Information Technology Security Services


JWU’s Information Technology Security Services Team (ITSS) is committed to protecting the university’s information resources from both internal and external threats.

Backlit computer screen with lines of code trailing into the distance.

Our Mission

ITSS strives to achieve this mission by deploying a defense-in-depth approach to security. The Information Security Office applies Security Best Practices to ensure the confidentiality, integrity and availability of the university’s information resources. ITSS collaborates with campus IT leaders and staff to assist in protecting information resources that are critical to the university.

ITSS is committed to maintaining the confidentiality and integrity of all JWU data stored, collected, transferred and processed through technology. In addition, the team ensures compliance with all applicable state, federal and international regulations and statutes, as well as contractual obligations to ensure the protection of the university’s information technology resources from unauthorized access or damage. ITSS also aims to educate and raise security awareness among students, faculty and staff.

Enhancing Security with Multi-Factor Authentication (MFA)

In a world that’s built on technology, nothing is more important than security. Your small actions make a big difference for your security, both at home and at Johnson & Wales University.

Graphic depicting the process for multi-factor authentication (MFA), which adds an additional layer of security to online transactions of all kinds.

Protecting JWU & Personal Data

In the modern digital landscape, depending solely on passwords exposes sensitive information to cyber threats. Attackers commonly employ phishing and social engineering tactics to compromise accounts and gain unauthorized access. To address these risks, Johnson & Wales University (JWU) requires Multi-Factor Authentication (MFA) for all university accounts, adding a crucial additional layer of protection.

How MFA Strengthens Security

MFA improves account security by requiring users to verify their identity using two or more distinct methods. These methods can include a password (something you know), a phone or security token (something you have), or biometric data such as fingerprints or facial recognition (something you are). If a password is compromised, an attacker would still need the second authentication factor to gain access, making it much harder to breach accounts.

Defending Against Threat Actors

This enhanced security helps protect against threat actors—individuals or groups who intentionally target systems, networks, or users. By requiring multiple forms of verification, MFA is widely considered a best practice for safeguarding organizational and personal accounts. It greatly reduces the likelihood of unauthorized access.

The Impact of MFA at JWU & Beyond

Implementing MFA at JWU not only helps protect university data but also promotes greater awareness of cybersecurity risks among users. Extending MFA protection to personal accounts—including financial, email, and social media—is both simple and highly effective for securing personal information. Everyone is strongly encouraged to enable MFA on their accounts to prevent unauthorized access and lower the risk of identity theft.

Common Targets & Threats

Threat actors often seek to steal personal or financial data, hijack email accounts to launch phishing attacks, or access other sensitive resources. Understanding these objectives is essential for university students, faculty & staff.

Limitations and Ongoing Vigilance

While MFA significantly enhances account security, it is not infallible. Sophisticated attackers may attempt to bypass MFA by sending deceptive “verification” emails that link to phishing websites where both passwords and MFA codes are requested. They may also impersonate IT staff by phone, attempting to trick users into revealing MFA codes. If successful, these techniques can allow attackers to infiltrate JWU accounts, send phishing messages, and access university data.

Best Practices to Minimize Risk

By remaining vigilant and consistently using multi-factor authentication, you help protect your accounts and contribute to a safer, more resilient digital environment for everyone at JWU.

  • Never share MFA codes or approve sign-ins you did not initiate.
  • Be skeptical of any email or phone request for verification or MFA codes.
  • Remember: JWU IT will never ask for your MFA code.
  • If you have any doubts about an email, forward it to phishing@jwu.edu for investigation by our team.

In a world that’s built on technology, nothing is more important than security. Your small actions make a big difference for your security, both at home and at Johnson & Wales University.


The ITSS Team

Nicholas Tella
Chief Information Security Officer
401-598-3030
nicholas.tella@jwu.edu

Mary Ide
Network Security Administrator
401-598-1558
mary.ide@jwu.edu

Vishal Ojha
Information Security Analyst II
401-598-3032
vishal.ojha@jwu.edu

David Armstrong
IT Quality Assurance Manager
401-598-1526
david.armstrong@jwu.edu

Jay Lally
PCI Compliance Manager
401-598-4491
jay.lally@jwu.edu

Alexander Nardolillo
Information Security Support Specialist
401-598-4493
alexander.nardolillo@jwu.edu

Prince Thapa
Information Security Support Specialist
401-598-4357
prince.thapa@jwu.edu