<?xml version="1.0"?>
<News hasArchived="false" page="2" pageCount="10" pageSize="10" timestamp="Mon, 07 Sep 2026 23:50:13 -0400" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts.xml?page=2&amp;tag=cybersecurity">
<NewsItem contentIssues="false" id="133473" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/133473">
<Title>Lessons from &#8216;Star Trek: Picard&#8217; &#8211; a cybersecurity expert explains how a sci-fi series illuminates today&#8217;s&#160;threats</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2023/05/Conversation-Star-Trek-150x150.jpg" alt="A Star Trek spacecraft seen orbiting above the Earth." style="max-width: 100%; height: auto;">
    <p><em>Written by <a href="https://theconversation.com/profiles/richard-forno-173226" rel="nofollow external" class="bo">Richard Forno,</a> principal lecturer in <a href="https://www.csee.umbc.edu/" rel="nofollow external" class="bo">computer science and electrical engineering</a>, UMBC</em></p>
    
    
    
    <p><em>Editor’s note: This article contains plot spoilers.</em></p>
    
    
    
    <p>Society’s understanding of technology and cybersecurity often is based on simple stereotypes and sensational portrayals in the entertainment media. I’ve written about how certain scenarios <a href="https://doi.org/10.1145/3121113.3132158" rel="nofollow external" class="bo">are entertaining but misleading</a>. Think of black-clad teenage hackers prowling megacities challenging corporate villains. Or think of counterintelligence specialists repositioning a satellite from the <a href="https://www.washingtonpost.com/archive/opinions/2000/07/02/a-look-at-spy-satellites-38/ea4e1779-da97-4081-94a7-14bb3993e5df/" rel="nofollow external" class="bo">back of a surveillance van</a> via a phone call.</p>
    
    
    
    <p>But sometimes Hollywood gets it right by depicting reality in ways that both entertain and educate. And that’s important, because whether it’s a large company, government or your personal information, we all share many of the same cybersecurity threats and vulnerabilities. As a former cybersecurity industry practitioner and current <a href="http://www.csee.umbc.edu/%7Erforno/" rel="nofollow external" class="bo">cybersecurity researcher</a>, I believe the final season of “<a href="https://www.paramountplus.com/shows/star-trek-picard/" rel="nofollow external" class="bo">Star Trek: Picard</a>” is the latest example of entertainment media providing useful lessons about cybersecurity and the nature of the modern world.</p>
    
    
    
    <p>So how does “Star Trek: Picard” relate to cybersecurity?</p>
    
    
    
    <h4>The nature of the threat</h4>
    
    
    
    <p>The show’s protagonist is Jean-Luc Picard, a retired Starfleet admiral who commanded the starship Enterprise-D in a previous series. Starfleet is the military wing of the United Federation of Planets, of which Earth is a member. In Season 3, the final season, Picard’s ultimate enemy, the Borg, returns to try conquering humanity again. The <a href="https://memory-alpha.fandom.com/wiki/Borg" rel="nofollow external" class="bo">Borg</a> is a cybernetic collective of half-human, half-machine “drones” led by a cyborg queen.</p>
    
    
    
    <p>The Borg has partnered with other villains and worked for over a decade to deploy hidden agents able to compromise the DNA data contained in the software underpinning the transporter – a teleportation device used regularly by Starfleet personnel. Over many years, a certain subgroup of Starfleet personnel had their DNA altered by using the transporter.</p>
    
    
    
    <p>Thus, in launching their final attack, the Borg is able to instantly activate thousands of “drones” to do its bidding in the form of altered, compromised Starfleet personnel. As Geordi La Forge, the Enterprise-D’s engineer, notes, “They’ve been assimilating the entire fleet this whole time, without anyone ever knowing it.” </p>
    
    
    
    <div>
    <div><div class="embed-container"><iframe src="https://www.youtube.com/embed/9v1GTS82OhM?feature=oembed" frameborder="0" webkitallowfullscreen="webkitAllowFullScreen" mozallowfullscreen="mozallowfullscreen" allowfullscreen="allowFullScreen">[Video]</iframe></div></div>
    </div>Instead of malicious software taking over computers, the plot involves malicious genetic code taking over humans.
    
    
    
    <p>The Borg’s prolonged, stealthy infiltration of the federation is indicative of how today’s most effective cyberattackers work. While it’s relatively easy to detect when hackers attempt to breach a system from the outside, experts worry about the effects of an enemy infiltrating critical systems <a href="https://www.wired.com/story/solarwinds-hack-supply-chain-threats-improvements/" rel="nofollow external" class="bo">from within</a>. Attackers can put malicious code in software during manufacturing or in software updates, both of which are avenues of attack that do not arouse suspicion until the compromised systems are activated or targeted.</p>
    
    
    
    <p>This underscores the importance of ensuring the security and integrity of digital supply chains from <a href="https://www.mxdusa.org/" rel="nofollow external" class="bo">product development</a> at the vendor through product deployment at client sites to ensure no silent “drones,” such as malware, are <a href="https://www.crowdstrike.com/cybersecurity-101/advanced-persistent-threat-apt/" rel="nofollow external" class="bo">waiting to be activated</a> by an adversary.</p>
    
    
    
    <p>Equally important, “Star Trek: Picard” presents the very real and insidious nature of the insider threat faced by today’s organizations. While not infected with a cybernetic virus, recently arrested Massachusetts Air National Guard airman Jack Teixeira shows the damage that can occur when a <a href="https://www.cisa.gov/topics/physical-security/insider-threat-mitigation/defining-insider-threats" rel="nofollow external" class="bo">trusted employee has malicious intent or becomes co-opted and inflicts significant damage</a> on an employer.</p>
    
    
    
    <p>In some cases, these compromised or malicious individuals can remain undiscovered for years. And some global adversaries of the U.S., such as China and Russia, are known for taking a long-term perspective when it comes to planning and conducting espionage activities – or <a href="https://www.washingtonpost.com/politics/2023/04/27/chinese-russian-hackers-are-making-moves-heres-how-nsa-is-trying-counter-them/" rel="nofollow external" class="bo">cyberattacks</a>.</p>
    
    
    
    <h4>Humans remain the weakest link</h4>
    
    
    
    <p>“Synchronistic technology that allows every ship in Starfleet to operate as one. An impenetrable armada. Unity and defense. The ultimate safeguard.”</p>
    
    
    
    <p>With these words, humanity’s military defenders activated a feature that linked every Starfleet vessel together under one unified automated command system. While intended to serve as an emergency capability, this system – called <a href="https://www.youtube.com/watch?v=nkkj4myTukY" rel="nofollow external" class="bo">Fleet Formation</a> – was quickly hijacked by the Borg as part of its attack on Earth. In essence, Starfleet created a Borg-like defense system that the Borg itself used to attack the federation.</p>
    
    
    
    <p>Here, the most well-intentioned plans for security were thwarted by enemies who used humanity’s own technologies against them. In the real world, capabilities such as on-demand real-time software updates, ChatGPT and centrally administered systems sound enticing and offer conveniences, cost savings or new capabilities. However, the lesson here is that organizations should not put them into <a href="https://www.technologyreview.com/2023/03/25/1070275/chatgpt-revolutionize-economy-decide-what-looks-like/" rel="nofollow external" class="bo">widespread use</a> without carefully considering as many of the potential risks or vulnerabilities as practical.</p>
    
    
    
    <p>But even then, technology alone can’t protect humans from ourselves – after all, it’s people who develop, design, select, administer and use technology, which means human flaws are <a href="https://theconversation.com/did-twitter-ignore-basic-security-measures-a-cybersecurity-expert-explains-a-whistleblowers-claims-189668" rel="nofollow external" class="bo">present in these systems</a>, too. Such failings frequently lead to a stream of <a href="https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents" rel="nofollow external" class="bo">high-profile cybersecurity incidents</a>.</p>
    
    
    
    <h4>Resiliency is not futile</h4>
    
    
    
    <p>To counter the Borg’s final assault on Earth, Picard’s crew borrows its old starship, Enterprise-D, from a fleet museum. The rationale is that its ship is the only major combat vessel not connected to the Borg collective via Starfleet’s compromised Fleet Formation protocol and therefore is able to operate independently during the crisis. As La Forge notes, “Something older, analog. Offline from the others.” </p>
    
    
    
    <div>
    <div><div class="embed-container"><iframe src="https://www.youtube.com/embed/BtTBjxOow2Q?feature=oembed" frameborder="0" webkitallowfullscreen="webkitAllowFullScreen" mozallowfullscreen="mozallowfullscreen" allowfullscreen="allowFullScreen">[Video]</iframe></div></div>
    </div>When a network has been compromised, it’s important to be able to use systems that aren’t connected to the network.
    
    
    
    <p>From a cybersecurity perspective, ensuring the <a href="https://csrc.nist.gov/glossary/term/availability" rel="nofollow external" class="bo">availability</a> of information resources is one of the industry’s guiding principles. Here, the Enterprise-D represents defenders in response to a cyber incident using assets that are <a href="https://cygnvs.com/resources/learning-from-experience-why-you-need-an-out-of-band-network-for-incident-response" rel="nofollow external" class="bo">outside of an adversary’s reach</a>. Perhaps more important, the vessel symbolizes the need to think carefully before embracing a completely networked computing environment or relying on any single company or provider of services and connectivity for daily operations.</p>
    
    
    
    <p>From natural disasters to cyberattack, what’s your plan if your IT environment becomes corrupted or inaccessible? Can your organization stay operational and still provide necessary services? For critical public messaging, do governments and corporations have their own uncorruptible Enterprise-D capabilities to fall back on, such as the <a href="https://fediverse.party/" rel="nofollow external" class="bo">fediverse</a>, the decentralized microblogging platform that is immune to <a href="https://www.theverge.com/2023/5/2/23708739/twitter-transportation-emergency-alerts-api-free" rel="nofollow external" class="bo">the impulsive manipulations</a> of Twitter’s ownership?</p>
    
    
    
    <h4>Prepare for the unknown</h4>
    
    
    
    <p>The “Star Trek” universe explores the unknown in both the universe and contemporary society. How the crews deal with these experiences relies on their training, the appreciation of broad perspectives and ability to devise innovative solutions to the crisis of the week. Often, such solutions are derived from characters’ interests in music, painting, archaeology, history, sports and other nontechnical areas of study, recreation or expertise.</p>
    
    
    
    <p>Similarly, as modern digital defenders, to successfully confront our own cyber unknowns we need a broad appreciation of things beyond just cybersecurity and technology. It’s one thing to understand at a technical level how a cyberattack occurs and how to respond. But it’s another thing to understand the broader, perhaps more systemic, nuanced, organizational or international factors that may be causes or solutions, too.</p>
    
    
    
    <p>Lessons from literature, history, psychology, philosophy, law, management and other nontechnical disciplines can inform how organizations plan for and respond to cybersecurity challenges of all types. Balancing solid technical knowledge with foundations in the liberal arts and humanities allows people to adapt comfortably to constantly evolving technologies and shifting threats.</p>
    
    
    
    <p><a href="https://charlestoncitypaper.com/2016/08/17/1970s-colossus-the-forbin-project-is-more-relevant-than-ever/" rel="nofollow external" class="bo">Dystopic metaphors</a> in fiction often reflect <a href="https://www.youtube.com/watch?v=_Wlsd9mljiU" rel="nofollow external" class="bo">current social concerns</a>, and the “Star Trek” universe is no different. Although rooted in a science fiction fantasy, “Star Trek: Picard” provides some accurate, practical and understandable cybersecurity reminders for today.</p>
    
    
    
    <p>Season 3, in particular, offers viewers both entertainment and education – indeed, the best of both worlds.</p>
    
    
    
