Skip to main content
  • Home
  • About
  • Faculty Experts
  • For The Media
  • ’Cuse Conversations Podcast
  • Topics
    • Alumni
    • Events
    • Faculty
    • Students
    • All Topics
  • Contact
  • Submit
Campus & Community
  • All News
  • Arts & Culture
  • Business & Economy
  • Campus & Community
  • Health & Society
  • Media, Law & Policy
  • STEM
  • Veterans
  • University Statements
  • Syracuse University Impact
  • |
  • The Peel
  • Athletics
Sections
  • All News
  • Arts & Culture
  • Business & Economy
  • Campus & Community
  • Health & Society
  • Media, Law & Policy
  • STEM
  • Veterans
  • University Statements
  • Syracuse University Impact
  • |
  • The Peel
  • Athletics
  • Home
  • About
  • Faculty Experts
  • For The Media
  • ’Cuse Conversations Podcast
  • Topics
    • Alumni
    • Events
    • Faculty
    • Students
    • All Topics
  • Contact
  • Submit
Campus & Community

Navigating Cybersecurity: How to Be Your Own Human Firewall

Thursday, October 10, 2024, By Christine Grabowski
Share
Information Technology Services
Hands typing on a laptop keyboard

Photo by Marilyn Hesler

Andrew McClurg, with Information Technology Services (ITS), is often asked how people can stay safe online to protect against scams and hackers. He breaks it down to some basic points to remember.

“I always focus on four main things: passwords, multi-factor authentication (MFA), keeping software updated and knowing how to spot phishing emails and how to report them,” says McClurg, an IT analyst with the Information Security (InfoSec) team.

Person with glasses wearing a navy blazer and plaid shirt, smiling at the camera.

Andrew McClurg

SU News caught up with McClurg for a Q&A on the best tips during Cybersecurity Awareness Month. Established in 2004 by Congress and the White House, the initiative raises awareness about cybersecurity’s importance and ensures people have the resources to be safer and more secure online.

For the University, InfoSec team members do everything they can to keep your experience online as safe as possible. As part of securing users and their data, the University has firewalls in place; these are security systems that monitor and control network traffic to protect a computer or network from cyberattacks. The challenge, however, is that hackers are getting smarter than ever. To stay safe online, you need to be your own human firewall.

What does that look like exactly? McClurg explains.

What can we do to keep our passwords safe?

  • Make sure all your passwords are unique across your accounts.
  • Create complex passwords.
  • Use long memorable phrases or song lyrics with numbers and special characters.
  • Never share your passwords with others. ITS staff will never ask for or need your password to assist you.
  • Setup a password manager to keep track of and monitor your passwords. This will suggest strong passwords, alert you to passwords that have appeared in data leaks and flag passwords used across accounts.

Why should we enable MFA?

MFA adds an extra layer of security to your accounts by requiring a second form of verification, such as a code or login approval request sent to your mobile device or email, in addition to your password. MFA requests could also require a biometric component, such as a fingerprint or facial recognition. The University requires the Microsoft Authenticator. Something important to keep in mind is that you should never share your MFA codes with others and ITS staff will never ask for or need your MFA code to assist you.

Want to learn more about MFA? Visit our Answers page.

How do software updates play a role in keeping devices secure?

In addition to new features and general maintenance, software updates often include security patches that close vulnerabilities that bad actors might use to install malware, steal data or launch other types of attacks. It is recommended to keep your systems updated to strengthen your security posture. Often operating systems (e.g. Windows, macOS, Android, iOS) and some software offer automatic updates to make this process easier for the user.

What is a phishing email and what should I do if I receive one?

Phishing emails are a common tactic used by cybercriminals to steal sensitive information. You should be wary of unexpected emails, especially if they ask for personal information, create a sense of urgency or contain suspicious links/attachments.

