'Falling' into National Cybersecurity Awareness Month 2024

Bill Balint • September 18, 2024

Faculty members are tired. Students are tired. Staff and administrators are tired. Those charged with trying to pay the bills are simply exhausted.


The education industry is bone weary from the almost daily news about yet another cybersecurity attack, stealing even more of the public’s private data. Weary of seeing their lives being increasingly complicated by constantly changing (and sadly not always effective) attempts at protecting their sensitive and confidential data. Passwords and PINs and facial recognitions and bouncing to text messages with that code to type back in before it expires.


It is really all too much.


The latest saga in this warped docuseries that never seems to have a final episode was the National Public Data (NPD) breach of background check data in which more than 2.5 billion records were stolen containing personally identifiable information, including social security numbers and even names of relatives. The fact NPD is sometimes used as a fraud prevention service is a microcosm of the irony surrounding many of these cases.


None of this is bound to stop anytime soon, but maybe a little well-spent time and focus on cybersecurity once a year could reduce that ominous risk.


Enter National Cybersecurity Awareness Month (NCSAM), which celebrates its 20th Anniversary in October. While certainly not as appealing on the surface, at least, to other celebrations that also claim October like National Roller Skating Month and National Positive Attitude Month, NCSAM takes no back seat when it comes to importance.


Sure, vigilance against the evils cybersecurity attacks is a 24 X 7 X 365 endeavor. But embracing 31 of those days to educate ourselves and take action – hopefully concluding with a great trick-or-treat ending – can make the following year less of a personal concern.


A great place to get started is with the non-profit National Cybersecurity Alliance (staysafeonline.org). The site features a treasure trove of practical, easy to digest quick pointers that can help make safe computing practices much easier to adopt.


Just one great resource is a webpage featuring links to the privacy policies for dozens of the most popular and important websites when it comes to personal information. Clearly arranged into categories such as mobile banking, health applications, social media and even dating sites, the Alliance can lead you to answers in a hurry.


The story gets better for those of us in education. NCSAM includes a section dedicated to free and low-cost resources targeted to teachers and students in the K-6, 6-12 and higher education sectors. Among the resources are tips for how best to encourage children to care about cybersecurity. Simple, practical advice all contained in what NCSAM estimates is a four-minute read.


NCSAM obviously makes its most positive impact when the institution itself gets on board. An institution’s participation by using October to recognize the serious impact cybersecurity attacks have on our lives, that of our institutions and society, in general, can make a significant positive impact. A great first step is for the institution to become a Cybersecurity Awareness Month Champion, which is a simple and free designation to – in the words of the Alliance - “represent those dedicated to promoting a safer, more secure and more trusted internet.”More than 100 educational institutions – ranging from K-12, higher education – took the pledge in 2023.


Since NCSAM was cofounded in 2004 by The Alliance along with the U.S. Department of Homeland Security in 2004, it is fitting the U.S. Cybersecurity & Infrastructure Security Agency (CISA) also offers a great free resource via its Secure Our World site (www.cisa.gov/secure-our-world) site.


Secure Our World is a terrific resource for education, as it includes resources like posters that can be placed in halls, classrooms, labs and libraries. There are more than a dozen two-page ‘tip sheets’ with colorful, easy-to-read infographics that can help our institution’s community at a glance. With subjects like passwords and multi-factor authentication (MFA), the focus is on the end user. Throw in a free cybersecurity bingo card for youth and another for organizations, and even the most resource-constrained institution can benefit.


The reality is no 31 days will stop events like the NPD breach. It will not stop the gloomy report from Malewarebytes (Based on ThreatDown research) that education was the victim of 265 known attacks in 2023 after the 129 just one year earlier.


But the silver lining in the cybersecurity space is that any improvement makes a positive difference. One fewer successful attack can make a tremendous impact. We can all hope for a year when cybersecurity professionals in education can replace thoughts of NCSAM with National Positive Attitude Month.




Bill Balint is contracted as the Advisory CIO for Education at Trivigil via Haven Hill Services LLC