    <hr>
    
    
    
    <p><em>This article is republished from <a href="https://theconversation.com/" rel="nofollow external" class="bo">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/lessons-from-star-trek-picard-a-cybersecurity-expert-explains-how-a-sci-fi-series-illuminates-todays-threats-204433" rel="nofollow external" class="bo">original article</a> and see more <a href="https://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">than 250 UMBC articles</a> available in The Conversation.</em></p>
    </div>
]]>
</Body>
<Summary>Written by Richard Forno, principal lecturer in computer science and electrical engineering, UMBC      Editor’s note: This article contains plot spoilers.      Society’s understanding of...</Summary>
<Website>https://umbc.edu/stories/cybersecurity-lessons-from-star-trek-picard/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/133473/guest@my.umbc.edu/802efa8fe7d9638f8a1da35f3be349bd/api/pixel</TrackingUrl>
<Tag>coeit</Tag>
<Tag>csee</Tag>
<Tag>cybersecurity</Tag>
<Tag>discovery</Tag>
<Tag>magazine</Tag>
<Tag>the-conversation</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>1</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Fri, 12 May 2023 12:09:10 -0400</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="133323" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/133323">
<Title>Center for Women in Technology Scholar shines on the volleyball court</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2023/05/Kayla-Tomas-Class-of23-1622-150x150.jpg" alt="A woman in a red outfit smiles at the camera" style="max-width: 100%; height: auto;">
    <h4><strong>Kayla Tomas</strong></h4>
    
    
    
    <p><strong>Degrees</strong>: B.S., Information Systems<br><strong>Hometown</strong>: Silver Spring, MD<br><strong>Post-grad plans</strong>: Cybersecurity Consultant for <a href="https://www.kpmg.us/" rel="nofollow external" class="bo">KPMG</a></p>
    
    
    
    <p><strong>Kayla Tomas</strong> cites UMBC’s Center for Women in Technology (CWIT) Scholars Program for empowering her and giving her a sense of community, especially as a Latina woman in STEM. In <a href="https://cwit.umbc.edu/cwitscholars/" rel="nofollow external" class="bo">CWIT Scholars</a>, a merit-based scholarship for talented undergraduates in computing and other technical fields, she developed friendships, found mentorship, and was able to create a close network of colleagues.</p>
    
    
    
    <p>A star athlete, Tomas played on the women’s Division 1 <a href="https://umbcretrievers.com/sports/wvball/index" rel="nofollow external" class="bo">volleyball team</a> all four years of her time at UMBC, and helped guide the team to championships in three consecutive years. She participated as a member of the <a href="https://my3.my.umbc.edu/groups/hlsu" rel="nofollow external" class="bo">Hispanic Latino Student Union</a>, and started her own Latin dance team. As a <a href="https://umbc.welcometocollege.com/grit-guide" rel="nofollow external" class="bo">Grit Guide</a>, she gave more than 50 tours of campus.</p>
    
    
    
    <p>UMBC’s alumni community has celebrated and supported Tomas through one of the university’s coveted <a href="https://www.alumni.umbc.edu/s/1325/21/interior.aspx?sid=1325&amp;gid=1&amp;pgid=451#:~:text=Eligible%20students%20may%20apply%20for,generous%20support%20of%20UMBC%20alumni." rel="nofollow external" class="bo">Alumni Endowed Scholarships</a>, awarded to six students each year through support from UMBC’s Alumni Association.</p>
    
    
    
    <img width="1200" height="800" src="https://umbc.edu/wp-content/uploads/2023/05/FD96E20D-44A8-48BA-97FC-FCC8FF338724_1_201_a-Kayla-Tomas-1200x800.jpeg" alt="A group of young women pose on a volleyball court with a sign saying America East Champions" style="max-width: 100%; height: auto;">The UMBC women’s volleyball team celebrates its 2022 America East Championship.
    
    
    
    <h4><strong>Has there been a mentor or fellow student who influenced your time at UMBC?</strong></h4>
    
    
    
    <p><strong>“Gina Ralston</strong>, a coordinator in admissions and orientation, was a staff mentor who influenced my time at UMBC. She continuously reassured me of how much of a positive impact I have. Gina was my boss when I worked as a Grit Guide. She made me feel appreciated and seen. I loved this job because I got to share my knowledge with younger students who are new to this process, maybe even women looking to be in STEM.”</p>
    
    
    
    <h4><strong>What has been the best part of your UMBC experience?</strong></h4>
    
    
    
    <p>“The best part of my UMBC experience would have to be <a href="https://umbc.edu/stories/umbc-volleyball-wins-third-consecutive-america-east-championship/" rel="nofollow external" class="bo">winning the America East title in volleyball three years in a row</a>. So much hard work, time, and dedication went into training, and it truly paid off. The friendships I made, the breakthroughs I experienced, and the challenges I faced, made me into a stronger individual and this couldn’t have happened without an amazing group of teammates. It has always been a dream of mine to play collegiate volleyball at the highest level and I achieved that. Seeing my family at every home and away game always put a smile on my face. They are my rock and have been through the highs and lows with me.”</p>
    </div>
]]>
</Body>
<Summary>Kayla Tomas      Degrees: B.S., Information Systems Hometown: Silver Spring, MD Post-grad plans: Cybersecurity Consultant for KPMG      Kayla Tomas cites UMBC’s Center for Women in Technology...</Summary>
<Website>https://umbc.edu/stories/center-for-women-in-technology-scholar-shines-on-the-volleyball-court/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/133323/guest@my.umbc.edu/811e9ec1cfeec24d218eb92d99011b50/api/pixel</TrackingUrl>
<Tag>class-of-2023</Tag>
<Tag>coeit</Tag>
<Tag>cwit</Tag>
<Tag>cybersecurity</Tag>
<Tag>information-systems</Tag>
<Tag>news</Tag>
<Tag>volleyball</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Mon, 08 May 2023 12:34:16 -0400</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="130830" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/130830">
<Title>UMBC researchers listed among the world&#8217;s top 2% of most-cited scientists and engineers</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2023/01/Pelton-Physics-lab22-5233-150x150.jpg" alt='Three people work with machinery in a lab. They wear protective glasses and gloves. One wears a sweater reading "UMBC Rerievers."' style="max-width: 100%; height: auto;">
    <p>More than 40 active UMBC researchers are listed among the top 2% of the world’s most-cited scientists and engineers in an analysis recently published by Elsevier.  </p>
    
    
    
    <p>These researchers include faculty across all three of UMBC’s academic colleges as well as UMBC’s NASA-funded centers, such as the <a href="https://gestar2.umbc.edu/" rel="nofollow external" class="bo">Goddard Earth Sciences Technology and Research (GESTAR II) Center</a>. Their work covers an incredibly diverse array of topics. Represented academic departments include:</p>
    
    
    
    <div>
    <div>
    <ul>
    <li> biological sciences</li>
    
    
    
    <li>chemical, biochemical, and environmental engineering</li>
    
    
    
    <li>chemistry and biochemistry</li>
    
    
    
    <li>computer science and electrical engineering</li>
    
    
    
    <li>geography and environmental systems</li>
    
    
    
    <li>information systems</li>
    
    
    
    <li>mathematics and statistics</li>
    
    
    
    <li>mechanical engineering</li>
    
    
    
    <li>physics</li>
    
    
    
    <li>psychology</li>
    </ul>
    </div>
    </div>
    
    
    
    <p>“We perform research to further our understanding of how the various aspects of our world function,” says <strong>Karl V. Steiner</strong>, vice president for research and creative achievement. “One of the highest recognitions in the scientific community is when other members of this community cite our work.”</p>
    
    
    
    <p>He notes, “The Elsevier analysis shows that our researchers are truly impacting the scientific community in a significant way.”</p>
    
    
    
    <h4><strong>History of citation honors</strong></h4>
    
    
    
    <p>The list includes faculty researchers who have also received other “highly cited” researcher accolades. In 2022, <strong>Erle Ellis</strong>, professor of geography and environmental systems (GES), was featured on <a href="https://clarivate.com/highly-cited-researchers/?action=clv_hcr_members_filter&amp;clv-paged=1&amp;clv-category=&amp;clv-institution=University%20of%20Maryland%20Baltimore%20County&amp;clv-region=&amp;clv-name=&amp;utm_medium=email&amp;utm_source=Eloqua" rel="nofollow external" class="bo">Clarivate’s Highly Cited Researchers list,</a> which includes papers ranked in the top 1% of citations within Clarivate’s Web of Science database. About 0.1% of the world’s researchers have received this distinction. Ellis is known for his transformational work on human-managed ecosystems, with his <a href="https://umbc.edu/stories/smithsonian-features-erle-elliss-research-on-how-humans-have-shaped-ecology-over-millennia-as-a-top-discovery-of-2021/" rel="nofollow external" class="bo">research described as top discovery</a> of 2021 by the Smithsonian National Museum of Natural History.</p>
    
    
    
    <img src="https://umbc.edu/wp-content/uploads/2023/02/Lorraine_Remer-5665-1200x800.jpg" alt="Lorraine Remer, one of UMBC's most-cited scientists -- a woman with glasses who is smiling while standing near a staircase." width="415" height="276" style="max-width: 100%; height: auto;">Lorraine Remer (Marlayna Demond ’11/UMBC)
    
    
    
    <p><strong>Lorraine Remer</strong>, research professor for the <a href="https://jcet.umbc.edu/" rel="nofollow external" class="bo">Joint Center for Earth Systems Technology</a>, who is affiliated with both GES and physics, is frequently honored for her geophysics publications. She received <a href="https://research.umbc.edu/umbc-research-news/?id=83168" rel="nofollow external" class="bo">the 2019 UMBC Research Faculty Excellence Award</a> following her recognition as one of “The Most Influential Scientific Minds” on the Thomson Reuters highly cited researchers list.</p>
    
    
    
    <p><strong>Anupam Joshi</strong>, director of <a href="https://cybersecurity.umbc.edu/" rel="nofollow external" class="bo">UMBC’s Center for Cybersecurity</a> and professor and chair of computer science and electrical engineering, was also included on Elsevier’s highly-cited list. His career trajectory demonstrates how UMBC faculty balance high-impact research with other forms of leadership. He has published more than 275 papers, has been granted nine patents, and has obtained research support from a variety of federal and industrial sources. At the same time, he is now serving as a <a href="https://umbc.edu/stories/umbcs-anupam-joshi-cybersecurity-innovator-to-expand-leadership-impact-as-2022-23-ace-fellow/" rel="nofollow external" class="bo">2022–23 American Council on Education (ACE) Fellow</a>, an intensive program focused on agility and innovative problem solving among higher education leaders. </p>
    
    
    
    <h4><strong>Measuring impact</strong></h4>
    
    
    
    <p>This latest most-cited researchers list is based on data annually compiled from author profiles in Elsevier’s abstract and citation database, Scopus. </p>
    
    
    
    <p>Elsevier’s 2022 <a href="https://elsevier.digitalcommonsdata.com/datasets/btchxktzyw" rel="nofollow external" class="bo">database of standardized citation indicators</a> classifies researchers into 22 fields and 174 subfields. Those with a composite indicator (c-score) within the top 2% of each subfield are included in the most-cited list. The list’s authors indicate that c-score is used because it “focuses on impact (citations) rather than productivity (number of publications)” and because it includes granular information on authorship, including co-authorship and author position (e.g., single, first, or last author). </p>
    </div>
]]>
</Body>
<Summary>More than 40 active UMBC researchers are listed among the top 2% of the world’s most-cited scientists and engineers in an analysis recently published by Elsevier.        These researchers include...</Summary>
<Website>https://umbc.edu/stories/most-cited-scientists-2022/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/130830/guest@my.umbc.edu/0a8209cd9947fb4136c6c8893cdbfae1/api/pixel</TrackingUrl>
<Tag>cahss</Tag>
<Tag>cbee</Tag>
<Tag>cnms</Tag>
<Tag>coeit</Tag>
<Tag>csee</Tag>
<Tag>cybersecurity</Tag>
<Tag>ges</Tag>
<Tag>gestar</Tag>
<Tag>is</Tag>
<Tag>jcet</Tag>
<Tag>meche</Tag>
<Tag>news</Tag>
<Tag>physics</Tag>
<Tag>rca-1</Tag>
<Tag>research</Tag>
<Tag>science-and-tech</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Wed, 25 Jan 2023 11:47:33 -0500</PostedAt>
<EditAt>Fri, 10 Feb 2023 17:01:24 -0500</EditAt>
</NewsItem>

<NewsItem contentIssues="false" id="129709" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/129709">
<Title>UMBC&#8217;s CyMOT receives $1.2M to expand cyber training for manufacturing workers</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2022/12/Nilanjan-Banerjee-150x150.jpg" alt="Person working on a machine with a bright light in a lab. They are wearing sunglasses." style="max-width: 100%; height: auto;">
    <p>UMBC researchers designed the Cybersecurity for Manufacturing Operational Technology (<a href="https://cymot.org/" rel="nofollow external" class="bo">CyMOT</a>) program to help manufacturing professionals grow their cybersecurity skills, protecting the sector from cyber threats and increasing their career opportunities. Now, the program has received significant additional funding to expand its impact.</p>
    
    
    
    <p>The CyMOT program—<a href="https://umbc.edu/stories/umbc-collaborates-with-mxd-to-develop-cybersecurity-curriculum-for-workers-in-manufacturing/" rel="nofollow external" class="bo">launched in 2020</a> in collaboration with the Chicago-based <a href="http://mxdusa.org/" rel="nofollow external" class="bo">MxD (Manufacturing x Digital)</a> and <a href="https://www.umbctraining.com/" rel="nofollow external" class="bo">UMBC Training Centers</a>—has been renewed with a $1.2 million grant from the U.S. Department of Defense’s Office of Local Defense Community Cooperation (OLDCC). The funding will support the implementation of new training curricula around machine learning and cybersecurity. </p>
    
    
    
    <p>“In recent years, there has been a large number of cyber attacks on the manufacturing sector,” says <strong>Nilanjan Banerjee</strong>, professor of computer science and electrical engineering and the grant’s principal investigator. To address this rising concern, Banerjee explains, CyMOT aims to “make sure that people that are in the manufacturing business can get trained and upskilled in cybersecurity concepts around manufacturing.”</p>
    
    
    
    <img src="https://umbc.edu/wp-content/uploads/2022/12/Nilanjan-Banerjee-5085-1-1200x801.jpg" alt="Close-up of a person's hands working on a machine with a very bright light." width="777" height="518" style="max-width: 100%; height: auto;">Banerjee working in his lab (Marlayna Dremond ’11/UMBC)
    
    
    
    <h4><strong>Expanding the curriculum</strong></h4>
    
    
    
    <p>The first initiative of the multi-phased project included developing a cybersecurity curriculum tailored for people who already worked in the manufacturing industry, building on their existing expertise. It provided training for a manufacturing cyber systems operator role and offered content through an online training platform. </p>
    
    
    
    <p>The first cohort included 25 manufacturing professionals. In summer 2022, the program expanded when community college students in Chicago were invited to participate in a modified version of the course.</p>
    
    
    
    <p>With this recent 12-month contract renewal, the next phase of the project will include courses for two more senior roles: a manufacturing artificial intelligence/machine learning engineer and an advanced manufacturing cybersecurity operator. This phase is slated to begin in February 2023. The additional funding will cover the cost for up to 150 new students interested in the programs. </p>
    
    
    
    <h4><strong>Creating an operational technology cyber range at UMBC</strong></h4>
    
    
    
    <p>As this program continues to grow, Banerjee also has a related objective in mind: building an operational technology (OT) cyber range at UMBC focused on cybersecurity in manufacturing. </p>
    
    
    
    <p>“We will have equipment on campus with software to run exercises for small and medium manufacturing businesses in Maryland and students at UMBC,” Banerjee explains. “The cyber range will include red team-blue team exercises, as well as exercises to learn about cyber attacks on a company’s infrastructure. We will also conduct exercises around attacks at the interface between information technology networks and operational technology networks.”</p>
    
    
    
    <p>With the cyber range, manufacturing professionals in the state can learn how to detect and mitigate cyberattacks through hands-on exercises using similar equipment found in a manufacturing OT environment.</p>
    
    
    
    <p>The cyber range will be a unique resource for training and research in Maryland. It will also tie to several cybersecurity programs offered by UMBC and an apprenticeship program offered through the Maryland Extension Partnership (MEP). With emphasis on digitizing the manufacturing sector in Maryland at a time of continually increasing interconnectivity and automation (known as Industry 4.0), the cyber range will act as the testbed to train manufacturers across the state.  </p>
    
    
    
    <h4><strong>Workforce development in Maryland</strong></h4>
    
    
    
    <p><strong>Donna Ruginski</strong>, UMBC’s executive director of cybersecurity initiatives and a co-PI of CyMOT, shares that the project has the potential to expand Maryland’s workforce development in a significant way, whether through curriculum development and delivery or an OT cyber range. </p>
    
    
    
    <img src="https://umbc.edu/wp-content/uploads/2022/12/Donna-Ruginski-8741-1-1-1200x800.jpg" alt="Professional portrait of woman smiling, wearing blue business suit and scarf" width="739" height="492" style="max-width: 100%; height: auto;">Donna Ruginski (Marlayna Demond ’11/UMBC)
    
    
    
    <p>“As the manufacturing industry implements digital transformation to Industry 4.0, cybersecurity training resources have become more important,” says Ruginski. “There is a shortage of people who can do cyber-related jobs. CyMOT is an avenue to up-skill and train a talent base positioned to fill those gaps in the workforce.” </p>
    
    
    
    <p>After getting its start with implementation in Chicago, CyMOT has attracted the attention of Maryland state agencies, such as the Department of Commerce, and has been recognized by leaders in manufacturing, such as the Regional Manufacturing Institute of Maryland (RMI). UMBC was named as one of RMI’s Champions of Maryland Manufacturing at its <a href="https://rmiofmaryland.com/2022-maryland-manufacturing-celebration-november-17/" rel="nofollow external" class="bo">2022 Maryland Manufacturing Celebration</a>, held earlier this fall. </p>
    
    
    
    <img src="https://umbc.edu/wp-content/uploads/2022/12/Donna-Ruginski-and-Nilanjan-Banerjee-UMBC-Nov-17-2022-1200x900.jpg" alt='Two smiling people stand, holding awards, in front of a sign that reads, "RMI Regional Manufacturing Institute of Maryland Champions of Maryland Manufacturing 2022"' width="774" height="580" style="max-width: 100%; height: auto;">Donna Ruginski and Nilanjan Banerjee accepting an executive citation at RMI’s 2022 Maryland Manufacturing Celebration. (Image courtesy of Donna Ruginski)
    
    
    
    <p>On behalf of UMBC, Banerjee and Ruginski accepted an executive citation in recognition of CyMOT’s contributions to Maryland’s manufacturing industry.</p>
    
    
    
    <p>“It is a great honor to be awarded an RMI Champions award,” says Banerjee. “The work around cybersecurity training and research performed at UMBC is having a true impact on growing the workforce and digitizing the regional manufacturing ecosystem, and the award is testimony to that fact.”</p>
    </div>
]]>
</Body>
<Summary>UMBC researchers designed the Cybersecurity for Manufacturing Operational Technology (CyMOT) program to help manufacturing professionals grow their cybersecurity skills, protecting the sector from...</Summary>
<Website>https://umbc.edu/stories/cyber-training-for-manufacturing-workers/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/129709/guest@my.umbc.edu/b15444f410a34ca8753b0ffbcc6048b4/api/pixel</TrackingUrl>
<Tag>coeit</Tag>
<Tag>csee</Tag>
<Tag>cybersecurity</Tag>
<Tag>feature</Tag>
<Tag>news</Tag>
<Tag>research</Tag>
<Tag>science-and-tech</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>3</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Fri, 09 Dec 2022 13:44:05 -0500</PostedAt>
<EditAt>Fri, 09 Dec 2022 13:44:05 -0500</EditAt>
</NewsItem>

<NewsItem contentIssues="true" id="128360" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/128360">
<Title>Non-Linear Paths to Leadership</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2022/10/image3-150x150.jpeg" alt="A young man with glasses stands with his arm around an older woman" style="max-width: 100%; height: auto;">
    <p><strong>Francisco Cartagena </strong>describes his academic journey as unorthodox. Now an employee for the City of Gaithersburg, Cartagena started his educational path as an undocumented student. While charting numerous challenges, Cartagena ’19, political science, M.P.S. ’22, cybersecurity, also found ample opportunities for growth along the way, becoming an effective leader of social change at UMBC at The Universities at Shady Grove.</p>
    
    
    
    <p>Cartagena arrived with his family from El Salvador as a preteen. In 2009, he graduated from high school and set out to Montgomery College to pursue his associate’s degree in general studies—a goal that would take him a decade to accomplish because of his legal status. There, Cartagena joined the college’s Latino Student Union and together they advocated for the Maryland Dream Act—a statute that would allow undocumented high school students to pay for in-state college tuition.</p>
    
    
    
    <p>“That experience really exposed me to the political science environment and how policy, with momentum, people, and activism, can actually be changed,” says Cartagena, who hopes eventually to leverage his role in local government to share the message that there are many attainable pathways to and through higher education.</p>
    
    
    
    <h4>Finding his momentum</h4>
    
    
    
    <p>Prior to the Maryland Dream Act’s passing in 2012, Cartagena was paying the international student rate for community college classes. To him, pursuing a bachelor’s degree seemed like a faraway dream.</p>
    
    
    
    <p>“There were some instances when I couldn’t attend school or when I could only attend one class,” reflects Cartagena. “But it gave me that momentum to say, ‘I’m just going to keep at it.’”</p>
    
    
    
    <div>
    <img width="1200" height="800" src="https://umbc.edu/wp-content/uploads/2022/10/image2-1200x800.jpeg" alt="A man wearing glasses and a suit smiles at the camera." style="max-width: 100%; height: auto;">Francisco Cartagena<div>
    <p>At Montgomery College, Cartagena learned about the UMBC-Shady Grove campus and its political science program. As a full-time working adult, he believed that UMBC-Shady Grove would be a good fit. With an extra push from his wife <strong>Cora Trelles Cartagena ’12, social work</strong>, Cartagena reached out to <strong>Sunil Dasgupta</strong>, political science program director and professor at UMBC-Shady Grove, to find out more.</p>
    </div>
    </div>
    
    
    
    <p>To Cartagena’s surprise, Dasgupta asked a question that would sell him on applying: “Why do you think you can complete this program?” Motivated by the challenge, Cartagena pushed forward and eventually proved that he would do more than succeed—he would lead.</p>
    
    
    
    <p>“Francisco is somebody that intuitively knew the importance of politics in transforming and changing our lives,” says Dasgupta. “I think part of the reason that happens is because he comes from an immigrant family. When you’re in that position, you quickly realize you have to master this if you want to help yourself, your family, and your community.”</p>
    
    
    
    <h4>An uplifting environment</h4>
    
    
    
    <p>Cartagena saw The Universities at Shady Grove (USG) as a place to practice his role in politics. As one of two students representing UMBC on the Student Government Association’s executive board, he learned more about the funding process at USG, the development of programs on campus, and the ins-and-outs of university partnerships.</p>
    
    
    
    <p>“When you have an environment with multiple people from different schools, you can truly see the different backgrounds, their intent, and how people process things,” Cartagena says.</p>
    
    
    
    <img width="533" height="640" src="https://umbc.edu/wp-content/uploads/2022/10/image0.jpeg" alt="Four smiling people in tennis apparel stand in a semicircle, holding their clubs in front of them." style="max-width: 100%; height: auto;">From left to right: Anne Khademian, USG Executive Director; Cartagena; Crystal Townsend, President &amp; CEO of Healthcare Initiative Foundation; Kevin Beverly, Chair of the USG Board of Advisors.
    
