Security Awareness
The Office of Information Security and Privacy (OISP) in the Office of Technology Services (OTS) provides Cybersecurity Awareness resources for Towson University.
Protect yourself and 91Ó°ÊÓÆÆ½â°æ
Security Best Practices
- Stay informed with the   (login required), which describes current threats affecting the general population and see examples of recent scams at 91Ó°ÊÓÆÆ½â°æ through the Phish Tank.
- Trust your instincts. If something feels suspicious, or too good to be true, it probably is.
- Take your time. Think before responding to urgent requests.
- When in doubt, consult. Talk with your supervisor or contact the Office of Information Security and Privacy through .
- Report it. Forward suspicious email to phishing AT_TOWSON, then delete. If you think your account has been compromised, let us know immediately through. Learn more.
Multi-Factor Authentication
Everyone with a NetID uses Duo MFA to protect their 91Ó°ÊÓÆÆ½â°æ account. Learn about
Getting Duo prompts you didn’t request? These are called MFA Bombing/Fatigue Attacks. Follow these best practices:
- Never approve Duo MFA prompts you didn’t initiate.
- Report repeated, unsolicited MFA notifications immediately through .
- If you continue to receive unexpected authentication requests, contact the OTS Tech Support Desk.
Password Security
Cybercriminals have developed sophisticated programs to guess your passwords. To protect yourself, it is important to create a strong password that cannot be easily hacked. Refer to 91Ó°ÊÓÆÆ½â°æ's password guidelines when creating a Towson University NetID or other online password.
Phishing
Phishing is a cybercrime targeting your email. Forward suspicious emails received in your 91Ó°ÊÓÆÆ½â°æ inbox to phishing AT_TOWSON. Learn more about different types of phishing, including social engineering and fraudulent job scams - and how to protect yourself and 91Ó°ÊÓÆÆ½â°æ on the phishing webpage.
Online Meeting Security
Follow the and security guidelines, which include including specifics for hosting meetings, and settings to consider before, when scheduling, and during meetings.
Confidential/sensitive online meetings:
- Follow the above security guidelines.
- Be extra diligent about protecting 91Ó°ÊÓÆÆ½â°æ confidential data.
- Understand 91Ó°ÊÓÆÆ½â°æ's definition and classifications of confidential data.
- Ensure the meeting is password protected, which requires participants to enter a password to join.
- Confirm meeting topics or calendar invites do not include any sensitive information.
- Make sure sensitive meetings are not recorded. Instructional meetings may be recorded with prior consent.
Security Checks
Use these from the National Cybersecurity Alliance to better secure your online accounts and digital devices and keep your data safe.