** Student Receives Employee Cybersecurity Training Email – User Support Workflow **

< !!! INTERNAL USE ONLY !!! >
Not for distribution directly to end user

Overview

This workflow defines how User Support should respond when a student receives an employee cybersecurity training email (Infosec IQ) in error.

The goal is to provide correct reassurance, document the interaction, and apply appropriate routing without escalating to unrelated departments or causing unnecessary concern.

Audience

User Support staff

Procedure

Step 1: When to Use This Workflow

Use this workflow when a student reports:

  • Receiving an Infosec IQ email assigning employee cybersecurity training
  • Receiving reminders for employee cybersecurity training
  • Asking whether they must complete the training
  • Providing screenshots that show employee‑only training modules
  • Being clearly added in error (known internal misassignment pattern)

This workflow does not apply when:

  • The user is employee-only and the training assignment appears legitimate
  • The content is student cybersecurity training in Brightspace
  • The issue involves MFA, phishing, or a security incident
  • HR or Compliance training is involved

Step 2: Initial Verification

Before responding, confirm the following:

  1. The user’s affiliation is verified as student-only, employee-only, student-worker, or dual-affiliation
    • Verify via Account Assist → Affiliation
  2. The email is an Infosec IQ employee training message
  3. The message was sent to the student’s CCBC email address
  4. The training is not the normal student cybersecurity content in Brightspace
  5. The situation matches a known internal misassignment pattern, if applicable
  6. If student-worker or dual-affiliation status exists, follow the IA verification path

If any check fails, stop and route appropriately.

Ticket Status and Documentation Requirements

Use In Progress while verifying the user’s affiliation, reviewing the reported message, and determining the correct workflow path.

Use On Hold – Pending Customer Response if waiting for the student to provide a screenshot or additional information.

For student-only misassignment cases, document the affiliation check, the Infosec IQ employee training message, and the reassurance provided.

For dual-affiliation or student-worker cases, document the affiliation found and route the ticket to Information Assurance (IA) for verification.

For suspicious or malicious-looking messages, do not advise the user to click links or open attachments. Follow the phishing or security incident workflow.

Do not close the ticket until the appropriate workflow path has been completed.


Step 3: What to Tell the Student

Phone Response

You received that cybersecurity training email by mistake. Students do not need to complete the employee training, and your account is not affected. You can safely ignore the message.

If additional reassurance is needed:

A few students were added in error. There’s nothing you need to do—just delete the email.


Ticket Response (Public Comment)

You received the employee cybersecurity training email by mistake. Students are not required to complete this training, and your account is not affected. You can safely ignore the message. Please let us know if you receive additional notices.


Step 4: STOP POINTS

User Support must not:

  • Tell a student-only user to complete employee training, or advise completion before IA confirms the assignment is legitimate
  • Escalate to HR, Payroll, Registrar, Systems, Desktop, Instructional Technology, or Brightspace
  • Modify or remove training assignments
  • Contact the vendor
  • Suggest the student was hacked or at risk
  • Speculate on system errors or assign blame
  • Mention internal patterns to the student

Step 5: Routing Scenarios

Student‑only misassignment

  • Reassure the student
  • Add an internal note
  • Close the ticket
  • No escalation required

Training appears in Brightspace

  • Use the Student Cybersecurity Training workflow
  • Do not use this article

Suspicious or malicious‑looking email

  • Do not advise clicking any links
  • Follow the phishing or security incident workflow

Student worker or dual-affiliation user

  • Reassure the user that their access is not impacted.
  • Do not determine whether the assignment is legitimate.
  • Route the ticket to Information Assurance (IA) for verification.

If IA confirms the training assignment is legitimate, advise the user to complete the training.


Internal Documentation

Use technician‑tone internal notes.

Student‑only case:

User is student‑only. User received Infosec IQ employee cybersecurity training email in error. User does not need to complete employee training. Provided reassurance. Matches known misassignment pattern. No escalation required.

Dual affiliation:

User appears to have both student and employee affiliation. User received the employee cybersecurity training email. Provided reassurance. Routed to IA for verification.


Customer‑Facing Responses

Standard response:

You received the employee cybersecurity training email by mistake. Students are not required to complete this training, and your account is not affected. You can safely ignore the message.

Dual‑affiliation response:

Because you appear to have both student and employee access, we are forwarding your question for verification. Your access is not impacted.

Suspicious email response:

Please do not click any links or open attachments until we verify the source. We will follow up shortly.


STOP POINT – Final Summary

If the user is student-only and the email is employee cybersecurity training:

  • The student does not need to complete the training.
  • No escalation is required.
  • Provide reassurance.
  • Add an internal note.
  • Close the ticket.

Do not escalate to HR, Payroll, Registrar, Systems, Desktop, Instructional Technology, Brightspace, or employee‑training teams.

Escalate only when:

  • The user has student-worker or dual-affiliation status → route to IA for verification.
  • The email appears malicious → follow the phishing workflow.

 

If none of the above apply, the workflow is complete.

Print Article

Related Articles (2)

This Article reinforces consistent ticket handling, contact, and documentation practices across the User Support team.
Instructions for Account Assist.