Showing posts with label data exposure. Show all posts
Showing posts with label data exposure. Show all posts

Saturday, March 29, 2025

Acceptable Use Policies and the Importance of Digital Security

Reviewing Our Acceptable Use Policy: Are We on Target?

Image Source: https://otter.ai/blog/what-are-ai-agents-a-guide-to-types-benefits-and-examples

Technology is woven into nearly every aspect of education, making Acceptable Use Policies (AUPs) essential for guiding responsible use. At my school, our AUP lays out clear expectations for students, but like many policies, it leans heavily on what they shouldn’t do rather than empowering them with best practices. The policy covers a wide range of digital behaviors, including internet usage, social media interaction, and device management. It is detailed and comprehensive, aligning with the requirements of the Children’s Internet Protection Act (CIPA) and addresses issues like cyberbullying, unauthorized access, and inappropriate content. However, it lacks substantial guidance on emerging technologies, most notably, Artificial Intelligence (AI). As AI tools become increasingly accessible, should our policy explicitly define appropriate AI use for learning? Without this clarity, students and faculty alike are left to navigate these tools without institutional guidance.

Faculty are also bound by an AUP, though it differs slightly from the student version. While we are trusted with more autonomy, the core principles remain the same. But are these policies comprehensive enough? And more importantly, do they adequately prepare us for the evolving risks of digital exposure?

The Reality of Data Exposure

Image Source: https://klik.solutions/great-info/top-internet-safety-rules/

To evaluate personal cybersecurity risks, I recently explored Have I Been Pwned, a site that reveals if an email has been caught in a data breach. What I found was unsettling: my personal email had been involved in three breaches, while my work email had been compromised six times. This raised immediate concerns. If my work credentials have been exposed that many times, what does that mean for my students?

Using this interactive tool, I traced the history of my data leaks. My first breach was in 2018 at Apollo, where information like my job title, email, and even social media profiles were exposed. A year later, LuminPDF followed, this time leaking passwords and authentication tokens. The breaches continued: People Data Labs in 2019, LinkedInScrape in 2021, and DemandScience in 2024. With each incident, more of my identity was exposed—email addresses, phone numbers, names, and job titles, all out there, potentially in the hands of bad actors.

Image Source: https://www.abc.net.au/news/2023-05-18/data-breaches-your-identity-interactive/102175688

This isn’t just an individual issue; it’s a systemic one. If educators and students aren’t actively protecting their data, we’re all at risk. Yet, our AUP barely touches on digital security beyond broad warnings against phishing scams. Shouldn’t we be teaching students how to actively safeguard their personal information?

Practical Steps for Stronger Security

After seeing my own data exposure, I turned to resources for improving security. One simple step is using stronger passwords. Instead of short, complex passwords that are difficult to remember, tools like Use a Passphrase generate long, easy-to-remember passphrases that are significantly harder to crack. Encouraging students and faculty to adopt passphrases over standard passwords could be a small but impactful addition to our AUP.

Image Source: https://proton.me/blog/what-is-passphrase

Additionally, we should explicitly incorporate guidance on managing personal data, recognizing the risks of data breaches, and using AI tools responsibly. Cybersecurity education shouldn’t just be an afterthought. It should be embedded into our policies and curriculum.

Moving Forward: Updating the AUP

Reflecting on my own experiences with data breaches, I feel a mix of anxiety and awareness. It’s unsettling to realize how much of my information has been compromised, but it also reinforces the need for vigilance. The reality is that we cannot simply abandon the internet; rather, we must take proactive steps to secure our digital presence. Just as we lock our doors or set house alarms for physical security, we must implement strong passwords, enable two-factor authentication, and remain cautious about sharing personal information online.

Our AUP should evolve to reflect this reality. We need to move beyond reactive policies that focus solely on restrictions and instead provide students and staff with actionable steps for responsible technology use. Cybersecurity experts, faculty, IT specialists, and even students should be involved in shaping these updates. A strong policy isn’t just about setting rules, it’s about equipping our school community with the tools to navigate an increasingly digital world safely and responsibly.