A fake email or message designed to trick you into clicking a link, sharing information, or taking another unsafe action.
Phishing
A secret combination of characters used to protect access to an account.
Password
Harmful software designed to damage, disrupt, spy on, or gain unauthorized access to a computer or device.
Malware
Before sensitive information like PII or PHI makes its way into an AI tool, this recently adopted security platform helps detect it.
STRAC
Someone you don’t recognize follows you toward a badge-only door and asks you to hold it open. What should you do?
Do NOT let them in
A message that appears to be from your boss urgently asks you to buy gift cards. What should your first step be?
Report the email by clicking the fishing hook in my email
This security feature requires more than just your password to prove that you are really you.
Multi Factor Authentication (MFA)
This type of malware locks or encrypts files and demands payment to get them back.
Ransomware
A message contains your name, job title, and details about your company. True or false: Those personal details prove the message came from someone you know.
False
An email appears to come from a coworker, but the request seems unusual. What should you do before acting?
Verify the coworker/email
This part of an email should be checked carefully because scammers may change just one letter to make an address look legitimate
Sender's Email Address
Instead of remembering dozens of unique passwords, this tool can securely create and store them for you.
Password Manager
A fake video or audio recording created with AI can make it appear that a real person said or did something they never did.
Deepfake
An employee pastes confidential company information into an unapproved public AI tool because they only want it to “summarize the text.” What's the security problem?
Exposing confidential Information
An attacker calls the pretending to be an employee and uses information from LinkedIn to answer questions convincingly. What are they trying to exploit?
Trust
This type of phishing attack is personalized for a specific person or group instead of being sent to thousands of random people.
Spear Phishing
You receive an MFA approval request on your phone, but you aren't trying to sign in. What should you do?
Deny/Report
An incident where sensitive or confidential information is accessed, stolen, or exposed without authorization.
Data Breach
When AI confidently produces information that sounds believable but is actually incorrect or made up, it's commonly called this.
AI Hallucination
Someone enters a secure area by following an authorized employee through the door without badging in. This is called what?
Tailgating
This phishing scam involves a criminal pretending to be a company executive, employee, or vendor to convince someone to send money or sensitive information.
Business Email Compromise (BEC)
Attackers repeatedly send login approval notifications to your phone, hoping you'll eventually get annoyed and press “Approve.”
MFA Fatigue
An attacker secretly watches communication between two parties and may intercept or alter the information being exchanged. This is known as this type of attack.
MITM (Man-In-the-Middle) attack
An employee removes customer names before entering data into an AI tool, but leaves email addresses and phone numbers. What type of information could still be exposed?
PII
Who is the one person in InfoSec you should never trust? (The biggest troll)
Andrew Gjovik