Skip to main content

Cybersecurity Education

October is Cybersecurity Month!

Brutus Buckeye using a laptop

Cybersecurity is a shared responsibility—and everyone has a role to play. This October, The Ohio State University is again partnering with the Big Ten Academic Alliance (BTAA) to invite colleagues from across higher education for a month of engaging virtual events focused on cybersecurity awareness, resilience, and innovation. 

 

Throughout the month of October, you'll have opportunities to learn from industry experts, campus leaders, researchers, and practitioners as they share insights. Gain perspective about best practices, emerging trends, and practical strategies for navigating today's evolving technology landscape. 

 

Regardless of your role at your institution, whether you're faculty, staff, or a student, you'll find sessions designed to expand your knowledge, spark new ideas, and help you strengthen cybersecurity within your role and your organization. 

OCT. 1: Game Show: Level Up Your Cybersecurity Game! 

Big Ten Academic Alliance Cybersecurity Gameshow 2026 

Thursday, Oct. 1: 1-2 p.m. ET 

Register

 

 Join an online game show to compete against Big Ten rivals in Level UP Your Cyber Game - College Gameday Edition! 

 

In today's world, strong cyber skills are essential, and this is your chance to test them. Get ready for a fast-paced, high-energy game show packed with exciting challenges and strategic dilemmas. You'll not only sharpen your cybersecurity skills but also gain practical tips to protect your digital life long after the final whistle. 

 

IMPORTANT: This session will be hosted by the National Cybersecurity Alliance. A separate registration is required using this link. 
 

SPEAKERS: 

  • Barry Eitel, Editorial Director, Staysafeonline.org 
  • Cliff Steinhauer, Director, Information Security and Engagement, Staysafeonline.org 

 

OCT. 6: How to Survive the AI Apocalypse 

Tuesday Oct. 6: 1-2 p.m. EST 

Register

 

It seems that the harder and faster we work, the more there is to do. And now we have AI. 

 

What does this mean for your job today, your longer term career, your ongoing well-being? Join us to consider what the problem really is, ways to approach this problem, and get leave with suggestions for how to manage this for you and your team 

 

SPEAKER: 

Helen Patton, Executive Cybersecurity Advisor 

OCT. 8: BTAA CISO Panel 

Thursday, Oct. 8: 1-2 p.m. EST 

 

Higher education institutions face security challenges that demand thoughtful, coordinated responses across many of our distributed environments. Addressing these challenges effectively requires not only structure and leadership but also a shared understanding of the complexity that underpins our work, all the while meeting the mission of teaching, learning, and research. Our panelists will cover topics related to risk within our organizations, how to build and deliver a strong security awareness program and culture, and where they see the security space evolving to further educate and promote security in higher education. 

OCT. 13: The CIS AI Journey

What Worked, What We Adjusted, What We're Still Figuring Out 
Tuesday Oct. 13: noon -1 p.m. EST 

 

Most organizations are being asked to adopt AI faster than they can answer basic questions about how to do it safely. At the Center for Internet Security, we chose to build our AI program governance first, before scaling use across the organization. This session walks through that journey candidly, including the questions we got right early, the ones we underestimated, and the places where our first plan needed real adjustment. 

 

Brian Calkin, CIS Chief Technology and Innovation Officer, will share how CIS stood up an AI governance board and a technical subcommittee, deployed enterprise AI tooling to staff, and worked through the security and data questions that surfaced along the way. What data can these tools touch? How do we vet vendors? Who reviews an agent before it acts on its own? How do we keep cost and sprawl under control? The talk focuses on what actually worked, what we changed, and what we are still figuring out. 

 

For higher education, the stakes are distinctive. Research, administrative, and IT environments each carry different data sensitivities and risk tolerances, and scaling AI across all three without a shared governance foundation invites trouble. Attendees will leave with a practical starting framework they can adapt, a set of questions worth answering before broad rollout, and a clear view of the tradeoffs from an organization living them now. 

 

SPEAKER: 

Brian Calkin, Chief Technology & Innovation Officer, Center for Internet Security 

OCT. 15:  Leading Secure AI Adoption in Higher Education

Governance Strategies for an Evolving Threat Landscape 

Thursday Oct. 15: 2-3 p.m. EST
 
Register

As universities rapidly adopt AI, leaders must balance innovation with security, privacy, and compliance. Drawing on experience leading cybersecurity initiatives across government and industry, M. K. Palmore will share practical governance strategies for managing AI risk, strengthening institutional resilience, and aligning cybersecurity with organizational priorities. Attendees will leave with actionable frameworks to support secure AI adoption across higher education. 

