Good afternoon, everyone.
Welcome to the second week of Cybersecurity Awareness Month. The theme for 2026 Cybersecurity Awareness Month is Don’t Make It Easy for Them; and by building and repeating strong security habits every day, we can all make life more difficult for the cybercriminals. Each week this month I will give simple tips for how to stay safe online. Today’s topic is Multifactor Authentication.
Multifactor authentication (MFA) is a security process that requires two or more distinct types of user authentication to verify a user’s identity before granting access to an account or a system. There are three types of factors:
- Something you know, which your NetID (username) and password;
- Something you have, which can be a smartphone app (e.g., Duo), a hardware token, a text code; and
- Something you are, which can be biometric data (e.g., fingerprint or facial scan).
UT currently uses Duo, which is two-factor authentication (2FA). While MFA is not exactly the same as 2FA, all 2FA is a type of MFA. Duo uses the first and second factors listed above. However, you should turn on MFA for all your personal accounts, as well. Check your settings for your bank, credit card, shopping accounts, etc., and make sure you turn on MFA if you have this option. This will certainly help protect your data and your identity. Most accounts will use Google Authenticator or Microsoft Authenticator. You should only download these two apps from Google Play or the Apple Store to ensure you are getting the secure versions.
Since MFA is a layered approach, using it for your accounts helps make you 99% less likely to be hacked. If even one credential becomes compromised, unauthorized users will not be able to meet the second authentication requirement and, therefore, will not gain access. Please remember that if you get a push notification or code, make sure you actually requested the code, text, etc., before you “allow” it and never, ever share that code with anyone. With so many notifications these days, we can inadvertently give someone access just by not paying close enough attention and pressing “allow” too quickly.
There is no better time than during Cybersecurity Awareness Month to complete your Cybersecurity Awareness Training if you haven’t already. Just log into K@TE using your NetID and password, then look for the 2026-2027 Compliance UTK training. The training package is role-based so there are different names, but the Cybersecurity Awareness training is one of the assignments within that package.
- If you get an error that says “This file can no longer be accessed”; or the training hangs up, there is something most people have in common that leads to this.
- The security awareness training has been known to not work as well when using the Firefox browser.
- If you get the error or the hanging and you are using Firefox, please log out of K@TE, then close your browser and try again using either Chrome or Edge.
- If you had been using Chrome or Edge and this happens to you, log out of K@TE, then close your browser and try again with the other browser.
- If you have not completed the training by the deadline, you will automatically lose access to almost everything using the NetID for authentication, including email, until you log into K@TE and complete the training.
Thank you all for everything that you do to keep the Institute and its data safe. When you have questions or concerns, please don’t ever hesitate to let me know!
Sandy
Important Note: Thank you so much for sharing these e-newsletters with family, friends, clients, students, and anyone else who may benefit from the information. I would like to stress that you should keep your students in mind, as non-employee students will not get this information without someone sharing. If anyone has an email group for students who are not employees of your department, please let me know what that address is, and I can include it. I do this as a blind copy so student names and addresses will not show up!
