Official guides / Student support & services
Cybersecurity - IT Services (Monash Malaysia)
Monash University Malaysia
Last checked: 8 Oct 2026 UTCWhat this page covers
- Cybersecurity
- Monash University implements a defence-in-depth approach to information security and employs a multitude of cyber security controls to protect our infrastructure and data.
- Phishing
- Recognise phishing emails
- What to do
- How to do it
- Why it matters
- Report phishing emails
- What to do
- How to do it
- Why it matters
- Cyber Hygiene
- What to do
- How to do it
- Why it matters
- Learn More
- What to do
- How to do it
- Why it matters
- Data Safety
- Share files securely
- What to do
- How to do it
- Why it matters
- Be aware of data exfiltration risk
- What to do
- How it happens
- Outsider attacks
- Insider threats
- Why it matters
Page text
Extracted from the official page for searching. Formatting, images and forms are not reproduced — open the original for anything you need to act on.
Cybersecurity At Monash University, being cyber aware is everyone's responsibility.
Cybersecurity
Monash University implements a defence-in-depth approach to information security and employs a multitude of cyber security controls to protect our infrastructure and data.
Phishing
Recognise phishing emails
What to do
Learn to recognise phishing emails and then report them.
Phishing emails used to be easy to spot, you had to look out for spelling errors, pixelated logos, and fake email addresses. With scammers becoming more professional, phishing emails can be harder to identify.
How to do it
Always ask yourself, am I expecting to receive this email? Most phishing emails are unsolicited. If you aren’t expecting it, be particularly careful.
Verify the information in the email. Go directly to the person, bank, business or department and check with them. Don’t use contact information provided in the email itself, use an email address or phone number provided on their official website.
You can also check by using Monash’s ‘report phishing’ button in Gmail, which will evaluate the email as safe, spam or malicious. See the report phishing emails section below for instructions on how to do this.
Why it matters
Scammers use email or text messages to try to steal your passwords, account numbers, or date of birth. If they get this information, they are a step closer to getting access to your email, bank, or other accounts.
Once they have access they could steal your money or data, install malware on your devices, or sell your information to other scammers.
Report phishing emails
What to do
Always report a suspected phishing email, even if you’re not sure.
How to do it
The quickest and easiest way to report a phishing email is to use Monash’s ‘report phishing’ button in Gmail. Currently this is only available on your desktop, not in the mobile app.
To report, follow these steps:
- Click the three dots at the top right, next to the reply icon (More will appear when you hover over this).
- Click " Report phishing " from the drop down list.
- Click the “Report Phishing Message” button.
You’ll receive a response from the Phishing Analysis Service (no-reply@e105.e.monash.edu) and the email will be evaluated as safe, spam or malicious. No further action is required.
Why it matters
Recognising a phishing email protects you, reporting a phishing email protects everyone. A couple of button clicks is all it takes.
If you spot a phishing email in your inbox, reporting it will also remove it from other people’s Monash inboxes.
Cyber Hygiene
What to do
If you can’t use your own data, connect to a secure Wi-Fi – Monash University’s is best.
How to do it
When you’re on campus, connect to the Monash wireless network, eduroam.
If you’re connecting remotely then be cautious of which Wi-Fi network you use. If you’re in a public place then avoid using any free Wi-Fi as this is not secured. Even if it requires you to use a password, it may not be a legitimate connection.
Why it matters
Using public or unsecured Wi-Fi is risky because the connection is not encrypted. This means anything you do could be monitored by a third party. Any information you enter, including passwords or payment details, could be easily viewed and stolen.
Learn More
Public Wi-Fi is a bit like a digital highway that anyone can travel on, versus a private road just for you. It’s ok to use when you’re browsing but don’t use it to enter passwords or to share sensitive information.
What to do
Use Monash’s VPN when you use your computer to access Monash systems. This is especially important:
- If you can only connect to public Wi-Fi
- When you access Monash systems from overseas
- For sensitive communications.
How to do it
Monash University Malaysia VPN, GlobalProtect is offered to Monash staff to access on-premises resources securely.
Refer GlobalProtect VPN Access guide
Why it matters
Monash's VPN is a virtual private network that establishes a secure connection between you and the internet. It’s more secure against external attacks and is required to access some Monash systems when you’re off-site.
- Using a VPN means all your data traffic is routed through an encrypted virtual tunnel. This disguises your IP address when you use the internet, making its location invisible to everyone. A VPN connection is more secure against external attacks.
Data Safety
Share files securely
What to do
Always check the settings when you share a file. Always choose the most ‘restricted’ and least privileged option available for files that contain confidential and sensitive information.
If you send a file as an email attachment, double check that you’re sending it to the correct recipients.
How to do it
When using Google Drive you can choose from the following sharing settings:
- Restricted – only the people you have added can access the file
- Monash University – only people within Monash can access the file
- Anyone with the link – anyone can access this file.
These permissions can be altered at any time in the life of the document.
To make sure you're giving the correct people permissions to access files and correspondence, always:
- Choose the correct sharing settings for the purpose of the file.
- Ensure that the email addresses that you enter are correct and you've Cc'd or Bcc'd correctly.
- Be mindful that using sharing settings other than the 'Restricted' setting can put your file at risk of being shared without your knowledge.
Why it matters
Accidentally sending a message or file to someone could be embarrassing but it could become a big problem if that document includes confidential information. It could lead to a violation of someone’s privacy or even to a data breach.
Be aware of data exfiltration risk
What to do
Be aware that cyber criminals will try to steal data from Monash systems and devices.
How it happens
Data exfiltration happens in two ways, through outsider attacks and insider threats.
Outsider attacks
An outsider attack occurs when an individual infiltrates a network to steal corporate data and potentially user credentials. This typically is a result of a cyber criminal injecting malware onto a device, such as a computer or smartphone, that is connected to the Monash University network.
Insider threats
Insider threats can be malicious, for example a staff member stealing their own organisation’s data and sending documents to their personal email address or cloud storage services – potentially to sell to cyber criminals.
Insider threats can also be caused unintentionally by careless behaviour that sees corporate data fall into the hands of bad actors.
Why it matters
Failing to control information security can lead to data loss that could cause reputational and financial damage to Monash.