09/29/2026 | Press release | Archived content
In October, the European Cyber Security Month, we encourage members of the University of Tartu to develop secure digital habits and increase their awareness of cyber threats. Cybersecurity is an important part of information security, the aim of which is to protect data, devices and information systems and to ensure that information reaches the right people in a secure manner.
Many cyberattacks do not begin with a sophisticated technical operation, but rather with what appears to be an ordinary email, message or phone call. Therefore, the security of our data, accounts and devices depends on all of us. During Cybersecurity Month, we will focus on one important topic each week.
Week 1. Phishing emails
The purpose of phishing emails is to trick people into opening malicious links or attachments, sharing their login credentials, or making hasty, ill-considered decisions. Warning signs include unexpected urgency, an unusual sender, a threatening tone, or a request to share sensitive information.
Before clicking a link, check the sender's address and the link's actual destination. Do not enter passwords or PIN codes as part of an activity that you did not initiate yourself. If something seems suspicious, seek advice from the UT IT helpdesk or verify the information with the sender through another communication channel.
If you have already clicked a suspicious link or entered your information, report it to the IT helpdesk immediately. Prompt reporting can help limit potential damage.
Week 2. Password security
A strong password and two-factor authentication are among the simplest ways to protect your accounts. Use different, sufficiently long passwords for different accounts. To store passwords securely, use a trusted password manager rather than your browser's password-saving feature.
Enable two-factor authentication wherever possible. Keep your work and personal accounts separate, and never share your passwords with others. If you suspect that a password has been compromised or fallen into unauthorised hands, change it immediately.
Week 3. Device security
Security updates fix known vulnerabilities and help keep devices protected. Install security updates for your operating system, browser and applications as soon as they become available. Download software only from official sources.
Always lock your screen when leaving your computer. Use standard user privileges for your day-to-day work and use administrator privileges only when required for a specific task. Never leave your laptop unattended and, where possible, encrypt the device's drive using software such as BitLocker or FileVault.
Keep at least one backup copy of important files in a separate secure location.
Week 4. Sharing data
Work-related files must be stored in university-provided environments such as OneDrive and SharePoint. Before sending a file or creating a share link, always check the recipients and access permissions.
The same level of care is needed when using AI tools. Do not enter confidential, personal, contractual or unpublished research or teaching-related information unless you have explicit authorisation and are using an appropriate environment. Share only the data that is genuinely necessary to complete the task. Read more about what data must not be entered into AI tools on the AI website.