CISA urges users to remain on alert for malicious cyber activity following a natural disaster such as a hurricane or typhoon, as attackers target potential disaster victims by leveraging social engineering tactics, techniques, and procedures (TTPs). Social engineering TTPs include phishing attacks that use email or malicious websites to solicit personal information by posing as a trustworthy organization, notably as charities providing relief. Exercise caution in handling emails with hurricane/typhoon-related subject lines, attachments, or hyperlinks to avoid compromise. In addition, be wary of social media pleas, texts, or door-to-door solicitations related to severe weather events.
Sensitive information is privileged information which – if compromised through alteration, corruption, loss, misuse, or unauthorized disclosure – could cause serious harm to an individual or organization. You must always give the highest level of protection to privileged information. Here we discuss Personally Identifiable Information, or PII.
For the purpose of data protection, Personal Identifiable Information is defined as any instance of an individual’s first name, or first initial, the last name, and any one of twenty-nine additional confidential items.
The additional confidential items include Social Security number, driver license, credit card number and expiration date, date or place of birth, wage and salary information, vehicle identifiers including license plate numbers, and medical history.
The key to remembering if the information can be used to uniquely identify a specific individual using non-public information, it’s considered PII and must be protected.
Example:
John Smith was born on January 1, 1965. Which listing below would be the example of PII?
- A) John Smith – DOB 1/1/1965
- B) John S. – DOB 1/1/196
- C) John Smith – DOB 1/1/xxxx
The answer is A. B and C are not examples of PII on their own.
Employees who do not take care of sensitive information can lead their organizations into fines, increased operating costs, loss of customer confidence, and even more governmental regulation. Do your part to keep your sensitive information safe at all times.
The KnowBe4 Security Team
KnowBe4.com