By Bill Balint March 27, 2025
While National Cybersecurity Month (October) and National Data Privacy Week (late January) seemingly growing in adoption, a couple of more-recent cybersecurity events will hopefully take that next step. AI Fools Week (Naturally Kicking off ‘AI’pril) The good folks over at the National Cybersecurity Alliance (NCA) have created their inaugural artificial intelligence (AI) awareness campaign, fittingly entitled “AI Fools Week”, taking place the Week of March 31 ( https://www.staysafeonline.org/aifools ). NCA even jokingly refers to the month as “AIpril”.  As is often the case, NCA offers a very well-done toolkit of tip sheets, infographics, posters, etc. for those looking to initiate a ‘be safe when using AI” campaign at their institution or place of business. One of the NCA toolkit’s more ironic, but interesting ideas is to leverage a concept dating back to Ancient Greece by creating a shared password (safe word) to combat “deepfake” voicemails, messages, even video calls. The kit suggests safe word systems are worthy for consideration beyond families – such as with fellow employees, close friends, caregivers and groups reliant upon virtual communication. Identity Management Day 2025 Identity Management Day 2025 ( https://www.idsalliance.org/event/identity-management-day-2025 ) will take place immediately after AI Fools Week on April 8. The awareness focus is a free, day-long online conference. The NCA and the Identity Defined Security Alliance play host to the event, which started in 2021. Of course, adhering to safe computing practices in this rapidly changing landscape is a 365-day per year battle (366 during leap years - LOL). Some might consider it impossible to avoid deepfakes for long because so much is beyond the individual’s control – especially in a GenAI world. But the silver lining is any improvement in protection is a positive and the event is geared toward promoting best practices. Higher Education Cybersecurity Digital Magazines Awareness days and weeks are nice and all, but this is also a daily effort where timely, helpful information made available within a few clicks is a vital asset. This is one way digital magazines can make a difference. Higher education might increasingly be operating ‘like a business’, but access to information from those who understand the unique higher education environment remains a plus. Fortunately, higher education cybersecurity professionals can find plenty of education-specific content without cost. It is true the mix of public sector, non-profit and for-profit websites are valuable. But targeted digital magazines also provide critical additional insight. Though not a comprehensive review, three sites appear to be among the leaders in this space. EdTech magazine’s cybersecurity site ( https://edtechmagazine.com/higher/security ), for example, published nine (9) new articles during a recent three-month period, featuring diverse topics like identity and access management (IAM), student BYOD security challenges, AI, and the age-old technical debt implications for security and privacy. Each article places the material into a higher education-centric context. One specific nice feature is the site’s article filtering, which allows readers to deep dive into 14 sub-topics in an instant. Campus Technology magazine has been a friend to the higher education IT community for some 35 years (known as Syllabus from 1988-2004 before adopting its current name). Cybersecurity has been part of its content for multiple decades and its website touts a cybersecurity portal ( https://campustechnology.com/Portals/Cybersecurity.aspx ) full of articles, podcasts, webcasts and whitepapers. The site included 10 articles in a recent 90-day timeframe and these included information about subjects ranging from AI, Educause HECVAT’s release, Jamf’s purchase of Identity Automation, etc. Education Technology Insights ( https://www.educationtechnologyinsights.com ) offers content spanning the education sector, with a focus on “…bringing forth a complete picture of how teachers are using different classroom technologies…”. Although there does not appear to be a cybersecurity-specific part on the site, there is plenty of content found via a general search. There are loads of higher education-focused sites that offer cybersecurity content, but most do not have it as a specific focus area. Inside Higher Ed, University Business, and GovTech are just a few. Of course, there are also many cybersecurity digital magazines that cut across all industries and certain content has implications for the education sector. Bill Balint is the owner of Haven Hill Services LLC, contracted as TriVigil’s Advisory CIO for Education.
By John Schimanski March 12, 2025
Let’s talk about something that most Chief Information Security Officers (CISOs) hesitate to discuss, BURNOUT . Cybersecurity is a high-stakes, high-pressure field. The constant barrage of threats, the responsibility of protecting an organization’s digital infrastructure, and the expectation of being on-call 24/7 can take a toll. Burnout among CISOs and security professionals is real, prevalent, and dangerous , not just for individuals but for organizations as well. Burnout can manifest in various ways: self-medicating with alcohol or drugs, struggling with depression, losing the ability to make decisions, or feeling so overwhelmed that you shut down. The risk is even higher during crises, such as a major ransomware attack, where long hours and intense pressure become the norm. The good news? Burnout is preventable. Recognizing the signs early and taking proactive steps can make all the difference. Understanding Burnout in Cybersecurity Burnout doesn’t happen overnight; it’s a gradual process. Security professionals often start by feeling stressed and overworked, but over time, that stress turns into chronic exhaustion, cynicism, and decreased effectiveness . The key warning signs include: Constant fatigue despite adequate rest Loss of motivation or feeling disconnected from work Irritability or mood swings with colleagues or family Difficulty concentrating or making decisions Physical symptoms like headaches, insomnia, or muscle tension A sense of helplessness or feeling like you’re failing If these symptoms sound familiar, it’s time to take action. Strategies to Prevent and Combat Burnout 1. Take Strategic Breaks Security incidents demand immediate attention, but working under constant stress isn’t sustainable. Taking short breaks throughout the day can help lower stress levels. I personally step away from screens for at least 10 minutes every two hours to give my mind (and eyes) a reset. 