An urgent text message claiming your bank account is locked and instructing you to click a link to verify your identity.
Smishing (SMS phishing)
Combining something you know with something you have is known as this security measure.
Multi-Factor Authentication (MFA / 2FA)
The Windows keyboard shortcut key combination that instantly locks your computer screen before stepping away from your workspace.
Windows Key + L
OCCU's IT incident response plan lists this as the first action to take if you believe you may have a ransomware infection on your device.
Disconnect the device from the network immediately
A fraudster calls an employee over the phone pretending to be a vendor to trick them into giving up credentials.
Vishing (voice phishing)
Rather than creating short, complex passwords with symbols, security best practice is to string together four or more random words into this type of credential.
Passphrase
Only USB drives with this setting enabled are permitted to be connected to OCCU devices.
Encryption (or Bitlocker)
Member account information, social insurance numbers, and payroll records fall into which of OCCU's 3 data classification tiers?
Class 1 - Confidential
A highly customized email attack that targets specific people or departments using personalized details gathered about the organization.
Spear phishing
The dangerous practice of using the exact same password for both your work and personal online accounts
Password reuse (or credential recycling)
Watching an employee's screen through a window or from far away to view confidential information or credentials
Shoulder surfing
This class of OCCU data may be shared or made available to the general public.
Class 3 - Public (or unrestricted)
Registering a fake domain name that closely resembles legitimate company address (e.g., swapping a lower-case L for the number 1)
Typosquatting (or lookalike domains)
An automated attack technique where hackers attempt a small list of commonly used passwords across thousands of different account usernames simultaneously to avoid locking out any single account.
Password spraying
Connecting a device to an unencrypted public Wi-Fi network exposes communication to this type of interception attack.
Man-in-the-middle attack
According to OCCU's Acceptable Use Policy, users are restricted from using this specific web browser feature to save credentials.
Remember Me, or Remember my Password, or Trust this Device
Cybercriminals sending a large number of MFA push notifications to a user's phone, hoping the user clicks "Approve" out of frustration or confusion.
A sophisticated cyber attack where an active login session token is stolen directly from a user's browser, allowing the fraudster to impersonate the user without needing their password or MFA.
These steps should always be performed when allowing a vendor to access a secured area within the branch.
Telling a manager
Checking the vendor's ID or badge
Asking why access is required
Ensuring they are supervised
When leaving their workstation, employees must take this action for any PII, confidential and sensitive data or documents.