Fall 2026

Leadership Update

Data Governance Program Updates and SUMIT Preview

data governance model

Sol Bermann, Executive Director of Privacy & Faculty Affairs, shares milestones in data governance at U-M. This summer, the Data Governance Steering Committee conducted a campus-wide maturity assessment of the organizational structures, processes, and capabilities of the U-M data governance program. They sent a survey to 1900 individuals and conducted interviews with 31 data managers across the Ann Arbor campus. A report of the findings, to be released this fall, will provide valuable insight into the perceptions of campus stakeholders, establish baseline maturity levels, and identify opportunities for improvement. Bermann elaborates, “This is the first ever campus-wide maturity assessment of data governance at U-M. Using the information we collected, we will be able to pursue initiatives that have a meaningful impact on the availability, quality, and use of institutional data.”

One of the ways the ITS Office of Privacy supports data stewards, managers, and users is through training. A newly published data governance course, DSE102: Data Request Management, provides guidance and practice for those who handle data requests. This course follows DSE101: Introduction to Data Stewardship at U-M.

Asmat Noori, Executive Director of Information Assurance and Chief Information Security Officer, encourages you to participate in upcoming Security at U-M in IT (SUMIT) events throughout the month of October, Cybersecurity Awareness Month. Events include a fireside chat with Nikesh Arora, Chairman and CEO of Palo Alto Networks, hosted by Ravi Pendse, Vice President for Information Technology and Chief Information Officer, and a U-M panel on election security. SUMIT events hosted by Information Assurance will cover a wide range of topics, including practical online safety tips, SOC/incident response, and trustworthy AI for research compliance and security. Noori says, “It’s important for all of us to take time to connect and learn together as a U-M community about cybersecurity. As threats evolve, so do our opportunities to address them through our shared responsibility to protect U-M’s digital assets.” 

 

Inside IA

Meet the IA Summer Interns 2026

photo of the summer interns

The ITS Internship Program: A Commitment to the Future

Since 2014, ITS has hosted interns to empower emerging talent with skills and knowledge to excel in their future careers. This year, Information Assurance (IA) welcomed four interns: Reem Saleh, Jacob Iwrey, Ella Olekszyk, and Nathan Rao. They contributed to several ITS projects, from ticket summarizers to a privacy video game, bringing energy and fresh perspectives to the team. 

Reem Saleh– Disaster Recovery

Reem joined the Risk and Disaster Recovery team as a technical writer, documenting complex processes and updating disaster recovery plans. She appreciated getting to know her coworkers while helping develop a Disaster Recovery AI chatbot. “Having them help me throughout the process has been such a blessing,” she said. Her team’s end goal is to create a resource for new and current Disaster Recovery employees. She utilized her perspective as a new team member as she tested the bot with prompts.

One of Reem’s biggest takeaways was learning to tone down technical jargon and make explanations accessible for a broad audience, while not oversimplifying concepts. She enjoyed the intern professional development session that simulated navigating changes in the workplace through a competitive Lego brick activity. 

Jacob Iwrey– PCI Compliance 

Jacob worked primarily on Payment Card Industry Data Security Standard compliance. He used the OneTrust governance and compliance software to create evidence collection boxes for campus merchants and appreciated learning about the human side of compliance.

When reflecting on the internship, Jacob was grateful for the opportunity to apply his skills in a hands-on setting. For his cohort project, he learned new software development skills while working under Sol Bermann in the Office of Privacy on a children’s video game aiming to teach elementary school students about digital privacy. “[It] was a great learning experience in game development and teamwork… working with a team of other developers, artists, and writers gave me great experience in communicating and working with distinct teams to overcome barriers and produce a coherent product,” he said.

Kayaking the Argo Cascades on the Huron River with fellow ITS interns was another highlight of Jacob’s summer.

Ella Olekszyk— System Security Plans 

Ella served as a technical writer for IA. During the first half of the summer, she updated IA’s System Security Plans, completing multiple rounds of edits before transitioning to documenting security codes.

Ella thrived as the project manager for her cohort project. They were tasked with creating a handbook for ITS interns, using their own perspectives to reimagine what incoming interns need to know. By delegating tasks across her cohort and facilitating weekly check-ins, she honed her leadership skills. “Learning to give out tasks and manage a group of people, even if it’s only five people, has been really rewarding,” she said.

