WCSU Cybersecurity Awareness Training
WCSU Cybersecurity Awareness Training
Staff Study Guide
Cybersecurity is everyone’s responsibility. Schools handle sensitive information every day, including student records, employee information, financial data, login credentials, and other confidential information.
Many cybersecurity incidents begin with a simple email, text message, phone call, or login request. The goal of this training is to help staff recognize suspicious activity, protect district information, and know what to do when something does not seem right.
1. Recognizing Phishing Emails
Phishing is an attempt to trick someone into providing information, clicking a malicious link, opening a harmful attachment, or taking an action that benefits an attacker.
Phishing messages may appear to come from:
- A coworker
- A principal or administrator
- The superintendent
- Google or Microsoft
- A bank or financial institution
- A vendor
- A delivery company
- Payroll or Human Resources
- A school-related service
Common warning signs include:
- Unexpected requests
- Messages creating urgency or fear
- Requests for passwords or verification codes
- Requests to purchase gift cards
- Unexpected invoices or payment changes
- Unusual attachments
- Links that lead to unfamiliar websites
- Messages asking you to log in unexpectedly
- A sender address that does not match the person or organization it claims to represent
Do not assume an email is legitimate simply because it contains a familiar name, logo, or email signature.
When in doubt, verify the request using a trusted method such as calling the person using a known phone number.
2. Protecting Your Password
Passwords protect access to district systems and information.
You should:
- Use unique passwords for different accounts.
- Use long, difficult-to-guess passwords or passphrases.
- Never share your password with another person.
- Never send your password by email or text message.
- Use an approved password manager when available.
WCSU Technology staff should never need to know your password.
If someone claiming to be from IT asks you for your password, do not provide it.
3. Multi-Factor Authentication
Multi-factor authentication, or MFA, provides additional protection when logging into an account.
An MFA request should only be approved when you are actively trying to log in.
If you receive an unexpected MFA request:
- Do not approve it.
- Deny the request if possible.
- Contact WCSU Technology.
An unexpected MFA prompt may mean that someone else already knows your password and is attempting to access your account.
Never provide an MFA verification code to another person.
4. Be Careful With Links and Attachments
Before clicking a link, consider:
- Was I expecting this message?
- Do I recognize the sender?
- Does the link appear to go where the message claims?
- Is the message asking me to log in unexpectedly?
- Is the request unusual for this person?
Be especially careful with unexpected attachments, including Word documents, PDFs, spreadsheets, compressed files, and shared-document notifications.
If you are unsure, contact WCSU Technology before opening the attachment or following the link.
5. Protecting Student and Employee Information
WCSU employees may have access to confidential or sensitive information.
Before sending or sharing information:
- Verify that you have the correct recipient.
- Only share information with people who have a legitimate need for it.
- Use district-approved systems and accounts.
- Check Google Drive sharing permissions before sharing documents.
- Do not forward sensitive district information to personal email accounts.
- Avoid storing district information in unapproved applications or services.
Take an extra moment to review recipients before sending email containing student, employee, financial, or other confidential information.
6. Artificial Intelligence and Sensitive Information
Artificial intelligence tools can be useful, but information entered into an AI service may leave district-controlled systems.
Do not enter confidential or protected information into an AI service unless the service has been specifically approved for that use.
Examples of information that should not be entered into an unapproved AI tool include:
- Student names combined with educational or behavioral information
- Student records
- IEP information
- Medical information
- Employee records
- Social Security numbers
- Passwords
- Financial information
- Confidential internal documents
For general questions, brainstorming, or non-confidential information, AI tools may be appropriate when used according to district policies.
7. Financial and Vendor Requests
Attackers frequently impersonate administrators, employees, and vendors.
Be especially cautious about requests involving:
- Wire transfers
- Direct-deposit changes
- Vendor bank-account changes
- Gift cards
- Invoices
- Payroll information
- Purchasing
A request should be independently verified if it is unusual or involves financial information.
Do not rely only on replying to the email that made the request. If the sender's account has been compromised, you may simply be replying to the attacker.
8. Phone and Social Engineering Attacks
Cyberattacks do not always happen through email.
Someone may call and claim to be:
- WCSU Technology
- Google or Microsoft support
- A vendor
- A school administrator
- A financial institution
Attackers may already know your name, position, school, or other publicly available information.
Do not provide passwords, MFA codes, or confidential information simply because the caller sounds convincing.
When unsure, end the conversation and independently contact the organization or person using information you already know is legitimate.
9. Physical Security
Cybersecurity also includes protecting physical devices.
Staff should:
- Lock their computer when leaving it unattended.
- Keep district devices secure.
- Report lost or stolen devices promptly.
- Never plug an unknown USB device into a district computer.
- Prevent unauthorized people from accessing staff-only areas or equipment.
If you find an unknown USB drive or other electronic device, provide it to WCSU Technology rather than connecting it to a computer.
10. If You Click Something Suspicious
Accidents happen. What matters is how quickly we respond.
If you:
- Click a suspicious link
- Open a suspicious attachment
- Enter your password into a suspicious website
- Approve an MFA request you did not initiate
- Send confidential information to the wrong person
- Notice unusual activity on your account or device
Contact WCSU Technology immediately.
Do not wait to see if something happens.
Fast reporting can allow Technology staff to reset credentials, investigate the activity, isolate a device, or take other steps before an incident becomes more serious.
Employees should never avoid reporting an incident because they are embarrassed about clicking something.
