Cyber Security Month: Week 1

Why awareness matters all year round 

As I’m sure many of you know, there have been a lot of big cyber attacks over the last 12 months. Retail was hit hard by ShinyHunters, who then moved on to Salesforce and, more recently, Instructure’s Canvas. Jaguar Land Rover was hit so badly that the Government had to step in with a loan guarantee. All of this has led to new legislation, and the Cyber Security and Resilience Bill, which is making its way through Parliament just now. It will force stricter security practices on certain high risk sectors, particularly around supply chain management. 

That last point matters because so many recent incidents started with a weakness in someone else’s systems rather than the victim’s own. We’ve had to respond to that and have brought in new tools to help us assess and manage third party risk, and we’re a lot stricter about third party access than we used to be. 

Passwords are another example of things changing. They’re close to being considered a legacy method now, which is interesting when you think how long we’ve relied on them. Stolen and compromised passwords keep turning up in attacks, and Microsoft is moving towards passkeys as a stronger alternative. You will see more about passkeys over the next few months as we start to shift to more secure authentication.  

You might be surprised (or might never have thought about it) that we’ve had a few incidents of our own over the years. We’ve recreated some of them here: Cyber Attack Insights: Learning from Real Incidents 

They’re a reminder that we must keep up with new methods, and that we need to find ways of keeping you informed without wearing you out. We try to share only what’s relevant, and mostly when I need you to do something or be aware of a particularly prolific method. We have technical controls in place, but for something like phishing, awareness is still the best defence we have.  

This is why the quarterly training matters. It is built it around recent attacks and changes in the cyber landscape, so you know what to look out for. The training is essential for all staff, but completion is sitting at around 30% and I’d love to see it closer to 50% by the end of Cyber Security Month.   

Training Details (Staff)  

All staff are required to complete the essential Cyber Security training through Metacompliance. You can access it in two ways: 

  • Via the Metacompliance app in Microsoft Teams (look for it in the left-hand panel) 

No login is required; you should be able to start immediately. The course is made up of multiple modules, so you can work through it at your own pace and complete it in stages. 

 If you haven’t yet completed the training, you’ll receive reminders from CyberAwareness@stir.ac.uk. 

Training Details (Students) 

  • Cyber Resilience - Familiarise yourself with the essentials of cyber resilience. Spot phishing, avoid scams, stay safe online, manage passwords, and protect your devices. 

Be aware of how much you share publicly 

The most convincing phishing and scam attempts aren’t generic. They use details about you that are easy to find, like your role, who you work with, or something you posted last week. This article from GEANT [LINK] explains how cyber criminals use publicly available information to manipulate people. If you’d rather watch than read, try these instead: 

  • Cybercrime for Newbies: How much can Granny Smith find out about you? A harmless picture here and a social media post there can add up to a detailed profile that criminals use to target us. What are you sharing? 
  • Jake Doubt Video Series: Social engineering meets true crime. When cyber criminals target staff at the University of Guilder, Head of Security Jake Doubt follows the digital breadcrumbs. Each episode looks at a real tactic used to deceive people, including deepfakes, romance and social media scams, and tailgating. 

What I’d like you to do 

I know I ask for a lot, and I know everyone is busy but, over the next month, I’d like you to: 

  • Take a look at the awareness materials we’ll be sharing each week 
  • Complete the cyber awareness training by the end of October 2026 
  • Tell me what you think. If you have feedback, questions, or something you’d like covered, get in touch at CyberAwareness@stir.ac.uk  

And one more thing, because it matters. If you click on something by accident or make a mistake, it’s okay. It happens to everyone, including people who do this for a living. What makes the difference is how quickly we find out. The sooner you tell me, the sooner we can protect your account and your device and limit the impact. Please report it straight away at information.centre@stir.ac.uk and there’s no need to worry about how it looks. 

Leave a Reply

Your email address will not be published. Required fields are marked *