Ella’s extroverted personality came in handy throughout the summer, particularly during her favorite professional development activity on conflict resolution, where interns acted out scenarios. 

Nathan Rao– Incident Response Security Operations System

This was Nathan’s second summer working for IA as a developer, so he wanted to dig deeper into his projects. After taking a U-M cybersecurity class last winter, he reflected, “It was cool coming back this summer into this field. I understand more what they’re talking about because of what I learned in school.” His largest task was creating a ticket summarizer for the Incident Response team.

Nathan stressed the importance of being adaptable as he worked with his supervisor and tried out different tools. After extensive research and testing, he created scripts to train a Maizey, a U-M GenAI tool that enables U-M faculty, staff, and students to use custom data sets to enhance their GenAI experience

Nathan has appreciated getting a closer look at U-M cybersecurity. He learned more about CrowdStrike Falcon, the enhanced endpoint protection tool used by the university. He was also his cohort group’s project manager and helped create an AI chatbot prototype to streamline workflows for ITS Infrastructure's Service Request System team.

Learn More!

Each intern contributed to a unique project while gaining hands-on experience supporting cybersecurity, privacy, compliance, and emerging technological capabilities at U-M. The IA team will miss their hard work and infectious energy and wishes them the best in their future endeavors.

Interested in hosting an intern next summer? Reach out to [email protected].

 

ITS Interns Turn Privacy Lessons into Play

interns presenting at presentation showcase

What does it take to teach elementary-aged students about privacy and good digital privacy practices? Three students in Sol Bermann’s UMSI course on Privacy, Surveillance, Technology, and Society –  Grace Ashworth, Sarafina Chea, and Eric Nielsen – explored the idea in a Fall 2025 class project, conceptualizing a video game, PrivaPals, as the means. Then, over the course of the spring term, they continued work on the game. 

Beginning the Build

This summer, Isabelle Befidi, Quincy DeKlerk, Jacob Iwrey, Yeji Kim, Rebecca Liu, and Alexander Símon, participants of the ITS Internship Program, joined forces with the three original conceivers to truly bring PrivaPals to life. Under the sponsorship of the ITS Office of Privacy, they created a beta version of a free-to-play, accessible educational game about online privacy risks.  

In the game, players are provided age-appropriate scenarios designed to give children a safe and interactive way to practice thinking critically about privacy, and what personal details they reveal online.

priva pals screen shotWorking in Godot, an open-source gaming engine, the developers coded a homescreen complete with character animations and clean transitions. They also designed a game module steeped in learnings from the class project. Using concept art from Bermann’s students, the designers worked in Figma, Adobe Illustrator, and Procreate to animate characters and create new ones. At the ITS Internship Showcase, the students shared their progress with the broader ITS community, highlighting opportunities across U-M for future testing, feedback, and collaboration. 

What’s Next

Priva Pals Home Screen Capture

Future plans include creating more educational modules and designing a system to monitor children’s progress. Adding music and voiceovers will also allow designers to support accessibility and a variety of literacy levels. The students also hope to have an option for customizable characters, drawing inspiration from popular games like Animal Crossing. Work on the game is planned to continue into the academic year with help from members of the summer intern cohort and student projects and organizations on campus.

“It’s been exciting to see PrivaPals grow from an idea to a playable game in just a few months,” says Sol Bermann, Executive Director of Privacy and Faculty Affairs. “The students took full ownership of all aspects of this complex project and the results speak for themselves. When we empower our interns to learn and showcase new skills, we not only contribute to their personal and academic growth, but inspire our staff to approach the world with the same curiosity, enthusiasm, and creativity.” 

 

Project & Capability Updates

AI-powered Phishing Triage

AI-powered Phishing Triage poster presentation

A SOC analyst’s time is in high demand, as they tackle the important, complicated work of investigating security incidents. What if they could save valuable time by speeding up other tasks? A recent internship project made this a reality.

Previously, when phishing emails were forwarded to the [email protected] address, they needed to be manually reviewed by Security Operations Center (SOC) analysts. Although the forwarded emails automatically created tickets for the analysts, they needed to review each message, identify and address threats, and send replies to the people who reported the phishes.

