Security Awareness Month: Our Shared Responsibility” via Handshake (

Thank you for sharing the responsibility for keeping our systems and data safe.


Mary Ann Blair
Director of Information Security
Information Security Office
Computing Services
Carnegie Mellon University
Phone: 412-268-8556
ISO Hotline: 412-268-2044