Educause Security Discussion mailing list archives

Re: Email Banner


From: "Bandy, John" <jbandy () SAMFORD EDU>
Date: Wed, 24 Jun 2020 15:13:41 +0000

We implemented it about 6 months ago.  I am sure there is some banner fatigue but for the most part our customers use 
it as a first line of defense when they get the spoofed email representing a Sr. Leader.

We implemented it by putting [EXTERNAL] at the beginning of the subject line.  We have whitelisted trusted partners 
(like Canvas, Hiretouch, mailing lists sending email on our behalf, etc).

I can tell you we have had fewer people fall for the "Are you available?" emails by checking this banner.  It has 
really helped the mobile email readers because no one holds down on the display name to get the address (not enough 
time or don't think about it).

John Bandy
Chief Information Security Officer
Technology Services

205-726-2692<tel:205-726-2692> | office
205-726-2524 | fax
JBandy () Samford Edu<mailto:JBandy () Samford Edu>
www.samford.edu<http://www.samford.edu/>
800 Lakeshore Drive
Birmingham, AL 35229<http://maps.google.com/maps?q=800+Lakeshore+Drive,+Birmingham,+AL+35229,+US>

[mford Samford University Logo]



From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Ballister, Mark
Sent: Wednesday, June 24, 2020 9:53 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [EXTERNAL][SECURITY] Email Banner

Good afternoon,

I am looking for information on who has implemented an external email banner and who has not.  For those that have, 
have you seen an improvement in user behavior around phishing?  Thank you for your time.

Thank you,
Mark

Mark J. Ballister, CPP | CISM | CISSP
Chief Information Security Officer (CISO)
University of Rochester
(585) 276-6200 (Office)
(585) 472-2361 (mobile)

[UR.4col.v2]


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://secure-web.cisco.com/1epTSuJ1sNmK9oaOrc6HbHvmDAqPbbI9PVD3Y0jbdij7zNVdFs0MkJ4y_NpTsvWrIBYdim8TJ0vfdWTR1ApsdXdl1C23E-Dcwno1pnSQ-WoF8niSCNg1R3XGJQM99ssN0FwRJTti3ZqPJ6SQcvcL4e3x1Dx42HYnDjOnyUQxuUJ03nG2Dhgl-4BmB7_DdTaO_clnR6daTCOzbQBv0FHUq4pFjjmAq55-844ErUHjrtqmpU5XSKgwF0KUT1YM63MJC_ago2Q2z25OX3Q8hFPSZZkffb3E86z1mEBnSX8GL4RJ3op-jTzT4K2TxKZ290nicSeW9CAdEWjzJ8Ju5d0vVFw/https%3A%2F%2Fwww.educause.edu%2Fcommunity>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Current thread: