Cyber security support & top tips
Ensure your devices are secure and that you're safe from malicious attacks.
Follow these cyber security tips and stay vigilant against online threats targeting your data, accounts and devices.
Cyber security threats are constantly increasing, which is why we've invested in comprehensive defensive measures to protect you from digital dangers.
Understanding how to manage your own cyber risks at uni, home and public spaces is important for your safety. Theft of your personal information, unauthorised tracking of your online activities or installation of malware onto your devices could result if you don't take the appropriate protective measures.
What to do if your account or device is compromised
Affected UNSW devices or accounts
If you believe your account or device has been affected by malware, report the cyber security incident by submitting an online form immediately.
UNSW data breaches
UNSW has published a new Data Breach Policy and Procedure. It's aimed at identifying, assessing, managing and responding to a breach of data held by UNSW. You can view the procedure and learn more on the Sharepoint site.
Common examples of data breaches include loss or theft of a device containing UNSW data, unauthorised access to UNSW systems, loss of user login details or any loss of data through a cyber-attack. As soon as you suspect or confirm that a breach has occurred, report it immediately to the UNSW IT Service Centre.
See also
Beware of malicious Wi-Fi networks
Avoid connecting to public Wi-Fi networks if you're in a public space, such as cafes, bars and restaurants. If possible, use your mobile phone's hotspot instead.
Quick & easy tips
Here's how you can improve your cyber security in just a few quick steps!
-
You know those pop-ups on your laptop, phone and other devices telling you a system update is available? Pro tip: don’t ignore them!
Latest versions of your device's operating system (OS) will include enhanced security features that older versions lack. Simply keeping your OS up-to-date is a low-effort way to keep your devices and information safe.
What we recommend
- Enable automatic updates where possible
- Avoid delaying updates when reminders appear
- Allow updates to download over mobile data and not just Wi-Fi (if you're on a mobile plan that can accommodate it)
- Restart your device regularly to auto-install updates.
-
Our devices can be vulnerable to malware, even through basic interactions with web-based services and software. Security software (like antivirus software) is typically used to protect devices, servers and networks from unauthorised access, viruses and other threats. This can be installed separately or integrated into an operating system.
What we recommend
- Look for security software that offers a multi-layered defence system. This includes features like anti-virus, anti-phishing, anti-malware, safe browsing and firewall capabilities.
- Check your device's built-in security software and ensure it's up to date.
-
Passwords, pins, patterns and security questions are important barriers for preventing unauthorised access to your accounts.
What we recommend
- Use different passwords for different accounts.
- Use a password manager to store your passwords in an encrypted format.
- Don’t store passwords or answers to security questions in plain text on your system or anywhere accessible to others.
Our protective measures for you
We've strengthened the password requirements for your UNSW accounts to help keep your information safe. If you need to change your password, please use the UNSW Identity Manager self-service portal.
To use all portal services, ensure you have a personal email address OR mobile number registered on myUNSW.
-
Multi-Factor Authentication (MFA) is an electronic verification method that requires two or more steps of authentication to provide access to online accounts, apps and other digital services.
Some online accounts may ask for your password (which is the first 'factor of authentication'). Afterwards, you'll be asked to input a one-time code (this is the second 'factor of authentication'). This one-time code may be sent to you by SMS or to a device you own.
What we recommend
- If you receive an email, SMS or notification from your MFA app triggered by a login attempt that wasn’t you, don't accept it. Reset your password and report the issue.
- Not all forms of MFA are equal. Mobile app-based login prompts with number matching (like the Microsoft Authenticator App) are stronger than SMS-based ones. Use strong MFA where possible, especially for private email accounts and cloud storage services.
Adding extra defence to your university accounts
At UNSW Bengularu, we use the Microsoft Authenticator App for all Single Sign-on (SSO) applications. These include your student email, myUNSW and Moodle. This ensures that only you can access your accounts and any sensitive information they contain.
-
Email and text messages are a popular way for cyber criminals to exploit individuals and organisations. Techniques like phishing and smishing (SMS-based phishing) are used to trick users into clicking malicious links, downloading attachments infected by malware or sharing sensitive information. These attacks are often disguised as legitimate emails from trusted sources, making it difficult for users to identify the threats.
