Cybersecurity Cookbook

Cybersecurity Cookbook

Cybersecurity Cookbook

Practical, everyday habits to protect research data, grouped by topic. Adopt what applies to your project; check data‑type guidance for anything regulated.

Submit a Ticket


These are recommended practices, not a substitute for project‑specific requirements. If your data is governed by HIPAA, CUI, a DUA, or an IRB protocol, follow those requirements first, and reach out to Research IT if you’re unsure.

Recipes By Topic

  • Use your own university account.
  • Never share accounts, passwords, or credentials.
  • Enable Multi-Factor Authentication (MFA) whenever available.
  • Use Single Sign-On (SSO) or Active Directory (AD) authentication whenever possible.
  • Grant access only to personnel with a legitimate project need.
  • Review access periodically and remove users who no longer require it.
  • Keep operating systems and applications up to date.
  • Apply security patches promptly.
  • Use university-managed devices whenever possible.
  • Ensure antivirus or endpoint protection software is active.
  • Lock devices when unattended.
  • Encrypt laptops, desktops, and removable media used to store research data.
  • Use approved encrypted methods to transmit sensitive information.
  • Store research data only in approved locations.
  • Use approved collaboration and file-sharing platforms.
  • Verify recipients before sharing sensitive information.
  • Do not use personal cloud storage services for sensitive research data unless specifically approved.

See approved storage options

  • Collect only the information necessary for the project.
  • Use de-identified data whenever possible.
  • Remove identifiers when no longer needed.
  • Follow approved retention and disposal requirements.

Researchers are responsible for complying with applicable research security requirements.

  • Complete required research security training.
  • Complete required cybersecurity awareness training.
  • Understand sponsor-specific research security requirements.
  • Consult the Export Controls Office before sharing controlled information internationally.
  • Review international collaboration requirements when working with foreign entities or institutions.
  • Review foreign travel requirements before project-related international travel.

Report suspected or confirmed incidents immediately, including:

  • Lost or stolen devices
  • Unauthorized access
  • Accidental disclosure
  • Malware infections
  • Phishing incidents
  • Suspected compromise of research data
  • Violations of sponsor security requirements

Report an incident