 

SPEAKER: 

M. K. Palmore, Founder & Principal Advisor, Apogee Global RMS 

OCT. 29: Introduction To The Evolving Federal Research Cybersecurity Landscape

The Evolving Federal Research Cybersecurity Landscape and What It Means For University IT Teams 

Thursday, Oct. 29: 2-3 p.m. EST 

 

Federal requirements around research cybersecurity are growing quickly, and university IT teams are increasingly the ones expected to put them into practice. This session offers a plain-language introduction to that landscape: what the new requirements are trying to accomplish, where things stand today, and why work that used to live in research compliance offices is showing up in the systems IT teams build and support every day. The conversation pairs a national policy perspective from EDUCAUSE with practical resources from the research security community, plus a look at how IT, security, and research offices can partner effectively. 

 

SPEAKERS: 

  • Jarret Cummings, Senior Advisor for Policy and Government Relations, EDUCAUSE 
  • Mike DiLalo, System Administrator, Center for Advanced Biotechnology and Medicine, Rutgers Health 
  • Carolyn Ellis, Director, Research Cybersecurity and Compliance, Arizona State University 
Info.

Upon completing your registration, you will receive a unique, non-transferable Zoom link in your registration confirmation email.

Risk Management Series: Command Artificial Intelligence Safely

Artificial Intelligence (AI) is reshaping how Ohio State teaches, researches, and operates. Understanding how AI systems work is key to using them effectively. Learning how to safely navigate AI determines whether you do so with expertise or with exposure. 
This 90-minute webinar examines the components of a trustworthy AI-driven workflow.

Completion of this course can be applied to the annual cybersecurity awareness requirement (IT16.1.1) for all university and medical center colleagues. In this webinar, you’ll learn how to use AI safely and effectively—from protecting data and choosing approved tools to crafting better prompts, understanding LLMs and avoiding risks like inaccurate citations, plagiarism and intellectual property theft.

Click here to find the webinar in BuckeyeLearn

 

Reach out!

You can request time to schedule Security Coordinator onboarding sessions, role-based training, or general security training by sending an email to securityawareness@osu.edu.  

Security Community Archived Agendas

Request in invitation by sending an email to securityawareness@osu.edu

Agendas will appear in the meeting invite for the current month. Past agendas can be reviewed here: 

Past Agendas

March 19, 2026

  • Password Policy Deadline April 7 - Brian Zieber.6
  • ACME Certificate Automation - Bob Joseph.97
  • Agentic AI and OpenClaw - Reg Jackson

February 19, 2026

  • Annual certification of Workday and Peoplesoft access – Emily Guthrie
  • 2025 Security & Privacy Control Assessment Overview - Bill Pfau
  • AWG and Mitigation Plans – Janet Stackpole
  • TIER Update – Jon Yeagley
  • Comment Period for Pen Test Rules of Engagement - Bob Pardee  
  • AppleID Block Update – Reg Jackson
  • NIST Interagency Reports (IR) - control overlays for securing AI systems – Rob Clifford 

 

January 15, 2026

  • Digital Security and Trust Updates
    • Google’s Data Protection
    • Duo Certificate Authority Change
  • Test your AI Security Smarts: Quiz Winners
  • December Phish Simulation Results
  • 2026 IDP Training

IT16 Training Options

IT16 ensures users are aware of security threats and behavior that makes them vulnerable, and capable of performing information security-related roles. Please review the following control requirements for training specifics:

IDP Annual Training

  • IT16.2.1 Institutional data training - all users of S4 (restricted) institutional data participate in university-approved institutional data training. Users of S4 (restricted) institutional data must participate in training before they are granted access to S4 (restricted) institutional data. Additionally, users must participate in any regulation-specific training before they are granted access to regulated data. Users must participate in one university-approved institutional data training annually.

The "Resources" tab below provides training resources to assist in meeting the training requirements in IT16.

Resources
  • IDP Annual Training (BuckeyeLearn) - Required for those who have access to S4 (Restricted) information
  • Security and Awareness Training (update coming...more to follow soon)
    1. View the Curriculum page from your browser: (new link soon)
    2. Click “Register”
    3. Enjoy the training courses together, or individual, as conveniently as your time permits
    4. When all courses are complete, return to your transcript. The course should show as “complete”
  • LinkedIn Learning - Ohio State faculty and staff have 24/7 free unlimited access to LinkedIn Learning which allows you to learn at your own pace. There are 30-70 new courses added weekly which are relevant to your current role.
  • Security Community meetings - held monthly, these events discuss developments across the security landscape, work being done to protect the university, and general security discussions. Send an email to securityawareness@osu.edu to request an invitation.

 

Security Coordinator Resources

The Ohio State IT Security Policy specifies the requirement for establishing security representatives from colleges, units, and campuses. The security representative, known as the Security Coordinator, serves as the unit liaison with Digital Security and Trust (DST) for security-related matters and activities, and is responsible for the execution of security activities in their college or unit.