    
    
    <p>When Cartagena attended USG’s job fair and spotted a table for Congressman Jamie Raskin’s office staffed by a fellow Latina, he saw a vision for his future. “At the time, a career in government or interning for a government official was so far-fetched, whether because of my status or my prior experiences. It was something I would just dream of,” explains Cartagena, who wound up spending the summer splitting his internship between Raskin’s Rockville office and his congressional office on the Hill—two experiences that propelled his career in government.</p>
    
    
    
    <p>“I still pinch myself because I’m a first-generation immigrant who came here from El Salvador with my parents…To be able to represent the county I grew up in—it was a bunch of mixed feelings that were finally culminating into something very positive,” says Cartagena.</p>
    
    
    
    <p>In 2018, Cartagena started with a role in the City of Gaithersburg’s human resources department and in 2021, transitioned to his current role as an I.T. project manager. Now, he oversees applications, business needs from different departments, and processes in the technology sector.</p>
    
    
    
    <h4>Continuing to lead</h4>
    
    
    
    <p>In 2019, as a master’s student studying cybersecurity at UMBC-Shady Grove, Cartagena continued his ongoing involvement on campus, joining the Graduate School Council and USG’s Advisory Board.</p>
    
    
    
    <p>During his final year in the program, Cartagena received a phone call from Dasgupta, who was creating an interactive bot to help Maryland voters identify political candidates most aligned with their values. He hoped that the bot, along with his podcast, <a href="https://ihppod.libsyn.com/" rel="nofollow external" class="bo">I Hate Politics</a>, would serve as informative tools. But realizing that a significant portion of the county was Spanish speaking, he enlisted Cartagena’s help.</p>
    
    
    
    <p>“The first person I called was Francisco. And it wasn’t a small job; it was pages and pages of translation,” Dasgupta says, adding that they only had about a couple of weeks to complete the project before elections began. Still, Cartagena took on the translation task without hesitation.</p>
    
    
    
    <img src="https://umbc.edu/wp-content/uploads/2022/10/image1-1200x900.jpeg" alt="" width="900" height="675" style="max-width: 100%; height: auto;">Cartagena and the USG Undergrad and Graduate Student Councils attend the State of Maryland House Appropriations meeting to advocate for the funding of USG by the State.
    
    
    
    <p>“That kind of collaboration uplifts UMBC and the community,” notes Dasgupta. “We continue to work with our students and alumni, and those interactions are very revitalizing. We find meaning through those relationships.”</p>
    
    
    
    <p>Cartagena notes he wouldn’t have made it this far without the resources and opportunities he found at UMBC-Shady Grove. “If there was a change I could recommend, it would be showing students and adult learners that there are other pathways for you to get that Ph.D., get that bachelor’s, or get that associate degree,” says Cartagena. “I think oftentimes students are afraid; it’s an investment of money and time, and you don’t know if you’re going to make it through…but you will find your niche if you stick it out.”</p>
    </div>
]]>
</Body>
<Summary>Francisco Cartagena describes his academic journey as unorthodox. Now an employee for the City of Gaithersburg, Cartagena started his educational path as an undocumented student. While charting...</Summary>
<Website>https://umbc.edu/stories/non-linear-paths-to-leadership/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/128360/guest@my.umbc.edu/b123bad86a3a147da7d64e0596278539/api/pixel</TrackingUrl>
<Tag>alumni</Tag>
<Tag>cybersecurity</Tag>
<Tag>magazine</Tag>
<Tag>politicalscience</Tag>
<Tag>shadygrove</Tag>
<Tag>universities-at-shady-grove</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Mon, 10 Oct 2022 16:05:54 -0400</PostedAt>
<EditAt>Mon, 10 Oct 2022 16:05:54 -0400</EditAt>
</NewsItem>

<NewsItem contentIssues="false" id="127239" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/127239">
<Title>UMBC&#8217;s Anupam Joshi, cybersecurity innovator, to expand leadership impact as 2022&#8211;23 ACE Fellow</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2020/02/Anupam-Joshi-5815-1024x683-1-150x150.jpg" alt="Portrait of man in a dress shirt with arm on a staircase railing." style="max-width: 100%; height: auto;">
    <p><strong>Anupam Joshi</strong>, a professor focused on both high-impact computing research and expanding access to computer science and cybersecurity education, has been named a <a href="https://www.acenet.edu/News-Room/Pages/ACE-Names-46-Emerging-Leaders-to-Fellows-Program.aspx" rel="nofollow external" class="bo">2022–23 American Council on Education (ACE) Fellow</a>.</p>
    
    
    
    <p><a href="https://cybersecurity.umbc.edu/anupam-joshi/" rel="nofollow external" class="bo">Joshi is the Oros Family Professor</a> and chair of computer science and electrical engineering at UMBC and director of <a href="https://cybersecurity.umbc.edu/" rel="nofollow external" class="bo">UMBC’s Center for Cybersecurity</a>. He will spend the coming academic year with <a href="http://www.usmd.edu" rel="nofollow external" class="bo">University System of Maryland</a> (USM) leaders, shadowing both USM Chancellor Jay A. Perman and Bruce Jarrell, president of the <a href="https://www.umaryland.edu/" rel="nofollow external" class="bo">University of Maryland, Baltimore</a> (UMB). </p>
    
    
    
    <p>UMBC has a strong history of leaders participating in the <a href="https://www.acenet.edu/Programs-Services/Pages/Professional-Learning/ACE-Fellows-Program.aspx" rel="nofollow external" class="bo">ACE Fellows program</a>, an intensive mentorship program that has prepared faculty, staff, and administrators for senior positions in college and university leadership since it began in 1965. More than 80 percent of the program’s 2,500 past Fellows have gone on to serve as chief executive officers, chief academic officers, other cabinet-level positions, or deans following their fellowship.</p>
    
    
    
    <p>“The ACE Fellows program embodies ACE’s goal of enriching the capacity of agile leaders to problem-solve and innovate, and it fuels the expansion of a talented and diverse higher education leadership pipeline,” said ACE President Ted Mitchell. “Fellows continue to excel in prominent leadership roles, and the potential of this new cohort to bring strong leadership to institutions across America greatly excites me.”</p>
    
    
    
    <h4>Focus on innovating institutions</h4>
    
    
    
    <p>Following a rigorous application process, ACE selected 46 Fellows this year from colleges and universities across the United States. Throughout the year, these Fellows will observe and work with senior leaders at their host institution, attend decision-making meetings, and focus on issues of interest. They will also conduct projects of pressing concern for their home institutions, with the goal of returning after their fellowship year prepared to guide positive change.</p>
    
    
    
    <p>“I am thrilled and honored to be mentored by two stalwarts of higher education in Chancellor Perman and President Jarrell,” Joshi says. “I look forward to learning from these leaders and working together to make a difference for the students in USM universities. I thank President Emeritus Hrabowski, President Sheares Ashby, and Provost Rous at UMBC for nominating me for this opportunity and their support.”</p>
    
    
    
    <img width="1200" height="800" src="https://umbc.edu/wp-content/uploads/2022/09/UMBC-Hogan-visit18-7804-1200x800.jpg" alt='Man in professional attire (Anupam Joshi) presents information that is shown on a very large screen behind him. The screen reads, "UMBC at Work."' style="max-width: 100%; height: auto;">Anupam Joshi presents UMBC’s economic impact metrics and workforce data to Maryland state leaders. (Marlayna Demond ’11/UMBC)
    
    
    
    <h4>Leadership trajectory</h4>
    
    
    
    <p>Joshi obtained a B.Tech degree from the Indian Institute of Technology (IIT) Delhi in 1989, and a master’s and Ph.D. from Purdue University in 1991 and 1993, respectively. He has published more than 275 technical papers, has been granted nine patents and obtained research support from a variety of federal and industrial sources. In 2014 he was named a Fellow of the Institute of Electrical and Electronics Engineers, or <a href="https://www.ieee.org/" rel="nofollow external" class="bo">IEEE</a>.</p>
    
    
    
    <p>As chair, Joshi leads one of UMBC’s largest departments. There he has overseen a near doubling of student enrollment at the graduate level and a 50% growth rate at the undergraduate level, accompanied by an increase in student body diversity. </p>
    
    
    
    <p>He has worked with partners in the UMBC Office of Institutional Advancement to raise funds supporting research from such industry partners as Northrop Grumman, GE, and Cisco. As a result of these efforts and collaboration with Jack Suess, UMBC’s chief information officer and vice president of information technology, the state recently announced the <a href="https://umbc.edu/stories/umbc-state-of-maryland-launch-maryland-institute-for-innovative-computing-at-cyber-summit/" rel="nofollow external" class="bo">creation of a Maryland Institute for Innovative Computing at UMBC</a>. </p>
    
    
    
    <img width="1200" height="800" src="https://umbc.edu/wp-content/uploads/2022/09/Professional-Fellows-luncheon2020-4994-1200x800.jpg" alt="Several people in professional attire sit at tables in a room. Focus is on one man who is smiling." style="max-width: 100%; height: auto;">Anupam Joshi celebrates with colleagues at an event for UMBC faculty named fellows of professional societies. (Marlayna Demond ’11/UMBC)
    
    
    
    <p>Joshi directs the Center for Cybersecurity, which brings together scholarship and research in cybersecurity from computer science, information systems, social sciences, humanities, public policy, and natural sciences. In this role, he serves on the <a href="https://msa.maryland.gov/msa/mdmanual/26excom/html/10cy.html" rel="nofollow external" class="bo">Maryland Cybersecurity Council</a>. </p>
    
    
    
    <p>Additionally, Joshi directs <a href="https://cybersecurity.umbc.edu/cyberscholars/" rel="nofollow external" class="bo">UMBC’s Cyber Scholars Program</a>, a joint effort between the Center for Cybersecurity and <a href="https://cwit.umbc.edu/" rel="nofollow external" class="bo">UMBC’s Center for Women in Technology</a>. This program is focused on supporting a diverse next generation of leaders in cybersecurity and computing.</p>
    
    
    
    <p>At the conclusion of the fellowship year, Joshi will return to these leadership roles with new knowledge and skills to expand UMBC’s work in innovative ways, supported by a network of emerging and longstanding university leaders across the nation.</p>
    
    
    
    <hr>
    
    
    
    <hr>
    
    
    