2. Find an Outlet Beyond Work Engaging in activities that provide mental relief is essential. For me, that includes reading (both work-related and for pleasure), swimming, shooting, gaming, talking with friends, riding my trike, or going to the movies. Whatever it is for you, sports, music, art, hiking, find something that allows your brain to reset. 3. Use Your Vacation Time (and Actually Unplug!) Many of us accumulate vacation days but hesitate to use them, fearing work will pile up. Use your time off. Fully unplugging, even for a few days, can reset your perspective and prevent burnout from spiraling. 4. Set Realistic Expectations CISOs often feel like they must handle everything themselves. This mindset is a fast track to burnout. Know your limits and delegate where possible. If you have a team, trust them. Security is a team effort, and you don’t have to be a hero every day. 5. Prioritize Physical Health Regular exercise is one of the best tools against stress. Studies show that physical activity boosts serotonin and helps improve cognitive function. Even a short walk or stretching routine can have a profound impact on your mental state. 6. Create a Routine to Reduce Decision Fatigue CISOs make critical decisions every day. Over time, constant decision-making wears down mental resources. Structuring parts of your day, whether it’s a morning routine, meal planning, or even wearing the same style of clothing, can free up brainpower for more important decisions. Top executives, from Steve Jobs to U.S. presidents, rely on routines to reduce decision fatigue. 7. Get Enough Sleep (And Learn to Recognize Fatigue) It sounds simple, but lack of sleep is one of the biggest contributors to burnout. Fatigue affects judgment, reaction time, and emotional resilience. If you’re waking up exhausted, it’s time to reassess your sleep habits. Short naps can also provide quick recovery when needed. 8. Talk About It—Don’t Struggle Alone Burnout thrives in isolation. CISOs are often expected to be strong, resilient, and unshakable, but everyone needs support. Find someone you trust, a friend, colleague, mentor, or therapist—and talk about what you're experiencing. Sometimes, just saying things out loud can bring clarity and solutions. Final Thoughts Burnout isn’t a sign of weakness; it’s a signal that something needs to change. Recognizing the warning signs and taking proactive steps can prevent long-term damage to both your well-being and your career. If you’re feeling overwhelmed, step back, reset, and reach out. You’re not alone, and help is available. Cybersecurity is a tough job, but it shouldn’t come at the cost of your health and happiness.
By Bill Balint February 27, 2025
A little cottage industry seemingly arises at the conclusion of each decade, joyously pointing out those long-since forgotten, failed techy items from the past 10 years that were supposed to impact the world but were miserable failures instead. While we are only at the midpoint of the 2020s, it is safe to say AI will not be the next Google Glass, 3D television or the loads of other mainstays on the 2010s lists of IT infamy. Higher education quickly realized both the potential AI positives and negatives as it applied to the teaching, learning and academic research space (think plagiarism on one hand matched against the prospect of personalized learning on the other). Underscoring this fact is the groundbreaking recent announcement that the California State University System intends to become the nation’s “first and largest AI-empowered university system” ( https://www.calstate.edu/csu-system/news/Pages/CSU-AI-Powered-Initiative.aspx ). However, AI adoption for administrative tasks – providing desperately-needed help as struggling institutions look to lower costs, attract/retain more students, and obtain external support via fundraising, grants, etc. – has been a little more deliberate. But this is changing fast, as it seems every higher education information system vendor is now flexing its AI muscles – or at least the sales and marketing teams are doing so. Phrases like ‘Throw your CRMs into the trash bin because mine innovates using AI’ or ‘I’ll see your legacy registration system and raise you a machine language course schedule wizard’ are lurking in that sea of PR if you read between the lines hard enough. The fear of missing the AI train must be balanced because higher education cybersecurity and data privacy risks because AI requires data and that’s where things get complicated. Higher education is always among the most vulnerable industries because its data is so valuable to cyber attackers, and it is considered an easy target. No industry has the combination of user churn, number of inexperienced and casual users, the plethora of personal devices, and an overriding culture of openness. Couple it with IT budgets and staffing often facing unprecedented challenges and it is a mix that attracts bad actors from across the globe. The increasing AI usage will likely bring even more frequent, more sophisticated attacks. Adding to the complexity is the presence of shadow systems housing sensitive or confidential data lurking in higher education for some 40 years. Among the relevant examples are a power user downloading student fiscal data onto a personal hard drive, a researcher locally storing sensitive data, and an office which has deployed an information system for which the IT department does not even know exists. Consider the dark possibilities if a user innocently exposes such data to a GenAI model.  This all means answers to traditional questions like ‘Where is the data actually stored and what security measures exist for that data both at rest and in transit?’ and ‘How robust are the tools restricting data access?’ deserve more scrutiny than ever. Perhaps more importantly, the question of ‘Does my executive who listened to AI hype at a conference last week and is now eager to buy an AI-infused product fully grasp the potential risk?’ At one time, it may have taken a concerning cybersecurity audit finding to catch the attention of the institution’s board or cabinet. But these can no longer those times and executive recognition of AI risk up front is critical. Executive leadership should prioritize the creation of practical, common-sense policies governing AI usage. Tactical and operational leadership needs empowered to keep those policies up to date and to make key decisions on tools and techniques to help keep data safe. They can then build appropriate procedures, guidelines, standards, FAQs, and best practices so users can effectively work in an emerging AI world. Bill Balint is the owner of Haven Hill Services LLC, contracted as TriVigil’s Advisory CIO for Education.
Share by: