The front line of critical infrastructure security: You

Every day, essential services depend on secure technology. Hospitals rely on electronic health records. Universities depend on learning platforms, research systems, financial applications and secure communications. Public agencies, utilities and businesses use interconnected systems to deliver services that communities need. 

During Cybersecurity Awareness Month 2026, the theme “Securing the Next 250” asks us to consider how today’s cybersecurity decisions will help protect America’s next era. That protection begins with one of the most common entry points for cyberattacks: phishing. 

What Is Phishing? 

Phishing is an attempt to trick someone into revealing information, approving an action, opening a malicious attachment or visiting a fraudulent website. Phishing may arrive through: 

  • Email 
  • Text message 
  • Phone call 
  • Microsoft Teams or another collaboration platform 
  • Social media 
  • QR code 
  • Shared document notification 
  • Unexpected multifactor authentication prompt 

Attackers frequently impersonate trusted organizations or people. A message may appear to come from a university leader, coworker, bank, delivery service, technology company or benefits provider. 

Watch for Social Engineering 

Social engineering is the use of manipulation to persuade someone to take an unsafe action. Attackers frequently create a sense of: 

  • Urgency: “Respond in the next 10 minutes.” 
  • Fear: “Your account will be disabled.” 
  • Authority: “The president needs this completed immediately.” 
  • Secrecy: “Do not tell anyone about this request.” 
  • Opportunity: “You are eligible for a refund.” 
  • Curiosity: “Review the confidential document.” 
  • Helpfulness: “Can you purchase gift cards for an event?” 

The message may contain correct names, job titles, logos or information gathered from public websites. Familiar information does not prove that a message is legitimate. 

Pause Before You Act 

Before selecting a link, opening an attachment, scanning a QR code or providing information: 

  1. Check the sender’s full email address. 
  2. Consider whether the request is expected. 
  3. Hover over links to inspect the destination. 
  4. Be suspicious of unexpected sign-in pages. 
  5. Verify unusual requests through a separate communication method (i.e., call the person instead of responding back to the suspicious email received.) 
  6. Never approve an unexpected authentication prompt. 
  7. Report suspicious messages using NEOMED’s reporting process. 

Do not use the phone number, link or reply address contained in a suspicious message to verify it. Instead, locate known contact information independently. 

Protect Your Credentials 

Your password and authentication approval are equivalent to keys. NEOMED IT will not ask you to provide your password by email, telephone, text message or online form. 

If a website asks you to sign in, inspect the address before entering your credentials. Password managers can help because they generally will not automatically enter credentials on an unfamiliar or fraudulent domain. 

Think You Are a Victim of Social Engineering/Phishing? 

Report the incident immediately. Quick reporting allows the security teams to investigate and contain possible damage! 

Some examples of incidents worth reporting include: 

  • Entering your password on a suspicious website. 
  • Approving an authentication request you did not initiate. 
  • Opening an unexpected attachment. 
  • Downloading or running unfamiliar software. 
  • Sending sensitive information to the wrong recipient. 
  • Purchasing gift cards or transferring money based on a suspicious request. 
  • Believing someone may be using your account. 

If this involves your NEOMED account or University data, contact the Help Desk as soon as possible. NEOMED IT would rather investigate a false alarm than discover an incident after significant damage occurred.  

If this involves your personal accounts or information, contact the respective company's customer service line for assistance. Some other considerations to keep in mind: 

  • Watch for any unauthorized charges to your account(s). If you believe your personal financial accounts may be compromised, contact your financial institution immediately to get guidance on freezing or closing the account(s). Additionally, you can flag your credit reports by contacting the fraud departments of any one of the three major credit bureaus: Equifax (800.685.1111); TransUnion (888.909.8872); or Experian (888.397.3742). 
  • Consider reporting personal attacks to your local police department and filing a report with the Federal Trade Commission or the Internet Crime Complaint Center. Make sure you keep a copy of the police report in a safe place. 

Prompt reporting is a responsible security action, not an admission of failure! 

Put it Into Practice! 

Before responding to an unexpected request, pause and independently verify it. A brief delay can prevent account compromise, financial fraud, data loss and disruption of essential services. 

Share this post