INFORMING, CONNECTING AND EMPOWERING EDUCATORS

From Passwords to Phishing: Cybersecurity Tips

Have you ever clicked a suspicious link, reused the same password one too many times or opened an email attachment before thinking twice? You are not alone. In today’s digital world, even the most cautious educators are facing a growing number of online threats both at work and at home, and cybercriminals are becoming increasingly effective at disguising their attacks.

According to Andy Beardsall, The Society’s Information Technology Administrator, phishing scams remain one of the biggest risks facing educators and the attacks have become far more sophisticated in recent years.

“What we’ve been seeing is the sophistication of phishing attacks have stepped up significantly,” said Beardsall.

Artificial intelligence (AI) tools have made phishing attempts more convincing by improving grammar, writing, and images and making the scams appear more realistic, while also automating the attack efforts.  At the same time, cybercrime has become more accessible through services that allow attackers to launch campaigns without advanced technical skills.

Teachers can receive phishing emails through school and personal email accounts, text messages, voice calls and even workplace communication platforms such as Microsoft Teams.

“Pretty much everywhere you could receive phishing,” said Beardsall.

While school divisions continue to strengthen cybersecurity measures, Beardsall said staff members play an important role in protecting themselves and their organizations.

“It’s important for the members to follow any of the policies and guidelines put out by their school division, because it will be specifically tailored to the security tools that they have in place,” he said. “Doing the basic good housekeeping for cybersecurity will protect you 99 per cent of the time.”

Cybersecurity tips:

  1. Use strong, unique passwords for every account.
  2. Enable multifactor authentication wherever possible.
  3. Be skeptical of urgent or unexpected messages sent by email, text, voice call or messaging platforms.
  4. Install software and device updates promptly so that security remains current.
  5. Report suspicious emails, lost devices or potential security incidents to your IT department immediately.

Andy Beardsall, The Society’s Information Technology Administrator, says schools are attractive targets because they contain large amounts of personal information and can be vulnerable to ransomware attacks.

Common Mistakes to Avoid

One common mistake is reusing passwords across multiple accounts. Beardsall said that attackers often compromise less secure accounts and then attempt to use the same password elsewhere.

Another misstep is opening links or attachments without first confirming they are legitimate. Hackers often make emails look urgent or important to pressure you into acting quickly. They can also “spoof” an email address, making a message appear to come from someone you know or trust, such as a colleague, your school division or a familiar organization, when it is coming from a scammer. Because email addresses and sender names can be faked, always take a moment to verify unexpected messages before clicking links, opening attachments or sharing personal information.

“If you have an email that you’re skeptical of, wait and open it on your laptop or your computer where you can fully inspect the sender, and all the information before acting on it.”

Schools are attractive targets because they contain large amounts of personal information and can be vulnerable to ransomware attacks.

“There is a huge amount of personal data on students and teachers,” said Beardsall. “And any organization with money in a bank account is a target.”

He recommended members consult their division’s Information Technology (IT) departments before using unfamiliar tools or services. This includes websites where teachers can download free lesson plans, videos or PDFs.

Multi-factor authentication is important in keeping passwords secure, with authentication apps such as Google Authenticator and Microsoft Authenticator being a better choice than receiving codes over text. Using a strong, unique, and long password offers the best protection, as well as updating it at least once a year.

Beardsall noted the importance of reporting potential incidents to your division’s IT department quickly. He added that educators should not feel embarrassed if they accidentally click a suspicious link.

“There is no shame in contacting your IT department,” he said. “The sooner they know, the sooner they can investigate and potentially limit the impact of a breach.”

Tools for Teachers

While they do not replace comprehensive cybersecurity training that can be accessed through your school division, Beardsall recommends the following informational tools for teachers: