National Cybersecurity Awareness Month 2026
Cybersecurity Awareness Month
at Niagara College
Cyber resilience does not require a computer science degree. Research by the Cybersecurity and Infrastructure Security Agency (CISA) confirms that practicing these four actions neutralizes over nine out of ten common digital attacks.
Month of October Campaign: 4 Foundational Behaviors
Consistent, everyday actions defend personal accounts, academic records, and campus networks.
Habit 01
Strong Passwords or Passphrases + MFA
True credential defense requires two layers working in tandem. Layer 1 replaces short, recycled passwords with memorable, long 4-word passphrases (16+ characters) stored in a password manager. Layer 2 enforces Multi-Factor Authentication (MFA)—the single most effective barrier against credential theft. Even if an adversary intercepts or phishes your passphrase, MFA blocks unauthorized access without physical possession of your registered authenticator or biometric passkey.
P@$$w0rd2026! (12 char)
beacon-orchard-copper-galaxy
Habit 02
Deploy Trusted Security Tools
Do not rely solely on default operating system settings. Equip your personal laptops and mobile devices with reputable, privacy-respecting security tools that intercept threats before they reach your browser:
Free national DNS service filtering malicious domains & botnets.
High-efficiency content blocker protecting against malvertising.
Audited open-source vault for generating and storing credentials.
Industry-grade endpoint protection against ransomware and exploits.
Habit 03
Recognize & Report Phishing
Phishing has evolved beyond obvious spam. Attackers now leverage generative AI to write flawless prose, spoof executive identities, replicate corporate portals, and execute targeted spear-phishing over email, SMS (smishing), and voice calls (vishing).
Use the Phish Forwarding Button in Microsoft Outlook or forward the raw message to [email protected].
Habit 04
Update Software & Firmware Promptly
Software updates do not just deliver interface changes; they deliver critical security patches that seal known vulnerabilities (CVEs) that cybercriminals scan for continuously. Automated updates eliminate the window of exposure.
Enable automated operating system and browser updates across all laptops, phones, and home Wi-Fi routers.
Niagara College Cyber Hygiene
Core practices for accounts, Passkeys, artificial intelligence safety, and device protection.
Passkeys: Phishing-Resistant Authentication
Passkeys replace traditional passwords with cryptographic keypairs tied to your device’s biometrics (Face ID, Touch ID, or Windows Hello). Your private key never leaves your device’s secure enclave, eliminating password theft and credential leaks by design.
Stored on company servers. If a server database is compromised, passwords can be stolen and credential-stuffed across other accounts.
The server only holds a public key. Even if the service is breached, public keys cannot be used by attackers to authenticate.
Account & Password Security
- Never reuse passwords: A compromise on an external service can expose your Niagara College access.
- Deploy a Password Vault: Use a vetted manager like Bitwarden or 1Password to maintain high-entropy, unique credentials.
- Protect Single Sign-on: Never approve spontaneous Microsoft Authenticator push alerts if you did not initiate the login.
AI Safety & Digital Footprint
- Safeguard Confidential Data: Never paste student records, proprietary Niagara College files, or credentials into public generative AI tools.
- Voice Cloning & Deepfakes: Attackers can clone leadership or faculty voices; verify financial or sensitive requests through direct internal extensions.
- Inspect AI Phishing: Modern spear-phishing messages are free of grammatical errors; evaluate the intent, sender domain, and urgency instead.
Device & Network Hygiene
- Avoid Untrusted Wi-Fi: Never access sensitive college databases on public networks without utilizing the Niagara College VPN.
- Auto-Lock Screens: Set laptops and mobile devices to automatically lock after 2–5 minutes of inactivity.
- Travel Precautions: Disable Bluetooth and automatic Wi-Fi joining when commuting or traveling, and never leave devices unattended.
Niagara College Phish Bowl
Real-world phishing messages reported by Niagara College students, faculty, and staff.
Account Suspension
Tactic: False urgency paired with deceptive links to harvest single sign-on credentials.
Fake Overdue Invoice
Tactic: Urgent financial pressure accompanied by malicious attachments or fraudulent payment routing.
Password Expiration
Tactic: Impersonates ITS Service Desk to trick users into submitting credentials and MFA codes on lookalike portals.
Gift Card Scam
Tactic: Impersonates executive deans or faculty via free external webmail (e.g., Gmail) requesting urgent favors.
Student Job / Internship Offer
Tactic: Targets students with unrealistic compensation to extract SIN, banking data, or advance-fee scams.
Suspicious Login Alert
Tactic: Panic-inducing fake alerts sent from compromised student or staff accounts to harvest secondary tokens.
How to Identify a Phishing Email (ITS Checklist)
Verify the actual email domain, not just the display name. Look for slight alterations.
Impersonal salutations like “Dear User” or “Dear Student” are common warning signs.
Demands for immediate action within hours are engineered to bypass critical thinking.
Hover over links to preview destination URLs before clicking. Never open unexpected attachments.
Niagara College ITS will never ask you to send passwords, bank details, or gift cards over email.
Emails flagged as originating from external sources require extra verification before responding.
Resources & Support Services
Official Niagara College support channels, training portals, and contact info.
ITS Security Office & Service Desk
Responsible for incident response, security policies, and technical support across Niagara College.
Awareness Modules & National Portals
Build your digital defense knowledge through interactive training modules and federal safety guidance.
CyberAware Platform: Complete optional training modules via myNC portal.
Get Cyber Safe: Government of Canada Campaign
IT Information Security Policies: Review institutional guidelines on acceptable use.