    <p><em>This UMBC News story draws from an </em><a href="https://www.usmd.edu/newsroom/news/2266" rel="nofollow external" class="bo"><em>USM press release (8/31/2022).</em></a><em> Learn more about ACE through stories on UMBC’s prior fellows, such as </em><a href="https://umbc.edu/stories/umbcs-timothy-nohe-brings-an-artists-perspective-to-prestigious-ace-fellowship/" rel="nofollow external" class="bo"><em>Tim Nohe</em></a><em>, visual arts; </em><a href="https://umbc.edu/stories/umbc-supports-emerging-higher-ed-leaders-through-ace-fellows-program/" rel="nofollow external" class="bo"><em>Kate Tracy</em></a><em> M.A. ‘01, Ph.D. ‘03, psychology; </em><a href="https://umbc.edu/sarah-shin-named-american-council-on-education-fellow-for-2017-18/" rel="nofollow external" class="bo"><em>Sarah Shin</em></a><em>, education; and </em><a href="https://umbc.edu/anne-brodsky-named-american-council-on-education-fellow-for-2016-17/" rel="nofollow external" class="bo"><em>Anne Brodsky</em></a><em>, psychology, among others. UMBC President Emeritus Freeman Hrabowski currently serves as the </em><a href="https://umbc.edu/stories/umbc-president-freeman-hrabowski-to-continue-higher-ed-leadership-as-ace-centennial-fellow/" rel="nofollow external" class="bo"><em>inaugural ACE Centennial Fellow</em></a><em>.</em></p>
    </div>
]]>
</Body>
<Summary>Anupam Joshi, a professor focused on both high-impact computing research and expanding access to computer science and cybersecurity education, has been named a 2022–23 American Council on...</Summary>
<Website>https://umbc.edu/stories/umbcs-anupam-joshi-cybersecurity-innovator-to-expand-leadership-impact-as-2022-23-ace-fellow/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/127239/guest@my.umbc.edu/0fe2b1e6a43a36243f2b4734b5f49b70/api/pixel</TrackingUrl>
<Tag>coeit</Tag>
<Tag>csee</Tag>
<Tag>cyberscholars</Tag>
<Tag>cybersecurity</Tag>
<Tag>majoraward</Tag>
<Tag>news</Tag>
<Tag>science-and-tech</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Fri, 02 Sep 2022 09:36:18 -0400</PostedAt>
<EditAt>Fri, 02 Sep 2022 09:36:18 -0400</EditAt>
</NewsItem>

<NewsItem contentIssues="false" id="127211" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/127211">
<Title>Did Twitter ignore basic security measures? A cybersecurity expert explains a whistleblower&#8217;s claims</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2022/09/ezgif.com-gif-maker-150x150.jpg" alt="A man with glasses stares through a window pensively" style="max-width: 100%; height: auto;">
    <p><em>By <a href="https://theconversation.com/profiles/richard-forno-173226" rel="nofollow external" class="bo">Richard Forno</a>, Principal Lecturer,Computer Science and Electrical Engineering</em>, <em><a href="https://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">UMBC</a></em></p>
    
    
    
    <p>Twitter’s former security chief, Peiter “Mudge” Zatko, <a href="https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/" rel="nofollow external" class="bo">filed a whistleblower complaint</a> with the Securities and Exchange Commission in July 2022, accusing the microblogging platform company of serious security failings. The accusations amplified the ongoing drama of Twitter’s <a href="https://theconversation.com/elon-musks-plans-for-twitter-could-make-its-misinformation-problems-worse-181923" rel="nofollow external" class="bo">potential sale to Elon Musk</a>.</p>
    
    
    
    <p>Zatko spent decades as an <a href="https://www.washingtonpost.com/technology/2022/08/23/peiter-mudge-zatko-twitter-whistleblower/" rel="nofollow external" class="bo">ethical hacker, private researcher, government adviser and executive</a> at some of the most prominent internet companies and government offices. He is practically a legend in the cybersecurity industry. Because of <a href="https://slate.com/technology/2022/08/twitter-whistleblower-peiter-mudge-zatko-elon-musk-bots.html" rel="nofollow external" class="bo">his reputation</a>, when he speaks, people and governments normally listen – which underscores the seriousness of his complaint against Twitter.</p>
    
    
    
    <p>As a former cybersecurity industry practitioner and current <a href="http://www.csee.umbc.edu/%7Erforno/" rel="nofollow external" class="bo">cybersecurity researcher</a>, I believe that Zatko’s most damning accusations center around Twitter’s alleged failure to have a solid cybersecurity plan to protect user data, deploy internal controls to guard against insider threats and ensure the company’s systems were current and properly updated.</p>
    
    
    
    <p>Zatko also alleged that Twitter executives were less than forthcoming about cybersecurity incidents on the platform when briefing both regulators and the company’s board of directors. He claimed that Twitter <a href="https://abcnews.go.com/Business/whistleblower-alleges-twitter-deceived-regulators-security-spam-twitter/story?id=88748290" rel="nofollow external" class="bo">prioritized user growth over reducing spam</a> and other unwanted content that poisoned the platform and detracted from the user experience. His complaint also expressed concerns about the company’s business practices. </p>
    
    
    
    <div>
    <div><div class="embed-container"><iframe src="https://www.youtube.com/embed/7OD9T5bX2LU?feature=oembed" frameborder="0" webkitallowfullscreen="webkitAllowFullScreen" mozallowfullscreen="mozallowfullscreen" allowfullscreen="allowFullScreen">[Video]</iframe></div></div>
    </div>
    <em>CNN interviewed Twitter whistleblower Peiter “Mudge” Zatko.</em>
    
    
    
    <h2>Alleged security failures</h2>
    
    
    
    <p>Zatko’s allegations paint a disturbing picture of not only the state of Twitter’s cybersecurity as a social media platform, but also the security consciousness of Twitter as a company. Both points are relevant given Twitter’s position in global communications and the ongoing struggle against <a href="https://cops.usdoj.gov/RIC/Publications/cops-w0741-pub.pdf" rel="nofollow external" class="bo">online extremism</a> and <a href="https://www.science.org/content/article/fake-news-spreads-faster-true-news-twitter-thanks-people-not-bots" rel="nofollow external" class="bo">disinformation</a>.</p>
    
    
    
    <p>Perhaps the most significant of Zatko’s allegations is his claim that nearly half of Twitter’s employees have direct access to user data and Twitter’s source code. Time-tested cybersecurity practices don’t allow so many people with this level of <a href="https://www.ssh.com/academy/iam/root-user-account#what-is-a-root-user?" rel="nofollow external" class="bo">“root” or “privileged” permission</a> to access sensitive systems and data. If true, this means that Twitter could be ripe for exploitation either from within or by outside adversaries assisted by people on the inside who may not have been properly vetted.</p>
    
    
    
    <p>Zatko also alleges that Twitter’s data centers may not be as secure, resilient or reliable as the company claims. He estimated that <a href="https://twitter.com/kimzetter/status/1562038809646092289" rel="nofollow external" class="bo">nearly half</a> of Twitter’s 500,000 servers around the world lack basic security controls such as running up-to-date and vendor-supported software or encrypting the user data stored on them. He also noted that the company’s lack of a robust business continuity plan means that should several of its data centers fail due to a cyber incident or other disaster, it could lead to an “<a href="https://www.cnn.com/2022/08/24/tech/twitter-whistleblower-takeaways/index.html" rel="nofollow external" class="bo">existential company ending event</a>.”</p>
    
    
    
    <p>These are just some of the claims made in Zatko’s complaint. If his allegations are true, Twitter has failed Cybersecurity 101.</p>
    
    
    
    <h2>Concerns over foreign government interference</h2>
    
    
    
    <p>Zatko’s allegations might also present a national security concern. Twitter has been used to spread disinformation and propaganda in recent years during global events like the <a href="https://help.twitter.com/en/rules-and-policies/medical-misinformation-policy" rel="nofollow external" class="bo">pandemic</a> and <a href="https://blog.twitter.com/en_us/topics/company/2017/Update-Russian-Interference-in-2016--Election-Bots-and-Misinformation" rel="nofollow external" class="bo">national elections</a>.</p>
    
    
    
    <p>For example, Zatko’s report stated that the Indian government forced Twitter to hire government agents, who would have access to vast amounts of Twitter’s sensitive data. In response, India’s at-times hostile neighbor <a href="https://thewire.in/south-asia/pakistan-concern-against-india-twitter-whistleblower-allegations" rel="nofollow external" class="bo">Pakistan accused</a> India of trying to infiltrate the security system of Twitter “in an effort to curb fundamental freedoms.”</p>
    
    
    
    <p>Given Twitter’s global footprint as a communications platform, other nations such as Russia and China could require the company to hire its own government agents as a condition of allowing the company to operate in their country. Zatko’s allegations about Twitter’s internal security raise the possibility of criminals, activists, hostile governments or their supporters seeking to exploit Twitter’s systems and user data by recruiting or blackmailing its employees may well present a <a href="https://www.fbi.gov/investigate/cyber/partnerships" rel="nofollow external" class="bo">national security concern</a>.</p>
    
    
    
    <p>Worse, Twitter’s own information about its users, their interests and who they follow and interact with on the platform could facilitate targeting for <a href="https://www.nytimes.com/2022/08/31/technology/pew-misinformation-major-threat.html" rel="nofollow external" class="bo">disinformation campaigns</a>, blackmail or other nefarious purposes. Such foreign targeting of prominent companies and their employees has been a major counterintelligence worry in the national security community for decades.</p>
    
    
    
    <a href="https://images.theconversation.com/files/482154/original/file-20220831-4904-4d9zno.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=1000&amp;fit=clip" rel="nofollow external" class="bo"><img src="https://images.theconversation.com/files/482154/original/file-20220831-4904-4d9zno.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip" alt="a line of men wearing beige berets in the foreground holds back a crowd of young men shouting and waving banners" style="max-width: 100%; height: auto;"></a><em>Opposition party members in India protest Twitter’s temporary ban of their leader. The whistleblower’s allegations include Twitter acquiescing to Indian government demands that the company employ government agents. <a href="https://www.gettyimages.com/detail/news-photo/indian-youth-congress-party-workers-hold-placards-during-a-news-photo/1234588037" rel="nofollow external" class="bo">Anadolu Agency (Getty Images)</a></em>
    
    
    
    <h2>Fallout</h2>
    
    
    
    <p>Whatever the outcome of Zatko’s complaint in Congress, the SEC or other federal agencies, it already is <a href="https://www.nytimes.com/2022/08/30/business/musk-twitter-legal.html" rel="nofollow external" class="bo">part of Musk’s latest legal filings</a> as he tries to back out of his purchase of Twitter.</p>
    
    
    
    <p>Ideally, in light of these disclosures, Twitter will take corrective action to improve the company’s cybersecurity systems and practices. A good first step the company could take is reviewing and limiting who has root access to its systems, source code and user data to the minimum number necessary. The company should also ensure that its production systems are kept current and that it is effectively prepared to contend with any type of emergency situation without significantly disrupting its global operations.</p>
    
    
    
    <p>From a broader perspective, Zatko’s complaint underscores the critical and sometimes uncomfortable role cybersecurity plays in modern organizations. Cybersecurity professionals like Zatko understand that no company or government agency likes publicity for cybersecurity problems. They tend to think long and hard about whether and how to raise cybersecurity concerns like these – and what the potential ramifications might be. In this case, <a href="https://www.cnn.com/2022/08/23/tech/twitter-whistleblower-peiter-zatko-security/index.html" rel="nofollow external" class="bo">Zatko says his disclosures</a> reflect “the job he was hired to do” as head of security for a social media platform that he says “is critical to democracy.”</p>
    
    
    
    <p>For companies like Twitter, bad cybersecurity news often results in a public relations nightmare that could affect share price and their standing in the marketplace, not to mention attract the interest of regulators and lawmakers. For governments, such revelations can lead to a lack of trust in the institutions created to serve society, in addition to potentially creating distracting political noise.</p>
    
    
    
    <p>Unfortunately, how cybersecurity problems are discovered, disclosed and handled remains a difficult and sometimes controversial process, with no easy solution both for cybersecurity professionals and today’s organizations.</p>
    
    
    
    
    
    
    
    <p><a href="https://theconversation.com/profiles/richard-forno-173226" rel="nofollow external" class="bo">Richard Forno</a>, Principal Lecturer in Computer Science and Electrical Engineering, <em><a href="https://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">University of Maryland, Baltimore County</a></em></p>
    
