Skip to main content

Harvest Good Cyber Habits This October for Cybersecurity Awareness Month

Cybersecurity Awareness Month, observed every October, is a nationally recognized initiative that educates individuals and organizations about cyber threats and promotes simple, actionable steps to stay safer online. During the month, the university Information Security Office (ISO) is reminding all of us to “Harvest Good Cyber Habits.”

Good cyber habits focus on simple, high-impact practices that take only a few minutes but have long-term impact.

Join and stay tuned to the #iso-public Slack channel for messages throughout the month. And share this information with your teams and networks: Cybersecurity awareness is for everyone.

Week 1 focus: Plant strong roots | Passwords & password managers

Here are some tips to plant strong roots of password protection:

  • Create a strong password that is long, random, and unique.
  • Use a password manager to remember your unique passwords.
  • Replace any reused or old passwords.
  • When available, set up Cardinal Key so Stanford logins skip passwords entirely.

Visit the Password Standards site to strengthen your account security today.

Week 2 focus: Layer up for fall | Multi-Factor Authentication (MFA)

A strong password isn’t the only best practice for cybersecurity—MFA adds a second layer of security, so a stolen password alone isn't enough to compromise an account. Confirm Duo Push is your default two-step method at accounts.stanford.edu, register a backup device, and never approve a Duo push you didn't request.

Set up Two-Step Authentication to add an extra layer of protection to your account.

Week 3 focus: Don't get fooled by AI | AI-powered scams & safe AI use

AI makes scams harder to spot: phishing emails read more naturally, and voices or video can be convincingly faked. Treat an unexpected voice or video request—even from someone familiar—with the same caution as a suspicious email, and verify unusual requests through a separate channel. When using AI tools for work, stick to Stanford-approved services, and remember high-risk data shouldn't go into public AI tools.

Read the “Dangers of Deepfake: What to Watch For" to learn how to identify and report suspicious content.
 

Week 4 focus: Fall cleanup | Software updates

Out-of-date software is one of the easiest openings for attackers, so keep automatic updates on for your operating systems, browsers, and apps. If your device is managed by Stanford, confirm it's compliant and encrypted at mydevices.stanford.edu.

With these four habits in place, you've done the hard work of planting and tending. Now it's time to see what those efforts bring.


Reap what you sow

Strong cyber habits, like a good harvest, come from small and consistent efforts. A few minutes spent this month on your passwords, MFA, AI awareness, and software updates will protect your accounts all year long. Stay tuned to Slack's #iso-public channel throughout October, share these tips with your team, and help keep the Stanford community secure.

Want to learn more? Check out these sites for additional cybersecurity tips:

Share Feedback

DISCLAIMER: UIT News is accurate on the publication date. We do not update information in past news items. We do make every effort to keep our service information pages up-to-date. Please search our service pages at uit.stanford.edu/search.