Educause Security Discussion mailing list archives

Re: Password change *recommended* -- RESULTS?


From: Chris Green <chrisgreen () GSU EDU>
Date: Thu, 24 Apr 2014 11:46:41 +0000

Broadcasts without the actual mechanisms of following up were low percentages <10%.  Probably the most damaging is that 
the 10% that blindly do it, once you take out the technical people that can parse your message, are likely the same 
people that are highly vulnerable to phishing attacks and blindly following the same instructions.

On Apr 23, 2014, at 8:58 PM, Pedersen, Krystal <Krystal.Pedersen () UMASSMED EDU<mailto:Krystal.Pedersen () UMASSMED 
EDU>> wrote:

Hello Everyone – I was looking to get an idea as to how successful a recommended password change broadcast is (to the 
entire school population)? Perhaps a percentage, such as -- last time we sent a broadcast out recommended a password 
change, with instructions on how to change your password, less than 1% of passwords were actually changed?

Thanks!

Krystal Pedersen, CISA
Information 
Technology<https://urldefense.proofpoint.com/v1/url?u=http://inside.umassmed.edu/is/index.aspx&k=7DHVT22D9IhC0F3WohFMBA%3D%3D%0A&r=yppbvsV1vRTy%2FrjhLIIxm488RCwdY6q%2B9kaVJLSs%2B%2F0%3D%0A&m=yK2vpimNGe5jEvJrH91Xdb7A5vzXa2AdJXcl2N9RiQM%3D%0A&s=db02037269f4aa8e0e558f02e28fea71f387fe3c1837ee57d10ea648cc9f2a42>
Information Security, Risk & Compliance Analyst
krystal.pedersen () umassmed edu<mailto:krystal.pedersen () umassmed edu>


Current thread: