This broad term describes malicious software designed to damage, disrupt, spy on, or gain unauthorized access to a system.
What is Malware?
A fraudulent message designed to trick someone into revealing information, clicking a malicious link, or opening an attachment.
What is phishing?
This security control requires something beyond your password—such as an authenticator app, security key, or biometric—to sign in.
What is multi-factor authentication (MFA)?
This technology creates an encrypted connection between your device and another network and is commonly used for secure remote access.
What is a VPN?
You accidentally click on a suspicious link but nothing appears to happen. This should be your next move.
What is report it to DivTech/Service Desk?
This type of malware encrypts or locks access to data and demands payment to restore it.
What is ransomware?
Phishing delivered specifically through text messages has this name.
What is smishing?
Instead of a short, complicated password, security guidance often recommends using a longer sequence of memorable words known as this.
What is a passphrase?
This process transforms readable information so that someone without the appropriate key cannot understand it.
What is encryption?
You receive an unexpected email from someone you know asking you to open a document. The messages feels unusual. Before opening it, you should do this.
What is verify the request through a trusted/separate method?
An attacker manipulates a person rather than exploiting technology to convince them to reveal information or perform an action.
What is social engineering?
Instead of sending an email or text, this phsihing technique uses a phone call or voice message.
What is vishing?
This tool securely stores credentials and can generate unique passwords so you don't have to remember every one.
What is a password manager?
This principle says that users should receive only the access necessary to perform their job—and nothing more.
What is least privilege?
Your authenticator suddenly asks you to approve a login you didn't initiate. You should deny it and do this immediately afterward.
What is report the unexpected authentication attempt? (and change your password)
This security risk comes from someone who already has legitimate access to an organization's systems or information.
What is an insider threat?
Unlike mass phishing, this attack is carefully crafted for a particular person or organization.
What is spear phishing?
Your password is long, complex, and impossible to guess—but you use the same one for your work account, email, and several websites. This practice is still your biggest password-related risk.
What is password reuse?
Rather than relying on one security control, this strategy uses multiple overlapping safeguards so another control can still protect the organization if one fails.
What is defense in depth?
You realize your agency laptop or phone is missing. Even if you think you know where you left it, you should do this promptly.
What is report the lost device?
Attackers compromise a trusted vendor, product, or service as a way to reach it's customers.
What is a supply-chain attack?
You spotted the phish! Deleting it protects your inbox, but using this outlook feature helps the Cyber Security team identify and respond to the threat.
What is the Phish Alert Button?
Instead of trying thousands of passwords against one account, attackers try a small number of common passwords against many accounts to avoid lockouts.
What is password spraying?
An website asks for your username. An attacker gives it database commands instead, hoping the application will execute them. This classic web attack is known as this.
What is SQL injection?
While working, your computer suddenly begins displaying security alerts, behaving strangely, or showing signs that it may be compromised. Rather than investigating it yourself, your priority should be this.
What is stop using it and contact the DivTech/Service Desk?