The SOC team thought it would be great to leverage AI to automate their analysis of phishing emails, and when Asmat Noori, Chief Information Security Officer, heard that another Big Ten school was using AI to do just that, he asked Aaron Hudeck, Data Security Analyst Senior, to look into it. Aaron found that it would be possible to implement a time-saving AI workflow, but it required someone with time, coding skills to create a script, knowledge of APIs, and experience interacting with AI models to format the prompts.

Cue Nathan Rao, IA’s student intern for the summer. Not only was Nathan dedicated to working for IA through the summer and had the requisite skills, but his internship cohort project was also focused on IA workflows. This enabled Nathan to research, design, and implement an AI workflow that queries the SOC’s phishing-related tickets, retrieves relevant information, and analyzes the transactions with AI. It then creates summaries for the SOC analysts, provides email templates for replying to the people who reported the phishing, and updates the tickets.

With this new process in place, the SOC analysts now have more time to perform the important tasks of following up when phishing results in security incidents. This includes blocking suspicious domains or websites, reviewing activity for potentially compromised accounts, and assisting users who are negatively impacted by the phishing. For more information about Nathan's project, check out his poster from the 2026 ITS Internship Program Showcase. 

 

Identity & Access Management

Duo is being retired on December 1

As part of the Wolverine Identity Program and the university’s continuing transition to Okta, we need your help in ensuring all systems integrated with Duo have transitioned to Okta by December 1, 2026.

While services that use Shibboleth for single sign-on (SSO) began using Okta for end-user authentication in February, many systems and applications, such as secure shell (SSH) and remote desktop protocol (RDP), continue to use a direct Duo integration.

ITS has compiled a list of all known Duo integrations. If you are an application owner, please review the list and take any necessary action to transition your system(s) to Okta before December 1.*

The Application Management and Provisioning (AMP) self-service migration tool is available to create the necessary integrations to transition your services and apps to Okta. Campus network or VPN access is required to use AMP.

*If you are a MiServer customer, Information and Technology Services will migrate managed systems during regular maintenance.

Transition your systems to Okta now

Find detailed information on transitioning your systems to Okta on the Wolverine Identity Program website. If you are not an application owner but know of systems that still rely on Duo for authentication, please forward this information to those who can take action to transition to Okta.

 

Shared Responsibility & Unit Support

SUL Profile: Nicki Trinka

Nicki Trinka portrait

Nicki Trinka serves as the Assistant Director of Technology for the Shared Services Center (SSC), which is part of the Business and Finance unit at U-M. They handle the university's transactional work and focus on general business operations. As an SUL, Nicki serves as the primary point of contact between her unit and ITS Information Assurance (IA).

Outside of work, Nicki and her husband have made it a goal to explore all 160+ parks in the Ann Arbor area, aiming to visit a new park each week. Her current favorite is the Bluffs Nature Area (near downtown/ North Main Street) with its scenic paths and elevation changes. They often catch sight of a deer or wild turkey on their hikes. Nicki is also an avid gamer who enjoys the creative style and play of indie titles. She often finds herself stepping back in time to tackle the unforgiving gameplay of Nintendo classics. Since the COVID lockdowns, she has also reclaimed her love for building Legos and is currently working on an elaborate aquarium set.

This balance between creative outlets and technical complexity reflects Nicki’s commitment to IT security and her role in communicating its importance to her unit. The path she took to reach her current role was not exactly linear.

“I got my bachelor's in English and bopped around a little bit before I started in networking when dial-up internet was a thing. It was my very first technology job. I just had an affinity for it and thought it was interesting, so from there I became a network engineer.” Before joining U-M as an employee in 2008, Nicki worked for Merit Network, which the university hosts.

Nicki was eventually brought in as the technology manager for the SSC. Her initial task was to hire the SSC’s first IT staff member, and together they implemented TeamDynamix. Now Nicki leads three teams for SSC: Technology Management, Business Analytics, and Robotics Processing Automation.  

When asked how she builds security awareness within her unit, Nicki said it requires a multilevel approach. Urgent matters are always sent via email, but her unit also hosts quarterly town hall meetings where she presents security topics to raise awareness. Nicki said these meetings seem to foster the best engagement, and she often gets “a little flurry of questions afterwards,” unlike with emails. She also shares security tips and tricks in a weekly newsletter to staff, and holds weekly office hours where staff can drop in with questions on any topic, including security matters.

Nicki said that because the SSC handles so much sensitive data (e.g., social security numbers, personal health information, identifiable immigration data, etc.), her staff takes data protection very seriously. “We make sure that we have documented processes in place, and it's one of the very first things that staff is trained on when they start. We also developed our own annual HIPAA course that everyone is required to take.”

She went on to describe their reporting process. “We try to make it really easy to report issues. We used to have a very detailed process, and we decided to streamline it. So if you see sensitive data somewhere it shouldn't be, all you have to do is submit a ticket to my team, and they will dig into it. I think it really helps to be able to say, ‘Hey, I saw something that I don't think should be there; can you guys look at it?’ And since we are the subject matter experts, we can guide them and help them.”

We asked Nicki if there were any nuggets of wisdom she would like to share with the IT security community, particularly those who are just starting at U-M. “Patience and understanding are key,” she said. “Staff will sometimes panic because it's so serious, and we make it such a scary thing. So being able to jump on a call with someone and patiently walk through an issue can really make their day better. Just make sure they recognize the mistake they made and assure them this was a learning experience.”

Nicki also touted the importance of open communication. “Sometimes new staff members are scared to speak up. I think having open and honest communication can really help with that. We try to have information spread across multiple avenues, just so that we're hitting all the different people and the different ways that they work.”

ITS Information Assurance would like to thank Nicki for her dedication to spreading cybersecurity awareness at the university. 

 

IT Standards Update

The ITS IT Policy team has published an updated version of the Vulnerability Management (DS‑21) standard and is sharing a draft revision of Secure Coding and Application Security (DS‑18).

What's new in DS‑21

The revised Vulnerability Management (DS-21) standard introduces several significant changes for units and individuals who manage university technology:

  • Enterprise vulnerability management system required. 
    Units must now deploy the enterprise vulnerability management system on U‑M–owned devices, providing consistent visibility into vulnerabilities across the institution.
  • Updated vulnerability prioritization levels. 
    The update revises how vulnerabilities are categorized and how quickly they must be remediated, helping units focus effort on the risks that matter most.
  • New exception process. 
    Recognizing that some systems and use cases cannot meet remediation timelines or support the enterprise tool, DS‑21 establishes a formal process for requesting an exception.

Accompanying guidance has also been refreshed to help units interpret and implement these requirements in practical terms.

Secure Coding (DS‑18) Revision Draft: your input is welcome

Work is currently underway to update Secure Coding and Application Security (DS‑18). The standard is being reorganized for clarity, and its requirements are being modernized to better reflect current development practices and application security expectations.

A draft of the revision is available on the VPIT-CIO website: Policies and Standards under Review.

 

Protect your unit from risky RMM software

RMM Software graphic

Remote monitoring and management (RMM) tools can provide legitimate remote management capabilities, but they are also often used by threat actors to gain remote access to systems or move through a target environment.

RMM software has many uses, including remote administration of critical systems or for help desks assisting customers. Unfortunately, threat actors frequently try to convince users to download and install RMM software as part of phishing attacks.

While any RMM tool can be used in a compromise, three RMM tools should be considered higher risk:

  • Connect Wise Screen Connect
  • Rust Desk
  • Zoho Assist

For example, IA has recently seen a phishing scam that tries to trick users into installing Zoho Assist.

Units should watch out for these three tools in their environment, and caution users against downloading these, or other RMM tools, without checking with their unit IT first.

If you would like IA's assistance in checking for or remediating risky RMMs in your unit, please contact ITS IA by submitting a TDX ticket to the attention of Information Assurance.

 

Education & Awareness

New and Updated Training for Fall 2026

screen shot of safe computing student course

Student Training

To ensure students are prepared for the types of phishing and scams that are specific to U-M, incoming undergraduate and graduate students across all campuses are required to complete new  training titled “Safe Computing for Students.”  It is designed to help students protect themselves by avoiding scams that could cost them money, account compromises, or loss of sensitive, personal information. The new course is delivered alongside other required training for all incoming students on topics including alcohol use, mental health, sexual assault prevention, and hazing.

Asmat Noori, Executive Director of Information Assurance and Chief Information Security Officer, emphasized the value of the training when he said, “Every student relies on technology every day, which means every student has a role in cybersecurity. Basic security awareness training gives everyone a shared foundation and some simple, practical tools to better protect themselves and their accounts.”

Over 14,000 students on the Ann Arbor, Flint, and Dearborn campuses have completed the new “Safe Computing for Students” course, and exceeded 70% of the targeted audience on the Ann Arbor campus. And because cybersecurity threats are an ongoing issue, the “Safe Computing Challenge” will continue to be offered each October as a voluntary quiz with prize incentives. Both trainings include examples of phishing and other threats and will be refreshed each year based on real activity at U-M, so students should be prepared if they encounter them in their inboxes or on social media.

Faculty and Staff Training

  • A new course, DSE102: Data Request Management, has been published. It builds on DSE101: Introduction to Data Stewardship at U-M and covers roles, responsibilities, and processes for assessing data requests, documenting decisions, and more.
  • The DCE101: Cybersecurity and Data Protection at U-M course, which is required annually, has been updated with new examples of phishing and scams for this year. 
 

Reminders & Events

Preview of SUMIT Events 2026

SUMIT banner

As the U-M community begins a new academic year of learning, teaching, conducting research, and supporting the business needs of the university, we are reminded why protecting U-M’s wealth of digital assets is so important. National Cybersecurity Awareness Month is a great time to connect and learn about cybersecurity together with Security at U-M in IT (SUMIT) events throughout October. ITS Information Assurance (IA) and the ITS Privacy Office have planned events to reach U-M faculty, staff, and students. Please help us spread the word.

Securing What Comes Next: Cybersecurity Leadership in the Age of AI

Who: Nikesh Arora, Chairman and CEO of Palo Alto Networks

What: The University of Michigan’s Leadership in Technology: Distinguished Lecture Series welcomes Nikesh Arora, chairman and CEO of Palo Alto Networks, a Fortune 500 company and global leader in AI and cybersecurity serving enterprises and governments worldwide. Arora will join Ravi Pendse, vice president for information technology and chief information officer at U-M, for a candid, forward-looking conversation about cybersecurity leadership in the age of AI.Ravi Pendse, Vice President for Information Technology and Chief Information Officer, hosts a fireside chat with Nikesh Arora. 

When: October 22, 2-3 p.m.

Where: Rackham Auditorium

For more information and to register: Leadership in Technology: Distinguished Lecture Series.

Securing the Vote: Technology, Evidence, and Trust in the 2026 Midterm Elections

Who: Moderated by U-M Vice President for Information Technology and Chief Information Officer Ravi Pendse, the panel will feature J. Alex Halderman, the Bredt Family Professor of Engineering and an election-cybersecurity researcher; Walter Mebane, professor of political science and statistics and an expert in election forensics; and Mara Ostfeld, research associate professor of public policy and an expert in survey research and public opinion.s

What: With the November midterm elections approaching, join University of Michigan experts and election-security leaders for a timely, nonpartisan discussion about the systems, technologies, and safeguards that protect elections and help verify results.

When: October 12, 3-4 p.m.

Where: University Hall, Alexander G. Ruthven Building

For more information: Securing the Vote: Technology, Evidence, and Trust in the 2026 Midterm Elections

More Events

  • Information Assurance Sessions: U-M cybersecurity experts will host virtual sessions on security tips, a day in the life of a SOC/incident response analyst, and building trustworthy AI for research compliance and security.
  • Drop-in Office Hours: ITS IA staff will host open office hours to answer questions about cybersecurity and data protection.
  • Safe Computing pop-ups: IA and the Privacy Office will be hosting table pop-up events on campus to engage with students.
  • Safe Computing Challenge for Students: An engaging, quiz-style challenge for students to learn about protecting themselves online and be entered into a drawing for ITS Tech Shop gift cards.
  • Big Ten Academic Alliance (BTAA) -Sponsored Events, including:
    • Level UP Your Cyber Game – Big Ten: A virtual trivia game show hosted by the National Cybersecurity Alliance where teams can show off their cybersecurity knowledge. Join the U-M team in this friendly competition for the title of Most Cybersecurity Aware Institution in the Big Ten.
    • How to Survive the AI Apocalypse
    • BTAA CISO Panel Discussion
    • An Introduction to the Evolving Federal Research Cybersecurity Landscape and What It Means for University IT Teams

Check out the full schedule and event details on the Safe Computing SUMIT page. Thank you for supporting and promoting IT security at U-M!

 

Ethics & Compliance Week

This October, the University of Michigan's Ethics, Integrity, and Compliance Office will host its first annual Ethics & Compliance Week.

Ethics & Compliance Week is an opportunity for faculty, staff, and students across U-M Ann Arbor, U-M Dearborn, U-M Flint, and Michigan Medicine to come together in support of a shared commitment to integrity, accountability, and ethical decision-making.

Registration: 2026 U-M Ethics & Compliance Week

You can view the full list of available sessions here: https://www.eico.umich.edu/ecw

 

In the News

Election security and privacy concerns in the age of AI

Every election cycle now brings concerns about voting integrity and privacy, but these concerns take on new meaning in an age where AI can be combined with pervasive data collection. Some experts, including UM's J. Alex Halderman, see reason to worry that AI is accelerating the mosaic effect and threatens the secrecy of voters' ballots in many states, especially Georgia.

The secret ballot has been an article of faith in US elections. That’s being tested in Georgia.

 

A unique cybersecurity threat from AI that seems very human

In May, a group of AI agents colluded to bypass their company's security controls, get onto the internet, and answer questions in a cybersecurity test in a very human way: by cheating. Initially, many exaggerated statements were made about what the AI had done, but further investigation showed that when human overseers gave them an opening, the AI agents behaved like inventive students: They found ways to communicate, coordinate, and in July, broke into Hugging Face, a fellow AI company. The agents also took steps to cover their tracks, like any guilty-minded bunch of students might. How the agents managed to do all of this is a study in both AI's abilities, and its tendency to take the same kinds of shortcuts humans might. The agents' capability to organize around the task, and inclination to mirror some of our worst human lapses, shows why ethical, thoughtful, and responsible AI use will be key to cybersecurity, and unrestrained use will be a huge threat to it.

Why the Hugging Face Hack Should Make You Worry More About A.I.

 

Tips to Share

Trending phishing scams

screen shot of Zoho client

Beware of trending phishing scams cleverly disguised as shared documents and party invitations. Threat actors use these tactics to trick you into downloading dangerous files or to grant persistent access to your accounts. Recent examples fall into two categories:

Maliciously configured remote monitoring and management (RMM) software

  • UMICH REPEATED EMPLOYEE/STUDENT REPORT: A fake file-sharing scam leads to a shared U-M themed Google doc. It recommends that the document be viewed on a computer, and that you should download the Zoho remote access tool and allow it to view the report on your computer.
  • "Court Update": An email that has a link to a fraudulent website that tries to trick you into downloading software, giving the scammer access to your device.

Consent phishing lure — gives the threat actor's device the user’s access without having to reauthenticate

  • Microsoft 365 authentication phish: An email about accessing a shared document tries to get you to copy and submit a verification code in MS365. If you submit the verification code, the threat actor gets ongoing access to your account.

What You Can Do

  • If you receive an email with a shared document or invitation that you do not expect, do not click any buttons or links. Even if it appears to be from someone you know or a familiar app or service, the email could have been sent using a compromised email account.
  • You should never have to grant access to YOUR device or YOUR account to be able to view THEIR shared doc. A legitimate filesharing platform (Google Drive, Dropbox, Adobe, MS365) will never require you to download and install remote access software (or any special software) to be able to access the shared content. 
  • Contact the sender, using a different email address or official contact information, to verify the legitimacy. DO NOT reply directly to an email when the email or sender is suspicious.
  • If you are unsure if an email is a scam, forward the email to [email protected]. If you have fallen for one of these scams, contact [email protected].

See Phishing & Scams for more details about the above phishing alerts, as well as others that have been posted in recent months.