The Staff Spotlight: Exploring Your UW Support Network
This series shines a light on the support systems that help staff at the University of Waterloo thrive. Through conversations with the staff behind this work, we highlight the services available to staff and opportunities to get involved and grow.
In honour of Cyber Awareness Month in October, we're spotlighting Andriana Vanezi, a Systems Integration Specialist with Information Security Services, where she helps staff and departments navigate cybersecurity risks and make informed decisions about technology. We spoke with her about cyber awareness, the simple habits that can help prevent attacks, and the role every member of the campus community plays in keeping Waterloo secure.
Tell us about your role in IST and how you help keep the university community safe.
My role is Systems Integration Specialist on the Information Security Services team. There are two parts to my role. One is risk management. In that role, I help campus evaluate new tools and projects based on a security lens, where I look for risks and mitigations. The second part of my job is cyber awareness across campus, which includes campaigns, presentations, and training.
Andriana Vanezi, Systems Integration Specialist, Information Security Services
It sounds really corny, but you are the last shield protecting campus, and you don't have to be a technically savvy person to be that shield.
Don't miss Andriana's upcoming UWSA workshop!
Cybersecurity at Home and Beyond
This interactive Cyber Awareness Month session will explore four practical themes that can help participants better protect themselves, their families, and their communities. Participants are encouraged to ask questions about their own experiences as well as concerns involving children, teenagers, spouses, parents, grandparents, friends, or other family members. Open to all staff and retirees. Please register on Portal to attend in person or online.
How did you find your way into this role?
I've been with the University of Waterloo for eight years, and I spent my first four years in the Office of Research working on systems. Then this role opened up in Information Security Services that allowed me to pair my two passions: picking things apart and finding the gaps, and translating technical jargon into a way that people can understand so it can really empower them. That's how I found my way to this role.
Part of your work involves helping people understand cybersecurity risks. What is the biggest cybersecurity myth that you'd like to bust?
I guess the biggest myth would be that you need to be very technically savvy to protect yourself from cyberattacks or breaches. When it comes down to it, most attacks happen because of the human element.
At the end of the day, it sounds really corny, but you are the last shield protecting campus, and you don't have to be a technically savvy person to be that shield.
If you could give every staff member one cybersecurity habit, what would it be?
Definitely the PAUSE framework. What that really means is trying to put a moment between an action and your reaction.
The PAUSE framework stands for:
- P is for Pause. Breathe before you react.
- A is for Awareness. How is the message or situation making you feel? Do you feel pressure? Urgency? Are you trying to please someone? Those feelings are data, and they're often the biggest clue when it comes to phishing and other attacks because they are so well crafted now.
- U is for Unpack. Think about the situation. Does it make sense? Would the president of the university ask you to go buy gift cards? Probably not, if you slow down and think about it.
- S is for Select your next step. Go outside the message to verify; don't use links inside the email.
- E is for Escalate. Report it to the Security Operations Centre (SOC – soc@uwaterloo.ca). Even if you're not sure it's an attack, or even if you've already clicked, there's no shame. Just report it.
The PAUSE framework isn't very technical, but it's probably the best defense we all have.
What are a couple other important things that staff can do to protect themselves and the university from cyber threats?
You've probably heard it many times, but you need long, strong, and unique passwords for every account. They should be at least 15 characters long. Of course, it's impossible to memorize all of these passwords, so use a password manager. There are great secure options, such as Bitwarden and 1Password. 1Password is Canadian, and both offer free options.
The other piece of advice is to always use multi-factor authentication. Here on campus, we use Duo. You may not know that your Duo application can actually be used for many different accounts. You can add Amazon, banking, and other accounts to use it as your two-factor authentication. Using an authenticator app is always the strongest method of two-factor authentication.
What do you wish every staff member knew about cybersecurity?
I wish every person on campus knew that cybersecurity is a shared responsibility.
It's not just the job of Information Security Services to keep everyone secure. We all play a role. The small habits of everyone are what build that shield around campus.
What are some tools or resources available to help staff build their cybersecurity knowledge and skills?
We have lots of resources on campus. Our Cyber Awareness website is really a hub that links to everything.
The thing I'd most like to highlight is our newsletter, which launched last year. It's called Honk If You're Secure. It has two sections:
- Tales from the SOC, which provides insight into real security incidents that happened on campus and allows everyone to learn from them.
- The Goose Guide, which offers awareness and guidance on emerging topics.
You can subscribe through the Cyber Awareness website.
What is something people might be surprised to learn about the cybersecurity work going on behind the scenes at UW?
I think people would be surprised to know that cybersecurity is really just risk management with a cool name. What we're doing is identifying risks, looking at the likelihood that something might happen, assessing the impact if it does happen, and then trying to mitigate that risk. And also responding when something actually does happen.
For example, we can help people think through whether they want to use a new AI tool. We can help them make a defensible decision. It might be a cool tool, but do you really want to give up all of your intellectual property to that AI tool?
It might be a cool tool, but do you really want to give up all of your intellectual property to that AI tool?
Andriana's top cybersecurity tips
Take a PAUSE
Pause: Breathe before you react.
Awareness: Take note of how the message makes you feel.
Unpack: Does this situation make sense?
Select your next step: Verify outside of the message itself.
Escalate: Report it to soc@uwaterloo.ca.
What’s your favourite part of working at UW?
Definitely being part of the community. Everybody is working toward the same goal, supporting the next generation of students and researchers.
What is another staff role that deserves a spotlight?
I would say Natasha Jennings. She is the IST Communications Officer and is responsible for letting campus know about technical updates and systems across the university. She's been instrumental in this cyber awareness campaign. I often find that supportive roles like that go unrecognized, even though they're integral to IST and really to all of campus.
Do you have an idea for a support, service, or team we should spotlight? Tell us! We prioritize suggestions that showcase less visible work, reflect a broad range of roles and lived experiences, and centre voices and roles that are often under-recognized.