Welcome to September! The semester is in full effect, with academics, athletics. clubs, and work all vying for attention. I’m glad you chose to come read the September newsletter, as it contains some important announcements and information. There’s information on sensitivity labels, alumni accounts, credit card information, and Cybersecurity Awareness Month packed into this month’s edition.
First, let’s discuss sensitivity labels. You’ve seen in the movies where someone is carrying a folder around with a big red sticker on it that says “Top Secret” or something similar. That’s kind of what sensitivity labels do for all of the documents and files we create in our systems. Once sensitivity labels are turned on by default (you can use them now, they just aren’t automatically applied) every Word document, Excel spreadsheet, PowerPoint deck, email, and Teams conversation will automatically have a label digitally applied to it. The labels range from Low to Secret, with Medium and High in between. The default label will be High. This may preclude some normal actions for the file or email, such as forwarding or creating an anonymous link. You can read the definitions for these labels at this page. Further questions about how these will work are answered in the FAQ located here – although, I will note that the FAQ needs updated – when we wrote it we were not going to set a default sensitivity tag, but we changed our minds. We’ll get it updated as soon as we can. You can change the label if you created the file, but you must adhere to the definitions of Low, Medium, High, and Secret as defined in the document above. If you’d like even more gory details about data sensitivity labels, you can check out the Microsoft documentation here.
Why would we implement a technical control like this? More and more, data is not stored on a protected file server located on our local network, but it lives in the cloud, via Teams, OneDrive, Outlook and other software systems that store data outside of our local network. Sensitivity labels allow us to have some control over where the files can be stored, how they can be transmitted, and what can be done to them. It is yet another layer of security. As I have mentioned before, security is all about layers. Applying data sensitivity labels won’t make all of our documents totally secure, but they allow us to use more tools to protect them. IMPORTANT: Default data sensitivity labels will be enabled on Monday, September 21st.
As a reminder, alumni accounts older than two years will be removed October 14th. There was an email sent out on Monday, September 14th about this. This is another layer of security we are implementing to protect the college and its data. Many alumni accounts lay dormant after a student graduates. Dormant accounts are opportunities for cyber-criminals to pick up limited access to our systems. Limited access can, through potential vulnerabilities, lead to elevated access and bad things happening. We explain this better in the email, so go take a look at it if you are an alum reading this or are about to graduate.
Another layer of security coming in the future is the detection and blocking of unencrypted emails containing credit card info or other sensitive information. I talked about this at length in the August newsletter, so if you missed it, take a few minutes to go back and read it. We currently detect these emails and have a rough idea who may be impacted the most by this change. If you feel you are one of these departments or users who may be impacted, please reach out to me about it (after reading the August newsletter, if necessary).
Finally, October is almost here and that means it’s almost Cybersecurity Awareness Month! Every October we celebrate Cybersecurity Awareness Month with extra articles, emails and a virtual scavenger hunt! The VSH is back and it will, as usual, provide the chance to win a prize each week and a grand prize at the end of the month for those who complete the hunt. We are also planning to have a table in Krannert during October to interact face to face with people, so you can see and talk directly with the person who keeps sending out those emails about cybersecurity.
Our cybersecurity awareness training will also kick off in October and will only be available to complete during the month of October. There will be no complaining about how December is too busy to complete your cybersecurity awareness training, because if you don’t get it done in October, you won’t get it done at all. Therefore (that’s one of my favorite words, but I don’t get a lot of chances to use it), take a few minutes as soon as the training goes live to complete it. Every student who completes the training will be entered into a drawing for yet another prize (TBD – let me know what would be a cool enough prize to compel you to complete your training).
For all you faculty and staff, I’m taking the opposite approach. Each school will be in competition with the other schools and every college administrative department will be pitted against each other to get the highest percentage of users completing the training. While I will not be able to reward the top school and department, I will publish the rankings for bragging/shaming rights, so each school and department should appoint a “whip” or cheerleader to get everyone to complete their training (again, during October).
The last item I want to mention in relation to Cybersecurity Awareness Month is a new service I want to offer to everyone, which will be an Opt-in mailing list where you will get tips every week about cybersecurity. These “tips” will include helpful information about how to be more cybersecurity-savvy along with brief notes about current events in cybersecurity. They’ll be in addition to the monthly newsletter and could potentially make you the “guru” for cybersecurity in your area. More information about them and details on how to sign up will be in October’s newsletter.
That’s it for September. I hope everyone’s semester is starting out great!
All Berry students, faculty and staff have MFA enabled on their Berry account, and you should use it in the most secure way via the Microsoft Authenticator app on your smart phone. But don’t stop there! Use the Microsoft Authenticator as your second factor on any site that supports Google Authenticator. Turn on MFA/2FA everywhere you can. Yes, it will take you another few seconds to log in, but your data and account will be safer.
Please continue to report those phishing emails! Avoid using “unsubscribe” links and report both spam and phishing via the “Report” button.
If I’m not covering a topic of cybersecurity you are interested in or concerned about, please let me know. I want to be your first and best resource on cybersecurity information, so tell me how I can help and inform you.
Check out https://support.berry.edu for more information about OIT and the services we provide. You can always check back here for warnings about current phishing emails, confirmations of valid emails you might have a question about, and data breach notifications.
LEGO is the coolest stuff ever! I’ve built stuff from LEGO blocks for longer than most of you have been alive, although lately, I prefer the LEGO Technics sets. If you like to watch people make things from LEGO that even the talented LEGO designers didn’t think of, follow this YouTube channel!
Featured Image: Jeff Brown/Berry College 2026





May News from Information Security