Celebrate Cybersecurity Awareness Month with UCOP
October is National Cybersecurity Awareness Month, and the UCOP Information Security Team is helping our colleagues learn how to protect themselves at work and in their private lives.
Read a message from UCOP Chief Information Security Officer April Sather
Cybersecurity Awareness Month is an opportunity to recognize that every aspect of our mission – and the trust placed in us by our communities – depends on strong cybersecurity. Artificial intelligence is changing the threat landscape, giving attackers new ways to create convincing social-engineering messages, impersonate trusted individuals and target our staff and systems at scale. AI is also accelerating vulnerability exploitation, leaving us less time to identify and address weaknesses. UCOP continues to evolve our defenses to meet this moment.
In parallel, we are committed to securely enabling staff to use AI in productive and responsible ways; visit the UCOP Artificial Intelligence Hub for the latest guidance and resources, including new agentic AI security guardrails. One of the most important drivers of successful AI outcomes is quality data. By keeping only the data we need and disposing of information appropriately when it is no longer required, we achieve two things: provide a strong foundation for trustworthy AI and reduce our target size for cybercriminals. Data we don’t have cannot be stolen. Following the UC records retention schedule helps us manage information responsibly, meet our legal and operational obligations, reduce unnecessary costs and limit the potential impact of a security incident.
Security is a shared responsibility, and our everyday choices truly matter. Use strong, unique passwords and multifactor authentication; pause before responding to unusual requests; install updates promptly; report suspected phishing or other concerns; and secure your devices wherever you work. I encourage everyone to take part in Cybersecurity Awareness Month activities and attend upcoming events, including the UC Cybersecurity Summit and other sessions hosted across our system.
Warm regards,
April Sather
Chief Information Security Officer
UCOP & Systemwide Cyber Defense Officer (Interim)
Register for systemwide virtual cybersecurity events
Listings reflect Pacific Time. Select each event name for registration.
2026 UC Cybersecurity Summit: Resilient Together
Oct. 6, 9 a.m. to 12 p.m. | Oct. 7, 9 a.m. to 12:30 p.m.
Learn how we can safeguard our institution and communities. Alongside leading voices in cybersecurity, we’ll examine an evolving digital landscape, from artificial intelligence and online safety, to privacy, fraud prevention and the protection of critical infrastructure. Whether you’re a security professional or simply curious about today’s digital risks, you’ll gain practical insights and a better understanding of how we can all build a more secure digital future.
AI Vulnerability Scanning in the Age of Mythos
Oct. 8, 12 – 1 p.m.
Join UC Santa Barbara Computer Science Professor and Vice Chair Christopher Kruegel for an insightful exploration into the evolving landscape of AI-driven vulnerability scanning. As autonomous models and AI capabilities like Mythos transform software security, traditional analysis techniques face unprecedented challenges. In this session, Dr. Kruegel breaks down how next-generation AI models uncover zero-days, where current automated scanning falls short, and what security teams must do to stay ahead of AI-accelerated threats.
The Vibes Are Off: How to Safely Build Apps with AI Agents
Oct. 13, 2 – 3 p.m.
“Vibe coding,” using AI to write applications for you, is everywhere in the coding world. It promises to enable novice coders to create apps far beyond their skill level and to help all coders work more efficiently. But these AI tools usually prioritize functionality and speed over security. That can be great for little local scripts, but it’s much more problematic when used for work or research. Join UCLA Health’s Senior Mayhem Creator Michael Taggart on a journey to explore how vibe coding can be done responsibly and securely — and how it can go horribly wrong.
Mental Malware: Why the Human OS Keeps Getting Hacked
Oct. 15, 11 a.m. – 12 p.m.
Social engineering works because it targets what makes us human: our biases, cognitive shortcuts, emotions and deeply wired instinct to trust. Drawing on studies from the field of psychology, this session unpacks the brain’s architecture that enables manipulation to be disturbingly effective. Learn how generative AI is raising the stakes, making it harder than ever to differentiate what’s real and what’s not. You’ll leave with a deeper understanding of the psychology behind deception — and how to push back.
From Extortion to Espionage: The Frontline Threat Landscape for Higher Education
Oct. 15, 12 – 1 p.m.
Higher education institutions are prime targets for cyber threats ranging from lucrative ransomware schemes to sophisticated state-sponsored espionage. Join Jeremy Rosado, senior intelligence analyst with the Google Threat Intelligence Group, for an insider’s look into the evolving threat landscape confronting colleges and universities.
Should I Put That Into ChatGPT? Protecting UC Data When Using AI
Oct. 20, 10 – 11 a.m.
A conversation featuring UCSF Data Security Compliance Director Mary Morshed.
AI and Privacy
Oct. 21, 12 – 1 p.m.
How does rapid AI adoption intersect with modern privacy laws? Join Goodwin Associate Reema Moussa for a focused, one-hour session on protecting user data, staying compliant and mitigating legal risk in the age of AI.
AI, Deepfakes & Social Engineering
Oct. 28, 10 – 11 a.m.
This UCSF-sponsored conversation will feature Ben Syn, director of University and Career Education at KnowBe4.
Public Interest Cybersecurity: How Cal Researchers Defend Nonprofits, Schools and Cities from Digital Threats
Oct. 29, 11 a.m. – 12 p.m.
Who gets left behind when federal resources focus only on “national security threats”? Join this talk by Sarah Powazek, director of public-interest cybersecurity at the UC Berkeley Center for Long-Term Cybersecurity, to learn how Cal researchers are shaping the national conversation on “critical infrastructure.” Sarah will share more about cutting-edge survey research on nonprofits and international coalition-building efforts to provide a safety net of digital defenses for all organizations, regardless of their technology budget size. She will also highlight key market failures the team is investigating, innovative solutions such as cybersecurity clinics and student/regional SOCs, and other ways academia, industry, government and nonprofits are joining forces to provide defenses against rapidly growing digital threats.
ClickFix: Turning User Trust Into Code Execution
Oct. 29, 2 – 3 p.m.
What is the “ClickFix” compromise? Join us for a cybersecurity presentation led by UC Irvine’s cybersecurity club, Cyber@UCI, exploring ClickFix, a social engineering technique that tricks users into performing actions that can ultimately compromise their devices. During this interactive demo, we’ll show what ClickFix is, why it’s malicious and the warning signs you need to recognize. We’ll also cover practical defenses and simple steps you can take to stop an attack before it becomes a security incident. Know hackers’ tricks, and you’ll nix the ClickFix!
Additional cybersecurity resources
- Information Security website
- Report an Incident or Vulnerability
- UCOP Unit Information Security Lead Directory
- UCOP Records Management
Tags: cybersecurity, National Cybersecurity Awareness Month

