Monash Hub

Official guides / Student support & services

Cybersecurity - IT Services (Monash Malaysia)

Official source

Monash University Malaysia

Last checked: 8 Oct 2026 UTC

View the official Monash page ↗

What this page covers

Page text

Extracted from the official page for searching. Formatting, images and forms are not reproduced — open the original for anything you need to act on.

Cybersecurity At Monash University, being cyber aware is everyone's responsibility.

Cybersecurity

Monash University implements a defence-in-depth approach to information security and employs a multitude of cyber security controls to protect our infrastructure and data.

Phishing

Recognise phishing emails

What to do

Learn to recognise phishing emails and then report them.

Phishing emails used to be easy to spot, you had to look out for spelling errors, pixelated logos, and fake email addresses. With scammers becoming more professional, phishing emails can be harder to identify.

How to do it

Always ask yourself, am I expecting to receive this email? Most phishing emails are unsolicited. If you aren’t expecting it, be particularly careful.

Verify the information in the email. Go directly to the person, bank, business or department and check with them. Don’t use contact information provided in the email itself, use an email address or phone number provided on their official website.

You can also check by using Monash’s ‘report phishing’ button in Gmail, which will evaluate the email as safe, spam or malicious. See the report phishing emails section below for instructions on how to do this.

Why it matters

Scammers use email or text messages to try to steal your passwords, account numbers, or date of birth. If they get this information, they are a step closer to getting access to your email, bank, or other accounts.

Once they have access they could steal your money or data, install malware on your devices, or sell your information to other scammers.

Report phishing emails

What to do

Always report a suspected phishing email, even if you’re not sure.

How to do it

The quickest and easiest way to report a phishing email is to use Monash’s ‘report phishing’ button in Gmail. Currently this is only available on your desktop, not in the mobile app.

To report, follow these steps:

  1. Click the three dots at the top right, next to the reply icon (More will appear when you hover over this).
  2. Click " Report phishing " from the drop down list.
  3. Click the “Report Phishing Message” button.

You’ll receive a response from the Phishing Analysis Service (no-reply@e105.e.monash.edu) and the email will be evaluated as safe, spam or malicious. No further action is required.

Why it matters

Recognising a phishing email protects you, reporting a phishing email protects everyone. A couple of button clicks is all it takes.

If you spot a phishing email in your inbox, reporting it will also remove it from other people’s Monash inboxes.

Cyber Hygiene

What to do

If you can’t use your own data, connect to a secure Wi-Fi – Monash University’s is best.

How to do it

When you’re on campus, connect to the Monash wireless network, eduroam.

If you’re connecting remotely then be cautious of which Wi-Fi network you use. If you’re in a public place then avoid using any free Wi-Fi as this is not secured. Even if it requires you to use a password, it may not be a legitimate connection.

Why it matters

Using public or unsecured Wi-Fi is risky because the connection is not encrypted. This means anything you do could be monitored by a third party. Any information you enter, including passwords or payment details, could be easily viewed and stolen.

Learn More

Public Wi-Fi is a bit like a digital highway that anyone can travel on, versus a private road just for you. It’s ok to use when you’re browsing but don’t use it to enter passwords or to share sensitive information.

What to do

Use Monash’s VPN when you use your computer to access Monash systems. This is especially important:

How to do it

Monash University Malaysia VPN, GlobalProtect is offered to Monash staff to access on-premises resources securely.

Refer GlobalProtect VPN Access guide

Why it matters

Monash's VPN is a virtual private network that establishes a secure connection between you and the internet. It’s more secure against external attacks and is required to access some Monash systems when you’re off-site.

  • Using a VPN means all your data traffic is routed through an encrypted virtual tunnel. This disguises your IP address when you use the internet, making its location invisible to everyone. A VPN connection is more secure against external attacks.

Data Safety

Share files securely

What to do

Always check the settings when you share a file. Always choose the most ‘restricted’ and least privileged option available for files that contain confidential and sensitive information.

If you send a file as an email attachment, double check that you’re sending it to the correct recipients.

How to do it

When using Google Drive you can choose from the following sharing settings:

  • Restricted – only the people you have added can access the file
  • Monash University – only people within Monash can access the file
  • Anyone with the link – anyone can access this file.

These permissions can be altered at any time in the life of the document.

To make sure you're giving the correct people permissions to access files and correspondence, always:

  • Choose the correct sharing settings for the purpose of the file.
  • Ensure that the email addresses that you enter are correct and you've Cc'd or Bcc'd correctly.
  • Be mindful that using sharing settings other than the 'Restricted' setting can put your file at risk of being shared without your knowledge.

Why it matters

Accidentally sending a message or file to someone could be embarrassing but it could become a big problem if that document includes confidential information. It could lead to a violation of someone’s privacy or even to a data breach.

Be aware of data exfiltration risk

What to do

Be aware that cyber criminals will try to steal data from Monash systems and devices.

How it happens

Data exfiltration happens in two ways, through outsider attacks and insider threats.

Outsider attacks

An outsider attack occurs when an individual infiltrates a network to steal corporate data and potentially user credentials. This typically is a result of a cyber criminal injecting malware onto a device, such as a computer or smartphone, that is connected to the Monash University network.

Insider threats

Insider threats can be malicious, for example a staff member stealing their own organisation’s data and sending documents to their personal email address or cloud storage services – potentially to sell to cyber criminals.

Insider threats can also be caused unintentionally by careless behaviour that sees corporate data fall into the hands of bad actors.

Why it matters

Failing to control information security can lead to data loss that could cause reputational and financial damage to Monash.