Educause Security Discussion mailing list archives

Re: Email Banner


From: "Albrecht, Travis" <000000ce07f65231-dmarc-request () LISTSERV EDUCAUSE EDU>
Date: Wed, 24 Jun 2020 18:10:43 +0000

More than a year ago we implemented a banner on incoming email from free email providers rather than all external 
email.  This catches a large portion of the threat without causing banner fatigue.  We also have a banner that was 
reviewed by a color-blind user, i.e. without red or brown.

CAUTION: This message was sent from an EXTERNAL EMAIL account. Please do not reply, click links, or open attachments 
unless you recognize the source of this email and know the content is safe.

Over the last year we have been expanding banner usage to raise awareness of other phishing indicators like: mixed 
Latin and Cyrillic text, link shorteners, "trusted sender" text, and links to commonly exploited infrastructure like 
jotform and wufoo.

HTH!

Travis Albrecht
CHIEF INFORMATION SECURITY OFFICER
............................................................................................
Information Technology Division
UW-Green Bay, 2420 Nicolet Drive, Green Bay, WI 54311
tel: (920) 465-2974  |  e-mail: albrecht () uwgb edu<mailto:albrecht () uwgb edu>
web: https://www.uwgb.edu/information-technology/security-policy/
follow: twitter<https://twitter.com/UWGBCyberSec>
outages and current phishing warnings: https://www.uwgb.edu/information-technology/outages/



From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Ballister, Mark
Sent: Wednesday, June 24, 2020 9:53 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Email Banner

Good afternoon,

I am looking for information on who has implemented an external email banner and who has not.  For those that have, 
have you seen an improvement in user behavior around phishing?  Thank you for your time.

Thank you,
Mark

Mark J. Ballister, CPP | CISM | CISSP
Chief Information Security Officer (CISO)
University of Rochester
(585) 276-6200 (Office)
(585) 472-2361 (mobile)

[UR.4col.v2]


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Calbrecht%40UWGB.EDU%7Cb5058882583a4e17528508d8184fc148%7C7fc34f9d1f754f96b5b33cdcaab03aea%7C0%7C1%7C637286078118607348&sdata=SMJbP%2Bpglpxlff7HsJLmTLdkTjjpdtwemM05zwxImGI%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Current thread: