Report a Security Incident

report

Computer Security Incident

A computer security incident is any attempted or successful unauthorized access, disclosure, or misuse of computing systems, data or networks, including hacking and theft.

  • Report anything unusual. If it sets off a warning in your mind, it just may be a problem. Don’t ignore it!
  • Immediately report suspected security incidents and breaches to your supervisor and the ITS Support CenterBe sure to indicate whether sensitive information may be at risk.
  • If you think your computer has been compromised, or someone might be accessing your computer remotely, it is best if you can unplug the network cable (and turn your wireless off, if you have it) and leave the computer on until help arrives.
  • Warning signs your computer might be infected

Theft of Computing Equipment

Report suspected theft of UCSC-related computing equipment to the police in addition to notifying the ITS Support Center and your supervisor.


Checklist for Lost or Stolen Mobile Devices

  • Immediately report lost or stolen devices to the police
    • Report to UCSC police for campus incidents and local police for off-campus incidents (phone is best)
    • Always get an incident or report number
    • Call them back if item is found, including if a separate agency contacts you regarding a found device
  • If you used the device for work
    • Also report it to the ITS Support Center (info above) so they can help identify and address potential compromised accounts or data
    • Notify your supervisor if it was a University-owned device
  • For phones, notify your cellular carrier-- see if they can deactivate the device
  • Change all passwords stored or used on the device, including email, Dropbox, banking, etc.
  • Notify credit card companies and banks if you used the device for shopping or banking
  • Try to track its location, if possible
  • Try remote wipe if sensitive data or passwords were stored

Tips for protecting mobile devices: http://its.ucsc.edu/security/mobile.html


Reporting Spam and Phishing

Here’s how you can help yourself and others.

  • DO NOT respond directly to a phishing attempt.
  • DO REPORT an email phishing attempt immediately to ITS and Google by following these steps:
    • Report to ITS: Copy the entire message including full headers and email that information to the ITS security team at help@ucsc.edu. Full headers provide information about the path the message took to get to you. Headers are a critical resource in determining the origin of a phishing email. ITS needs full headers to investigate the phish. Instructions on finding headers for a message.
    • Report to Google: In Gmail, open the message, click the Down arrow (next to the Reply button), and then click Report phishing.

Prevent


For ITS Staff:

List of KBs relating to computer security incident reporting and response (login required)


Rev. April 2017