The Center of Urban and Regional Planning for Postgraduate Studies at the University of Baghdad held a workshop titled “Protecting Personal Data and Institutional Systems.” The workshop was presented by Assistant Lecturer Lama Sabbar Zamel, Head of the Information Technology Unit at the Center, and was attended by the Center’s faculty and staff.
The workshop aimed to enhance employee security awareness regarding the protection of personal data and institutional systems. It emphasized the importance of using official email securely by outlining best daily practices that contribute to reducing the risk of hacking, protecting official devices and files, and promoting a culture of reporting any suspicious activity or untrusted messages.
The workshop addressed several key topics, including defining personal data and institutional systems, employee responsibilities in protecting information, best security practices for protecting accounts and systems, mechanisms for identifying phishing emails while protecting institutional email and work devices, and procedures for working remotely securely and avoiding the use of untrusted public networks. Sabbar addressed the importance of protecting information and data within the university work environment, outlining the employee’s role in maintaining confidentiality and ensuring the secure use of institutional systems. She focused on the most prominent cyber risks that employees may face, particularly phishing emails, suspicious links, and weak passwords.
The workshop concluded by recommending the need to enhance employee security awareness through regular workshops and training courses on protecting personal data and institutional systems. It emphasized the importance of using strong passwords for official accounts, changing them regularly, and not sharing them with anyone or storing them in unsecured locations. The workshop also stressed the importance of activating two-factor authentication for official accounts, as it provides an additional layer of protection against unauthorized access attempts. Employees were advised not to open suspicious links or attachments and to verify the sender’s address before engaging with any email, given the reliance on official email for institutional correspondence. The workshop further recommended avoiding the use of personal accounts for exchanging work-related documents or information, and emphasized preventing the installation of unauthorized software on institutional devices, relying only on software approved by the relevant authority. The lecturer, Ms. Sabbar, also recommended the importance of regularly backing up important files to protect them from loss, malfunctions, or ransomware attacks, using secure and reliable networks when working outside the organization, and reporting any suspicious messages, unusual activity, or security issues on the device or official account to the IT department.