Security Coordinator resources:

Past Cybersecurity Events

Cybersecurity Days Logo

Cybersecurity Days

This section details our collaboration with the BIG10 Academic Alliance (BTAA) to celebrate October as National Cybersecurity Awareness Month. Check back closer to October 2026 for updated events.  

Contact cybersecuritydays@osu.edu if you have questions or want to provide feedback.

Past Agendas
2025

Join the Cybersecurity Gameshow

Wednesday, Oct. 1, 2025 - 1:30-2:30 p.m.

All users cam benefit from good cyber skills and we’re here to put your mind through the motions! Join us for a turbocharged game show in a friendly competition with other Big Ten colleges. Power up with essential info and practical techniques to safeguard your digital life.

BTAA CISO Panel: Securing the Mission: Building Awareness and Resilience in Higher Ed

Thursday, Oct. 9, 2025 - 2-3 p.m.

IT professionals know that higher education institutions face security challenges that demand thoughtful, coordinated responses across many of our distributed environments. Addressing these challenges effectively requires not only structure and leadership but also a shared understanding of the complexity that underpins our work, all the while meeting the mission of teaching, learning and research. Our panelists will cover topics related to risk within our organizations, how to build and deliver a strong security awareness program and culture, and where they see the security space evolving to further educate and promote security in the higher education space. 

Scary Cyber Tales: Don’t Let Your Data Go Bump in the Night

Wednesday, Oct. 22, 2025 - 2-3 p.m.

All users can benefit from this event, which is a spine-chilling journey into the real-life dangers of the digital world.  We’ll share real-world stories of cyberattacks, data breaches, and online scams that will make you think twice about your digital security. Learn about the most common threats, from phishing and ransomware to malware and social engineering, and get practical tips on how to protect yourself. Join our team of cybersecurity experts for an hour of spooky tales and essential security lessons to ensure your digital life doesn’t turn into a scary cyber tale!

Rachel Tobac: Exploiting Trust - The Human Element of Security 

Wednesday, Oct. 29, 2025 - noon -1 p.m.

IT professionals know that it only takes 1 email, a 30 second call, or 1 social media DM for her to hack you and gain access to your money, data, and systems.  Meet Rachel Tobac, who executes these social engineering attacks for a living and uses her real-life ethical hacking stories to keep organizations up to date on the methods criminals are using to trick people.  She’ll break down recent cyber attacks in the news, and how to defend against the latest hacking methods, even when criminals are using AI.  Her tales from the field and live hacking demonstrations throughout the presentation are sure to keep you and your team “politely paranoid” to catch the next human hacker in the act.

2024

Application Security (DevSecOps) - May 22, 2024

With the goal of expanding role-based cybersecurity education, Cybersecurity Days is presenting a virtual, three-hour Microsoft Teams webinar focused on application security.

Agenda

8:30am: Webinar opens to attendees

9:00 - 9:15am: Agenda overview

DevSec

9:15 - 10:00am: Code Confidence – Marc Archuleta

  • DevSecOps best practices
  • Application scanning
  • Automation in the pipeline
  • Static and dynamic vulnerability scanners
  • LIVE DEMO

10:00 - 10:15am: Questions and answers

10:15 - 10:30am: Break

SecOps

10:30 - 11:00am: Container Services – Jeff McDonald

  • Why containers?
  • Kubernetes
  • Zero trust networking
  • Continuous deployment
  • Never deal with passwords again
  • LIVE DEMO

11:00 - 11:30am: Choose your own adventure discussion

11:30am - 12:00pm: University-provided tools, services and documentation

This session will be interactive. We aim to introduce tools and services that you and your team can use to improve the security of your products. At the discretion of your manager or unit, this session could be used to comply with ISCR IT7.10.1-2.

2023
2022
2021
2020

Protect your Digital Life

A bear trap with the words 'fix now' above it.

Avoid ClickFix!

This new cyber threat doesn’t sneak in—it asks you to invite it. Think before you copy and paste—ClickFix attacks rely on your clicks to succeed.

A representation of a heartbeat monitor labeled 'alert'

Plan Your Legacy

You’ve made a will for your house—have you made one for your Instagram?  When you’re gone, your online accounts live on—unless you make a plan.

A person holding a tablet with a screen showing a digital lock labeled 'privacy'

Enable Multifactor

Cyberattacks are smarter—your security should be too. When one click can stop a breach, multi-factor authentication makes the difference.

Longer Password

Build Stronger Passwords

You can’t ignore passwords, but you can make them easier and stronger. Strong passwords don’t have to be painful—here’s how to simplify your security.

An email being snagged by a fishing hook

Learn to Avoid Phishing

That “urgent” email might be a trap—learning how to spot the signs is your best defense. Phishing scams don’t need your trust—they just need one click.

Construction hat with a block O laying across an open laptop computer.

Understand Responsible Use

University devices are for work first—use them wisely, use them well. Personal use is allowed—but not unlimited. Know the rules.