Cyber Security for Higher Education Institutions
Practical resources to help HEIs and FEIs improve their cyber security

Senior Leaders, including VCs, PVCs, Registrars and Deans
Senior leaders should understand the potential impact of cyber attacks and must take ultimate responsibility for the digital resilience of the organisation, while also ensuring that all staff and students are aware of their roles in security.

Cyber security & universities: Managing the risk report
Written by experts from UUK, Jisc and the NCSC, with support from UCISA, this guidance outlines the main threats and the impact of recent attacks against individual organisations across the UK research and education sector. It sets out leaders’ responsibilities to understand and mitigate these risks and provides action points to consider and more detailed advice around cyber security.
Academic staff and researchers
An open, collaborative approach to teaching and research activity is fundamental to the success of universities, but it also carries a degree of risk; universities and their data are valuable targets for cyber criminals.

Protecting the UK's thriving Research and Innovation sector
To support the integrity of the system of international research collaboration, the NCSC, in collaboration with NPSA, have Trusted Research guidance. Designed in partnership with the sector, it provides guidance to researchers, university staff and funding organisations to help keep sensitive research and intellectual property secure from theft, misuse or exploitation.

Get confident with what cyber security means for you and learn some actionable steps you can take to stay safe online with Top tips for staff
CISOs and IT teams
CISOs and IT Teams enable institutions to function effectively; building and maintaining the IT infrastructure required to deliver quality education at scale, while sustaining an understanding of technology and risks to effectively protect staff, students, researchers, and the valuable projects they work on from online threats.
Guidance for supporting VIPs
High-profile individuals can attract influence, but also significant risk. Carefully managed engagement and clear processes which enhance VIP security can build resilience from online threats, protecting a university's data, and reputation.
Reporting an HEI or FEI cyber incident

Where to Report a Cyber Incident.
Reporting cyber incidents can also be made to Report Fraud. If you're in Scotland, then reports should be made to Police Scotland. If the incident involved a data breach we would advise reporting it to the Information Commissioner’s Office (ICO) under GDPR guidelines.