Successful mail-based and text-based attacks can lead to data breaches, unauthorised access to systems, financial losses and reputational damage.
What we recommend
- Report all potential phishing emails. Your personal email service provider will have a way to let you do this. Follow the instructions for Outlook, if you are using your UNSW Bengaluru account
- Avoid opening attachments or links from unsolicited emails. Remember, you can check the identity of a sender via secondary methods, such as by phone or in-person, or search for the site via a search engine
- Never open emails that make outlandish claims or offers that seem “too good to be true”
- Enable mobile device security spam filters where possible. Learn more for Apple and Android
- Beware of suspicious messages requesting personal details or containing links.
What to do if your UNSW Bengaluru account has been affected
If you think you have clicked on a phishing link or downloaded a malicious attachment sent to your inbox, act fast. Report the cyber security incident to UNSW IT Service Centre.
When you report potential phishing emails, UNSW Cyber Security will identify other mailboxes the phishing email could have reached and invoke our incident response practices.
If you receive a communication about your program, enrolment or related matters and you're not sure if it's legitimate, contact the UNSW Bengaluru Student Centre to verify it.
-
Backup and recovery methods ensure that important information stored on your devices and applications is accessible to you elsewhere. If the primary location is disrupted, you can then restore the data from your secondary location. This is a common way to prevent data loss issues.
What we recommend
- Regularly back up personal information stored on devices to your preferred collaboration and storage platform
- Use strong passwords and MFA for your chosen storage platforms
- Encrypt laptops, PCs and mobile devices so they can't be tampered with if stolen.
Backing up your university data just got easier
As a UNSW Bengaluru student, you have access to Microsoft Office 365 services, including OneDrive and SharePoint. These services can help you encrypt and synchronise uni-related information. This ensures that you can safely access your data across your devices.
Advanced tips
Learn additional tips on how you can improve the security of your online ecosystem.
-
Your network router serves as the entry point to your home network. Without adequate security measures and timely updates, network routers become more susceptible to compromise. This can endanger other devices connected to the network.
What we recommend
- Keep routing devices on your home network up-to-date with the latest patches (preferably through automatic updates). This will minimise vulnerabilities and enhance security.
- Replace routing devices when they reach their end-of-life (EOL) for support. This allows them to continue receiving updates and patches as new vulnerabilities are discovered.
- Consider using your own routing device alongside the modem/router provided by your Internet Service Provider (ISP). This will give you greater control over your home network's routing and wireless capabilities.
- Use modern router features to establish a separate wireless network specifically for guests. This will segregate it from your more trusted and private devices. Most network routing devices also allow configurations to block certain types of network traffic.
-
If your Wi-Fi connection isn’t secure, it can be used to steal sensitive information (such as passwords and documents) and to infect your devices with malware.
What we recommend
Ensure that your personal or ISP-provided Wireless Access Point (WAP) supports Wi-Fi Protected Access 3 (WPA3). When setting up WPA3 or WPA2/3:
- Use a robust passphrase to your network device with a minimum length of fourteen characters;
- Modify the default Service Set Identifier (SSID) to a unique value;
- Avoid hiding the SSID. This does not provide any additional security to your wireless network and may cause compatibility issues.
-
Most current home networks consist of different devices, including laptops, PCs, phones, tablets, gaming consoles and other smart devices. These are often from different manufacturers and come with varying degrees of security. Keeping the devices on separate networks can prevent malicious activity from pivoting from device to device.
What we recommend
Implement network segmentation within your home network by creating distinct segments for your primary Wi-Fi, guest Wi-Fi, and IoT network. This segregation ensures that less secure devices are prevented from directly interacting with your more secure devices.
-
Email security protocols add mechanisms to protect your email from threats, maintain privacy and ensure the overall security of communication.
What we recommend
For your personal email accounts, use email services that employ secure means of authentication. These might include strong Multi-Factor Authentication (MFA) and robust encryption protocols such as Transport Layer Security (TLS).
Communicate through UNSW Bengaluru email accounts with ease of mind
Email is the most widely used communication tool between students and academic staff. Students have access to our secure email system hosted by Microsoft Office 365. This system has extensive cyber security controls, including anti-phishing and anti-malware protection.
Need help?
The UNSW IT Service Centre is here to assist you with issues regarding your devices, accounts, cyber security and network issues. We're here to help.