    
    
    <p>This article is republished from <a href="https://theconversation.com" rel="nofollow external" class="bo">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/did-twitter-ignore-basic-security-measures-a-cybersecurity-expert-explains-a-whistleblowers-claims-189668" rel="nofollow external" class="bo">original article</a>.</p>
    </div>
]]>
</Body>
<Summary>By Richard Forno, Principal Lecturer,Computer Science and Electrical Engineering, UMBC      Twitter’s former security chief, Peiter “Mudge” Zatko, filed a whistleblower complaint with the...</Summary>
<Website>https://umbc.edu/stories/did-twitter-ignore-basic-security-measures-a-cybersecurity-expert-explains-a-whistleblowers-claims/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/127211/guest@my.umbc.edu/9cc4c5bdd3298f242ddda8e345aab860/api/pixel</TrackingUrl>
<Tag>coeit</Tag>
<Tag>csee</Tag>
<Tag>cybersecurity</Tag>
<Tag>discovery</Tag>
<Tag>magazine</Tag>
<Tag>the-conversation</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Thu, 01 Sep 2022 13:03:04 -0400</PostedAt>
<EditAt>Thu, 01 Sep 2022 13:03:04 -0400</EditAt>
</NewsItem>

<NewsItem contentIssues="true" id="126686" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/126686">
<Title>UMBC students, educators, and researchers advance Maryland through innovative computing partnership</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <img width="150" height="150" src="https://umbc.edu/wp-content/uploads/2022/08/Nadja-Franklin-MDOT22-8924-150x150.jpg" alt="" style="max-width: 100%; height: auto;">
    <p>In early 2022, <strong>Nadja Franklin</strong> ‘23 was exploring summer opportunities through the <a href="https://careers.umbc.edu/" rel="nofollow external" class="bo">UMBC Career Center</a> when she heard about a chance to connect with tech internships at Maryland’s state agencies. As a business technology administration major, her interest was piqued. She arrived at the on-campus internship event with résumé in hand, ready to discuss her skills, and her preparation and enthusiasm paid off. </p>
    
    
    
    <p>The hiring event was hosted by the <a href="https://umbc.edu/stories/umbc-state-of-maryland-launch-maryland-institute-for-innovative-computing-at-cyber-summit/" rel="nofollow external" class="bo">Maryland Institute for Innovative Computing</a> (MIIC) to help state agencies expand their technical talent pipeline through intern recruitment. The MIIC is a collaboration between the <a href="https://www.usmd.edu/" rel="nofollow external" class="bo">University System of Maryland</a> and partners in the public and private sectors, launched in 2021. Administered by UMBC, the MIIC addresses workforce challenges related to computing and analytics in state agencies. Students at colleges and universities across Maryland are eligible to apply for internships through the MIIC, connecting skilled students with state employers seeking fresh tech talent.</p>
    
    
    
    
    
    
    
    <div>
    	<blockquote>
    		
    		<div>	
    			<div>
    				<div>“</div>
    			</div>
    
    			<div>
    				<p>“The State of Maryland has realized tremendous value from the partnership with UMBC through the technology internship program. Beyond the contribution of the students during their internship, many have gone on to become permanent members of the team. This program helps to fill the workforce pipeline with qualified and talented workers, lessening the impact caused by the shortage of technology and cybersecurity workers.”</p>
    
    				
    
    				
    				<h3>Chip Stewart</h3>
    				<h4>Maryland’s State Chief Information Security Officer</h4> 						
    								</div>
    
    		</div>		
    	</blockquote>
    </div>
    
    
    
    
    
    
    
    
    
    
    <h4><strong>Talent meets opportunity</strong></h4>
    
    
    
    <p>The MIIC is continuously growing the pipeline of tech talent ready to support state agencies in the longer term, helping them run securely and efficiently. So far, in 2022, they’ve connected nearly 40 interns with opportunities at state agencies across Maryland, including the Department of Labor, Department of Information Technology, Department of Health, Department of Transportation and the Chief Data Office within the Governor’s Office.</p>
    
    
    
    <p>“The MIIC reflects Maryland’s dedication to ensuring our state agencies have the technical staffing and internal infrastructure they need,” explains <strong>Annie Weinschenk</strong>, program director of workforce initiatives in the UMBC Career Center. </p>
    
    
    
    <p>“With cyber crime on the rise, including attacks on government agencies, MIIC is helping to build a skilled workforce dedicated to service within the state of Maryland,” Weinschenk says. “MIIC internship areas range from data science, cybersecurity, and artificial intelligence, to geographic information systems at seven agencies across Maryland.”</p>
    
    
    
    <h4><strong>Prepared to succeed</strong></h4>
    
    
    
    <p>Franklin is a <a href="https://cwit.umbc.edu/tsite/" rel="nofollow external" class="bo">T-SITE Scholar</a> in <a href="https://cwit.umbc.edu/" rel="nofollow external" class="bo">UMBC’s Center for Women in Technology</a> who transferred to UMBC from the Community College of Baltimore County. At the MIIC event, she connected with the <a href="https://mdot.maryland.gov/pages/home.aspx" rel="nofollow external" class="bo">Maryland Department of Transportation </a>(MDOT) about projects that would draw on her interests and experience, and she realized the opportunity could be a great match.</p>
    
    
    
    <p>Afterward, she quickly completed her application for a project management internship in MDOT’s information technology department. She also accessed other Career Center resources to help her stand out as a top candidate, including interview prep with Weinschenk and Career Center Director <strong>Christine Routzahn</strong>.</p>
    
    
    
    <p>“Students come to their internship experiences with a variety of backgrounds, levels of experience, and majors,” says Weinschenk. “We work to make sure they put their best foot forward, so they can access these unique hands-on learning opportunities.” </p>
    
    
    
    <h4><strong>Meaningful connections</strong></h4>
    
    
    
    <p>Franklin’s primary project with MDOT involves radio frequency identification (RFID), tagging IT and non-IT assets for use in various projects across the agency. But she has particularly enjoyed the chance to meet with MDOT’s chief information officer and deputy chief information officer. She’s also had a chance to learn about the broad range of projects across MDOT, and how project management works, through supporting directors’ meetings. </p>
    
    
    
    <img width="1200" height="800" src="https://umbc.edu/wp-content/uploads/2022/08/Nadja-Franklin-MDOT22-8914-1200x800.jpg" alt='Student (an intern through the Maryland Institute for Innovative Computing) sits on concrete sign in front of an office building. The sign reads "MDOT: Maryland Department of Transportation" and "Harry R. Hughes Building" with the "es" in "Hughes" not visible.' style="max-width: 100%; height: auto;">Nadja Franklin. (Marlayna Demond ’11/UMBC)
    
    
    
    <p>Franklin also drew on her writing skills and creativity to help develop scripts for MDOT training videos, and she enjoyed a unique chance to participate in the video filming and production process. </p>
    
    
    
    <p>Beyond learning new skills, her favorite aspect of the internship has been MDOT’s inclusive, welcoming environment.</p>
    
    
    
    <h4><strong>K-12 and higher ed partnerships</strong></h4>
    
    
    
    <p>While Franklin came to UMBC interested in a career in tech, that’s not the case for many students who have the talent and skills to succeed in tech fields. With this in mind, the MIIC has also focused on expanding K-12 initiatives, to help prepare students earlier on for these high-demand careers, particularly in cybersecurity.</p>
    
    
    
    <p>Earlier this year, Governor Larry Hogan announced the launch of the Maryland Cyber Range for Elevating Workforce and Education, operated by the MIIC. This $1.2 million initiative will expand cybersecurity education and training through collaboration with the Maryland Center for Computing Education (MCCE), Virginia Tech U.S. Cyber Range, and the nonprofit Teach Cyber.</p>
    
    
    
    <p>This partnership will include initiatives at all educational levels, from K-12 through higher education and workforce training. The U.S. Cyber Range will provide access to a high quality simulated environment for teachers and students to learn cybersecurity. </p>
    
    
    
    <p>Overall, this collaborative effort will enable Maryland to continue to grow and strengthen the state’s cybersecurity education infrastructure, explains <strong>Jack Suess</strong>, UMBC’s vice president of information technology and chief technology officer. </p>
    
    
    
    <h4><strong>Innovating cybersecurity education </strong></h4>
    
    
    
    <p>A leader in cybersecurity education, UMBC is also advancing the field in other ways, complementing the work of the MIIC. For example, <strong>Alan T. Sherman</strong>, professor of computer science, recently received more than $260,000 of a $500,000 grant from the National Science Foundation (NSF) to study and improve how cybersecurity is taught at the U.S. Naval Academy and U.S. Military Academy. </p>
    
    
    
    <p>The project, Examining Pedagogy in Cybersecurity (EPIC), is collaborative with the University of Illinois Urbana-Champaign and University of Minnesota Duluth, and is funded through NSF’s Secure and Trustworthy Computing (SaTC) program. Because the academies teach cybersecurity to all first-year students, EPIC offers a large-scale opportunity to investigate how simulation-based teaching and learning affects different student populations.</p>
    
    
    
    <p>In the first phase of the research, Sherman and his collaborators—including computer science Ph.D. student <strong>Andew Slack</strong> and <strong>Linda Oliva</strong>, assistant professor of education—will study how instructors at the academies structure and teach their cybersecurity courses. In the second phase, they will introduce active simulation-based learning exercises and pedagogies and assess their effectiveness. </p>
    
    
    
    <p>UMBC’s championship-winning Cyberdawgs cyberdefense team will help adapt and improve learning materials. As one quantitative measure of the new pedagogy’s effectiveness, EPIC will assess students’ conceptual understanding using the Cybersecurity Concept Inventory (CCI), developed by Sherman and his team. </p>
    
    
    
    <h4><strong>Benefits for Maryland</strong></h4>
    
    
    
    <p>MIIC initiatives continue to expand in new directions. In research, <a href="https://www.hilltopinstitute.org/" rel="nofollow external" class="bo">The Hilltop Institute at UMBC</a> is receiving funding to bring together health data related to opioid addiction from different state sources to more accurately identify patients’ risks for relapse. Like the MIIC’s educational initiatives, this work demonstrates how innovations in computing can benefit Maryland and its residents.</p>
    </div>
]]>
</Body>
<Summary>In early 2022, Nadja Franklin ‘23 was exploring summer opportunities through the UMBC Career Center when she heard about a chance to connect with tech internships at Maryland’s state agencies. As...</Summary>
<Website>https://umbc.edu/stories/umbc-advances-maryland-through-innovative-computing-partnership/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/126686/guest@my.umbc.edu/677bb319e0fccaab53315b06228fb1bc/api/pixel</TrackingUrl>
<Tag>business-technology-administration</Tag>
<Tag>career-center</Tag>
<Tag>coeit</Tag>
<Tag>csee</Tag>
<Tag>cwit</Tag>
<Tag>cybersecurity</Tag>
<Tag>education</Tag>
<Tag>feature</Tag>
<Tag>information-systems</Tag>
<Tag>news</Tag>
<Tag>policy-and-society</Tag>
<Tag>rca-2</Tag>
<Tag>science-and-tech</Tag>
<Tag>tsite</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Wed, 03 Aug 2022 14:43:51 -0400</PostedAt>
<EditAt>Wed, 03 Aug 2022 14:43:51 -0400</EditAt>
</NewsItem>

<NewsItem contentIssues="false" id="119459" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/119459">
<Title>Local governments are attractive targets for hackers and are ill-prepared</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <p><em>By</em> <em><em><a href="https://theconversation.com/profiles/richard-forno-173226" rel="nofollow external" class="bo">Richard Forno</a>, principal lecturer, Computer Science and Electrical Engineering, <a href="https://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">UMBC</a></em></em></p>
    