If you receive a suspicious email, be sure to consider the following:

  • Does the URL look right?
    • On your smartphone or tablet, press the link and hold down until a dialog box appears containing the URL.
    • On your computer, hover over the link with your mouse. The URL will usually appear in the lower-left corner of your window.
  • Does the login screen look right? Do not enter your NetID and password unless you are certain it is safe.
  • Are you expecting the document or link? Be suspicious of unexpected emails sharing documents and links. If you are not sure, contact the sender (preferably via text message, phone or an alternative email address) and ask if they shared a document with you.
  • Do you know the person sharing it? Consider the message suspicious if you do not know the person the message is from. Be aware, though, that phishers often use compromised accounts to send their messages, and they can also forge the sending address. If you feel at all unsure, call the person and ask if they shared a document or link with you.
  • Can you tell what the document is? Is it clear to you from the document title and message what the document is and why the sender is sharing it with you? Phishers often send vague messages that just say a document has been shared with you. They rely on your curiosity. Do not open suspicious shared documents just to see what they are.
  • Beware of flattery. Customized emails that compliment research and ask you to look at a shared document or link related to it. If it looks suspicious, do not log in.
  • Be suspicious of emails offering deals that seem too good to be true. For example, remote work that pays exceptionally well for little time investment or offers of heavily discounted or even free technology hardware, tools and musical instruments. A favorite of the security team is the free baby grand Yamaha piano, which appears several times each year.

You can report suspicious emails by using the Report Phishing function within Microsoft Outlook. This will alert the security team who will take the appropriate actions to remediate the incident, which may include deleting the email from all inboxes, locking accounts if sent from a Syracuse account and blocking the sender. Additionally, for the latest list of phishing emails that have recently circulated throughout the Syracuse University community, visit the ITS Phish Bowl.

  • Author

Christine Grabowski

  • Recent
  • NSF I-Corps Semiconductor and Microelectronics Free Virtual Course Being Offered
    Wednesday, July 16, 2025, By Cristina Hatem
  • Jianshun ‘Jensen’ Zhang Named Interim Department Chair of Mechanical and Aerospace Engineering
    Wednesday, July 16, 2025, By Emma Ertinger
  • Traugott Professor of Mechanical and Aerospace Engineering Bing Dong to Present at Prestigious AI Conference
    Wednesday, July 16, 2025, By Emma Ertinger
  • Lender Center Researcher Studies Veterans’ Post-Service Lives, Global Conflict Dynamics
    Tuesday, July 15, 2025, By Diane Stirling
  • Maxwell’s Robert Rubinstein Honored With 2025 Wasserstrom Prize for Graduate Teaching
    Tuesday, July 15, 2025, By News Staff

More In Campus & Community

Lender Center Researcher Studies Veterans’ Post-Service Lives, Global Conflict Dynamics

Corri Zoli ’91, G’93, G’04 was recently named a research associate of the Lender Center for Social Justice. She applies social science, law and public policy perspectives to problems of warfare, governance in modern human conflicts and the role of…

Maxwell’s Robert Rubinstein Honored With 2025 Wasserstrom Prize for Graduate Teaching

Robert Rubinstein, Distinguished Professor of Anthropology and professor of international relations in the Maxwell School of Citizenship and Public Affairs, is the recipient of the 2025 Wasserstrom Prize for Graduate Teaching. The prize is awarded annually to a faculty member…

National Ice Cream Day: We Tried Every Special at ’Cuse Scoops So You Don’t Have To

National Ice Cream Day is coming up on Sunday, July 20, and what better way to celebrate than with a brain freeze and a sugar rush? Armed with spoons and an unshakable sense of duty, members of the Syracuse University…

Message From Chief Student Experience Officer Allen W. Groves

Dear Members of the Orange Community: It is with profound sadness that I write to remember two members of our Syracuse University community, whose lives were cut short last Thursday when they were struck by a vehicle at the intersection…

Haowei Wang Named Maxwell School Scholar in U.S.-China/Asia Relations

Haowei Wang, assistant professor of sociology in the Maxwell School of Citizenship and Public Affairs, has been named the Yang Ni and Xiaoqing Li Scholar in U.S.-China/Asia Relations for the 2025-26 academic year. Wang’s one-year appointment began on July 1….

Subscribe to SU Today

If you need help with your subscription, contact sunews@syr.edu.

Connect With Us

  • X
  • Facebook
  • Instagram
  • Youtube
  • LinkedIn
Social Media Directory

For the Media

Find an Expert Follow @SyracuseUNews
  • Facebook
  • Instagram
  • Youtube
  • LinkedIn
  • @SyracuseU
  • @SyracuseUNews
  • Social Media Directory
  • Accessibility
  • Privacy
  • Campus Status
  • Syracuse.edu
© 2025 Syracuse University News. All Rights Reserved.