Are you providing too much information in your Out Of Office notifications?
Details around your day or time of return, reason for absence, email signature, and alternative contact details may be a gold mine of useful information for hackers. This information can be used for social engineering and targeted attacks.
Do Not Provide:
- Location
- Duration
- Reason for absence
- Job title
- Contact information
- Detailed alternative contact information
Instead, Use Vague Wording:
- Currently unable to reply
- Unavailable at the moment
- Instead of specific individuals to contact, say “Contact my department”
Internal vs. External:
- Set an OOO message for colleagues within an organization
- Set an OOO message to external email addresses- this version should never have a signature attached
**While OOO notifications are useful for clients and colleagues not being left wondering what’s happened to their inquiry, they should be kept brief to limit the security risk. The less said, the better.**
Leave a Reply