    
    
    <p>President Joe Biden on March 21, 2022, warned that <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/statement-by-president-biden-on-our-nations-cybersecurity/" rel="nofollow external" class="bo">Russian cyberattacks on U.S. targets are likely</a>, though the government has not identified a specific threat. Biden urged the private sector: “Harden your cyber defenses immediately.”</p>
    
    
    
    <p>It is a costly fact of modern life that organizations from <a href="https://www.energy.gov/ceser/colonial-pipeline-cyber-incident" rel="nofollow external" class="bo">pipelines</a> and <a href="https://www.zdnet.com/article/ransomware-the-key-lesson-maersk-learned-from-battling-the-notpetya-attack/" rel="nofollow external" class="bo">shipping companies</a> to hospitals and any number of private companies are vulnerable to cyberattacks, and the threat of cyberattacks from Russia and other nations makes a bad situation worse. Individuals, too, <a href="https://theconversation.com/ukraine-conflict-brings-cybersecurity-risks-to-us-homes-businesses-177893" rel="nofollow external" class="bo">are at risk</a> from the current threat.</p>
    
    
    
    <p>Local governments, like schools and hospitals, are particularly <a href="https://www.recordedfuture.com/state-local-government-ransomware-attacks/" rel="nofollow external" class="bo">enticing “soft targets</a>” – organizations that lack the resources to defend themselves against routine cyberattacks, let alone a lengthy cyber conflict. For those attacking such targets, the goal is not necessarily financial reward but disrupting society at the local level.</p>
    
    
    
    <p>From issuing business licenses and building permits and collecting taxes to providing emergency services, clean water and waste disposal, the services provided by local governments entail an intimate and ongoing daily relationship with citizens and businesses alike. Disrupting their operations disrupts the heart of U.S. society by shaking confidence in local government and potentially endangering citizens.</p>
    
    
    
    <h2>In the crosshairs</h2>
    
    
    
    <p>Local governments have suffered <a href="https://theconversation.com/hackers-seek-ransoms-from-baltimore-and-communities-across-the-us-118089" rel="nofollow external" class="bo">successful cyberattacks</a> in recent years. These include attacks on targets ranging from <a href="https://www.nbcnews.com/news/us-news/hackers-have-taken-down-dozens-911-centers-why-it-so-n862206" rel="nofollow external" class="bo">911 call centers</a> to <a href="https://apnews.com/article/coronavirus-pandemic-technology-health-business-hacking-aecb37a35f3677e4f2cc62362a23defa" rel="nofollow external" class="bo">public school systems</a>. The consequences of a successful cyberattack against local government can be <a href="https://www.vox.com/recode/2019/5/21/18634505/baltimore-ransom-robbinhood-mayor-jack-young-hackers" rel="nofollow external" class="bo">devastating</a>.</p>
    
    
    
    <div>
    <a href="https://images.theconversation.com/files/454250/original/file-20220324-19-19c6cza.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=1000&amp;fit=clip" rel="nofollow external" class="bo"><img src="https://images.theconversation.com/files/454250/original/file-20220324-19-19c6cza.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip" alt="an ornate 19th-century building topped with a dome in a big city downtown" style="max-width: 100%; height: auto;"></a><em>A cyberattack on the city of Baltimore disrupted municipal services for weeks in 2019. <a href="https://newsroom.ap.org/detail/BaltimoreVirusAttack/14bfabf1b4aa444895f0e69a99cb48a4/photo" rel="nofollow external" class="bo">AP Photo/Patrick Semansky</a></em>
    </div>
    
    
    
    <p>I and other researchers at University of Maryland, Baltimore County have studied the cybersecurity preparedness of the United States’ <a href="https://www.governing.com/archive/number-of-governments-by-state.html" rel="nofollow external" class="bo">over 90,000 local government entities</a>. As part of our analysis, working with the <a href="https://icma.org/" rel="nofollow external" class="bo">International City/County Management Association</a>, we polled local government chief security officers about their cybersecurity preparedness. The <a href="https://www.wiley.com/en-us/Cybersecurity+and+Local+Government-p-9781119788287" rel="nofollow external" class="bo">results</a> are both expected and alarming.</p>
    
    
    
    <p>Among other things, the survey revealed that nearly one-third of U.S. local governments <a href="https://doi.org/10.1111/puar.13028" rel="nofollow external" class="bo">would be unable to tell</a> if they were under attack in cyberspace. This is unsettling; nearly one-third of local governments that did know whether they were under attack reported being attacked hourly, and nearly half at least daily.</p>
    
    
    
    <h2>Ill-equipped</h2>
    
    
    
    <p>Lack of sound IT practices, let alone effective cybersecurity measures, can make successful cyberattacks even more debilitating. Almost half of U.S. local governments reported that their IT policies and procedures were not in line with industry best practices.</p>
    
    
    
    <p>In many ways, local governments are <a href="https://theconversation.com/equifax-breach-is-a-reminder-of-societys-larger-cybersecurity-problems-84034" rel="nofollow external" class="bo">no different</a> from private companies in terms of the cybersecurity threats, vulnerabilities and management problems they face. In addition to those shared cybersecurity challenges, where local governments particularly struggle is in hiring and retaining the necessary numbers of qualified IT and cybersecurity staff with wages and workplace cultures that can compare with those of the private sector or federal government.</p>
    
    
    
    <p>Additionally, unlike private companies, local governments by their nature are limited by the need to comply with state policies, the political considerations of elected officials and the usual perils of government bureaucracy such as balancing public safety with the community’s needs and corporate interests. Challenges like these can hamper effective preparation for, and responses to, cybersecurity problems – especially when it comes to funding. In addition, much of the technology local communities rely on, such as power and water distribution, are subject to the dictates of the private sector, which has its own set of sometimes competing interests.</p>
    
    
    
    <p>Large local governments are better positioned to address cybersecurity concerns than smaller local governments. Unfortunately, like other soft targets in cyberspace, small local governments are much more constrained. This places them at greater risk of successful cyberattacks, including attacks that <a href="https://www.theguardian.com/technology/2017/oct/27/nhs-could-have-avoided-wannacry-hack-basic-it-security-national-audit-office" rel="nofollow external" class="bo">otherwise might have been prevented</a>. But the necessary, best-practice cybersecurity improvements that smaller cities and towns need often compete with the many other demands on a local community’s limited funds and staff attention.</p>
    
    
    
    <h2>Getting the basics right</h2>
    
    
    
    <p>Whether they are victimized by a war on the other side of the world, a hacktivist group promoting its <a href="https://www.theguardian.com/technology/2012/nov/22/anonymous-cyber-attacks-paypal-court" rel="nofollow external" class="bo">message</a> or a criminal group trying to extort payment, local governments in the U.S. are enticing targets. Artificial intelligence hacking tools and vulnerabilities introduced by the spread of smart devices and the growing interest in creating “<a href="https://www.nationalgeographic.org/article/smart-cities/" rel="nofollow external" class="bo">smart cities</a>” put local governments even more at risk.</p>
    
    
    
    <p>There’s no quick or foolproof fix to eliminate all cybersecurity problems, but one of the most important steps local governments can take is clear: Implement basic cybersecurity. Emulating the National Institute of Standards and Technology’s <a href="https://www.nist.gov/cyberframework" rel="nofollow external" class="bo">national cybersecurity framework</a> or other industry accepted best practices is a good start.</p>
    
    
    
    <p>I believe government officials, especially at the local level, should develop and apply the necessary resources and innovative technologies and practices to manage their cybersecurity risks effectively. Otherwise, they should be prepared to face the technical, financial and political consequences of failing to do so.</p>
    
    
    
    <p>*****</p>
    
    
    
    <p><em>Header image:  Hackers can disrupt local government services, like this library in Willmar, Texas. The town suffered a cyberattack in August 2019. <a href="https://newsroom.ap.org/detail/CyberAttacksCities/55163b1884304986b53bc189883efb6f/photo" rel="nofollow external" class="bo">AP Photo/Tony Gutierrez</a> </em></p>
    
    
    
    <p><em><a href="https://theconversation.com/profiles/richard-forno-173226" rel="nofollow external" class="bo">Richard Forno</a>, Principal Lecturer in Computer Science and Electrical Engineering, <a href="https://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">University of Maryland, Baltimore County</a></em></p>
    
    
    
    <p><em>This article is republished from <a href="https://theconversation.com" rel="nofollow external" class="bo">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/local-governments-are-attractive-targets-for-hackers-and-are-ill-prepared-179073" rel="nofollow external" class="bo">original article</a>.</em></p>
    </div>
]]>
</Body>
<Summary>By Richard Forno, principal lecturer, Computer Science and Electrical Engineering, UMBC      President Joe Biden on March 21, 2022, warned that Russian cyberattacks on U.S. targets are likely,...</Summary>
<Website>https://umbc.edu/stories/local-governments-are-attractive-targets-for-hackers-and-are-ill-prepared/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/119459/guest@my.umbc.edu/d8a57eaf01d6cceca31f400e66388fa8/api/pixel</TrackingUrl>
<Tag>csee</Tag>
<Tag>cybersecurity</Tag>
<Tag>discovery</Tag>
<Tag>magazine</Tag>
<Tag>the-conversation</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Mon, 28 Mar 2022 17:32:05 -0400</PostedAt>
<EditAt>Mon, 28 Mar 2022 17:32:05 -0400</EditAt>
</NewsItem>

<NewsItem contentIssues="false" id="119460" important="false" status="posted" url="https://my3.my.umbc.edu/groups/coeit-news-events/posts/119460">
<Title>Older Americans are given the wrong idea about online safety &#8211; here&#8217;s how to help them help themselves</Title>
<Body>
<![CDATA[
    <div class="html-content">
    <p><em>By <a href="https://theconversation.com/profiles/helena-m-mentis-1075210" rel="nofollow external" class="bo">Helena M. Mentis</a>, professor, Information Systems, <a href="https://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">UMBC</a> and <a href="https://theconversation.com/profiles/nora-mcdonald-1157126" rel="nofollow external" class="bo">Nora McDonald</a>, assistant professor, Information Technology, <a href="https://theconversation.com/institutions/university-of-cincinnati-1717" rel="nofollow external" class="bo">University of Cincinnati</a></em></p>
    
    
    
    <p>Recently, the U.S. Social Security Administration <a href="https://blog.ssa.gov/my-social-security-what-to-know-about-signing-up-or-signing-in/" rel="nofollow external" class="bo">sent out an email</a> to subscribers of its official blog explaining how to access social security statements online. Most people know to be suspicious of seemingly official emails with links to websites asking for credentials.</p>
    
    
    
    <p>But for older adults who are wary of the prevalence of scams targeting their demographic, such an email can be particularly alarming since they have been told that the SSA <a href="https://www.aarp.org/money/scams-fraud/info-2020/social-security-email.html#:%7E:text=Social%20Security%20will%20never%20send,in%20exchange%20for%20a%20payment." rel="nofollow external" class="bo">never sends emails</a>. From <a href="https://dl.acm.org/doi/10.1145/3465217" rel="nofollow external" class="bo">our research</a> designing <a href="https://dl.acm.org/doi/10.1145/3411764.3445071" rel="nofollow external" class="bo">cybersecurity safeguards</a> for older adults, we believe there is legitimate cause for alarm.</p>
    
    
    
    <p>This population has been schooled in a tactical approach to online safety grounded in fear and mistrust – even of themselves – and focused on specific threats rather than developing strategies that enable them to be online safely. Elders have been taught this approach by organizations they tend to trust, including <a href="https://www.aarp.org/about-aarp/info-2021/oats-senior-planet.html" rel="nofollow external" class="bo">nonprofits that teach older adults how to use technology</a>.</p>
    
    
    
    <p>These organizations promote a view of older adults as highly vulnerable while also encouraging them to take gratuitous risks in defending themselves. As <a href="https://scholar.google.com/citations?user=_VdWyEcAAAAJ&amp;hl=en" rel="nofollow external" class="bo">information technology</a> <a href="https://scholar.google.com/citations?user=u3BoLzgAAAAJ&amp;hl=en" rel="nofollow external" class="bo">researchers</a>, we believe it doesn’t need to be this way.</p>
    
    
    
    <h2>Older adults and online safety</h2>
    
    
    
    <p>Older adults may be at heightened risk of cybersecurity breaches and <a href="https://www.lifelock.com/learn/identity-theft-resources/seniors-victims-of-identity-theft" rel="nofollow external" class="bo">fraudulent behavior</a> because they lack experience with internet technology and represent a <a href="https://www.huffpost.com/entry/scams-older-adults_n_1317285" rel="nofollow external" class="bo">financially attractive target</a>. Older adults may also be more susceptible because they struggle with their confidence in using technology even as <a href="https://doi.org/10.1016/j.chb.2010.06.020" rel="nofollow external" class="bo">they recognize its benefits</a>.</p>
    
    
    
    <p>We have been <a href="https://doi.org/10.1145/3411764.3445071" rel="nofollow external" class="bo">developing technology tools</a> that help aging Americans maintain their own online safety no matter what challenges they may face, <a href="https://www.usenix.org/system/files/soups2020-mcdonald.pdf" rel="nofollow external" class="bo">including cognitive decline</a>. To do so, we needed to understand what and how the people we study are <a href="https://doi.org/10.1145/3465217" rel="nofollow external" class="bo">learning about cybersecurity threats</a> and what strategies they are being taught to <a href="https://doi.org/10.1145/3290605.3300573" rel="nofollow external" class="bo">reduce their vulnerabilities</a>.</p>
    
    
    
    <p>We have found that older adults attempt to <a href="https://doi.org/10.1145/3465217" rel="nofollow external" class="bo">draw on personal experience</a> to develop strategies to reduce privacy violations and security threats. For the most part, they are successful at detecting threats by being on the lookout for activities they did not initiate — for example, an account they do not have. However, outside experts <a href="https://doi.org/10.1145/3432954" rel="nofollow external" class="bo">have an inordinate amount of influence</a> on those with less perceived ability or experience with technology.</p>
    
    
    
    <h2>What ‘experts’ are telling older Americans</h2>
    
    
    
    <p>Unfortunately, the guidance that older adults are getting from those who presumably have authority on the matter is less than ideal.</p>
    
    
    
    <p>Perhaps the loudest of those voices is the <a href="https://www.aarp.org/" rel="nofollow external" class="bo">AARP</a>, a U.S. advocacy group that has been carrying out a mission to “empower” individuals as they age for over six decades. In that time, it has established a commanding print and online presence. Its magazine reached <a href="https://www.prnewswire.com/news-releases/aarp-the-magazine-has-the-highest-readership-of-all-us-magazines-mri-finds-300573427.html" rel="nofollow external" class="bo">over 38 million mailboxes in 2017</a>, and it is an <a href="https://www.washingtonpost.com/opinions/heres-why-ill-never-ever-join-the-aarp/2016/11/11/f95c14de-a790-11e6-8042-f4d111c862d1_story.html" rel="nofollow external" class="bo">effective advocacy group</a>.</p>
    
    
    
    <p>What we found was that the AARP communiqués on cybersecurity use storytelling to create cartoonish folktales of internet deception. A regularly featured diet of sensational titles like “<a href="https://www.aarp.org/money/scams-fraud/info-2017/military-scams-fd.html" rel="nofollow external" class="bo">Grandparent Gotchas</a>,” “<a href="https://www.aarp.org/money/scams-fraud/info-05-2010/spring_swindles.html" rel="nofollow external" class="bo">Sweepstakes Swindles</a>” and “<a href="https://www.aarp.org/money/scams-fraud/info-10-2011/fraud-scams-to-watch-for-2012.html" rel="nofollow external" class="bo">Devilish Diagnoses</a>” depict current and emerging threats.</p>
    
    
    
    <div>
    <a href="https://images.theconversation.com/files/453433/original/file-20220321-27-jwsvp9.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=1000&amp;fit=clip" rel="nofollow external" class="bo"><img src="https://images.theconversation.com/files/453433/original/file-20220321-27-jwsvp9.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip" alt="a man wearing a hooded sweatshirt and sunglasses types on a laptop computer" style="max-width: 100%; height: auto;"></a><em>Much of the cybersecurity advice given to elders fosters the cartoonish misconception that flesh-and-blood scam artists lurk in their midst. <a href="https://www.gettyimages.com/detail/photo/hacker-man-with-laptop-stealing-personal-data-from-royalty-free-image/1093756844" rel="nofollow external" class="bo">5m3photos/Moment via Getty Images</a></em>
    </div>
    
    
    
    <p>These scenarios appeal to readers the way crime shows have historically appealed to TV audiences: by using narrative devices to alarm and thrill. Ultimately they also delude viewers by leaving them with the misconception that they can use what they’ve learned in those stories to defend themselves against criminal threats.</p>
    
    
    
    <h2>Folktales and foibles</h2>
    
    
    
    <p>One job of folktales is to spell out the hazards that a culture wants its members to learn in childhood. But by presenting cyber-risk as a set of ever-evolving stories that focuses on particular risks, the AARP shifts attention away from basic principles to anecdotes. This requires its members to compare their online experiences with specific stories.</p>
    
    
    
    <p>Readers are implicitly encouraged to assess the plausibility of particular scenarios with questions like, Is it possible that I have any unpaid back taxes? And, Do I actually have an extended warranty? It requires people to catalogue each of these stories and then work out for themselves each time whether an unsolicited message is a real threat based on its content, rather than the person’s circumstances.</p>
    
    
    
    <h2>No, it’s not personal</h2>
    
    
    
    <p>Through this inventory of stories and characters, we also found that the AARP was personalizing what is, at root, a set of structural threats, impersonal by nature. The stories often characterize scammers as people in the reader’s very midst who use local news to manipulate older adults.</p>
    
    
    
    <p>Real threats are not “sweepstake swindlers” or “Facebook unfriendlies,” with a live scam artist sensitive to the needs and foibles of each intended victim. There is rarely a human relationship between the cyber-scammer and the victim — no con artists behind the notorious “grandparents scam.” The AARP bulletins and advisories imply that there is — or, at least, implicitly foster that old-fashioned view of a direct relationship between swindler and victim.</p>
    
    
    
    <h2>Don’t engage</h2>
    
    
    
    <p>Perhaps even more worrisome, AARP advisories appear to encourage investigation into scenarios, when engagement of any sort puts people at risk.</p>
    
    
    
    <p>In one post alerting people to “<a href="https://www.aarp.org/money/scams-fraud/info-2017/military-scams-fd.html" rel="nofollow external" class="bo">8 Military-Themed Imposter Scams</a>,” they discuss “prices too good to be true,” when the very concept of buying a car on Craigslist, or an “active-duty service member” urgently selling a car, should be a red flag discouraging any form of engagement.</p>
    
    
    
    <p>Internet users of any age, but especially more vulnerable populations, should be urged to withdraw from threats, not be cast as sleuths in their own suspense stories.</p>
    
    
    
    <h2>Protecting older adults in the age of surveillance capitalism</h2>
    
    
    
    <p>In order to reduce everyone’s risk while online, we believe it’s important to provide a set of well-curated principles rather than presenting people with a set of stories to learn. Everyone exposed to threats online, but especially those most at risk, needs a checklist of cautions and strong rules against engagement whenever there is doubt.</p>
    
    
    
    <p>In short, the best strategy is to simply ignore unsolicited outreach altogether, particularly from organizations you don’t do business with. People need to be reminded that their own context, behaviors and relationships are all that matter.</p>
    
    
    
    <p>Because, in the end, it’s not just about tools, it’s about worldview. Ultimately, for everyone to make effective, consistent use of security tools, people need a theory of the online world that educates them about the <a href="https://theconversation.com/explainer-what-is-surveillance-capitalism-and-how-does-it-shape-our-economy-119158" rel="nofollow external" class="bo">rudiments of surveillance capitalism</a>.</p>
    
    
    
    <p>We believe people should be taught to see their online selves as reconstructions made out of data, as unreal as bots. This is admittedly a difficult idea because people have a hard time imagining themselves as separate from the data they generate, and recognizing that their online lives are affected by algorithms that analyze and act on that data.</p>
    
    
    
    <p>But it is an important concept — and one that we see older adults embracing in our research when they tell us that while they are frustrated with receiving spam, they are learning to ignore the communications that reflect “selves” they don’t identify with.</p>
    
    
    
    <p>*****</p>
    
    
    
    <p><a href="https://theconversation.com/profiles/nora-mcdonald-1157126" rel="nofollow external" class="bo"><em>Nora McDonald</em></a><em>, Assistant Professor of Information Technology, <a href="https://theconversation.com/institutions/university-of-cincinnati-1717" rel="nofollow external" class="bo">University of Cincinnati</a> and <a href="https://theconversation.com/profiles/helena-m-mentis-1075210" rel="nofollow external" class="bo">Helena M. Mentis</a>, Professor of Information Systems, <a href="https://theconversation.com/institutions/university-of-maryland-baltimore-county-1667" rel="nofollow external" class="bo">University of Maryland, Baltimore County</a></em></p>
    
    
    
    <p><em>Header image:  Telling elders scary stories about online scammers is not the best way to keep them safe. <a href="https://www.gettyimages.com/detail/photo/midsection-of-senior-woman-using-mobile-phone-royalty-free-image/1306726470" rel="nofollow external" class="bo">Olga Gavrilenko/EyeEm via Getty</a></em>.</p>
    
    
    
    <p><em>This article is republished from <a href="https://theconversation.com" rel="nofollow external" class="bo">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/older-americans-are-given-the-wrong-idea-about-online-safety-heres-how-to-help-them-help-themselves-177215" rel="nofollow external" class="bo">original article</a>.</em></p>
    </div>
]]>
</Body>
<Summary>By Helena M. Mentis, professor, Information Systems, UMBC and Nora McDonald, assistant professor, Information Technology, University of Cincinnati      Recently, the U.S. Social Security...</Summary>
<Website>https://umbc.edu/stories/older-americans-are-given-the-wrong-idea-about-online-safety-heres-how-to-help-them-help-themselves/</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/119460/guest@my.umbc.edu/49e1a40c6bb02edc921faf3640e73a11/api/pixel</TrackingUrl>
<Tag>cybersecurity</Tag>
<Tag>discovery</Tag>
<Tag>information-systems</Tag>
<Tag>magazine</Tag>
<Tag>the-conversation</Tag>
<Group token="umbc-news-magazine">UMBC News &amp;amp; Magazine</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/umbc-news-magazine</GroupUrl>
<AvatarUrl>https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="original">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/original.png?1748556657</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="xlarge">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xlarge.png?1748556657</AvatarUrl>
<AvatarUrl size="large">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/large.png?1748556657</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/medium.png?1748556657</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/small.png?1748556657</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xsmall.png?1748556657</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/001/943/24435aa6207c452e7bc15cc74b42c7bb/xxsmall.png?1748556657</AvatarUrl>
<Sponsor>UMBC News &amp; Magazine</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Thu, 24 Mar 2022 15:30:17 -0400</PostedAt>
<EditAt>Thu, 24 Mar 2022 15:30:17 -0400</EditAt>
</NewsItem>

</News>
