Digital security

Guidance and support for staying safe online

Below you will find advice, guidance, documentation and as well as resources to help you combat security threats which will keep University, sensitive research and your personal data safe.

Security services

IT Security top tips and guidance

The University has a range of systems and processes in place to help keep you safe online, but there are a few simple steps you can take to help protect your personal data and University account from viruses, spam and phishing attempts:

Multi-factor authentication (MFA)

Multi-factor authentication (MFA) has now been added as an additional layer of security for staff and students working away from the University and accessing VPN and web services. Please visit the MFA pages to find support and guidance on how to set up DUO, our chosen multi-factor authentication platform.

Changes to Cyber Essentials requirements

Cyber Essentials requirements are subject to change circa every 12-18 months. The latest question set, Danzell, introduces new requirements that we are making provisions to deliver. 

What are the new requirements? 

Multifactor Authentication is now required when accessing services from campus and VPN networks.  

All Saas/Cloud services in use across the university must implement either Multifactor Authentication (MFA) or Single Sign On (SSO) where the platform provides the functionality. This includes where it is a paid addon and extends to social media accounts e.g. Facebook, Instagram, LinkedIn, etc. 

Devices running unsupported operating systems or with out-of-date security patches must be blocked from accessing services until they are brought up to a compliant level.

What does this mean? 

Staff and students on campus should expect to see MFA prompts when accessing services. This does not mean you will be prompted each and every time you sign into an application as session tokens for services like Microsoft 365 services will allow access once an initial MFA prompt has been approved. 

Users of cloud services that are not integrated with the university EntraID or IdP must ensure that MFA is implemented for any cloud services you are using. Failure to do so is an automatic failure of Cyber Essentials. 

Cyber Essentials (CE) certification opens doors for government research contracts and provides evidence to funding bodies. CE is a bare minimum requirement for a lot of research, especially central government and private companies. Certification failure would hamper the University core strategic aim around research 'We will be more ambitious in our research and innovation endeavour' 

Devices running unsupported operating systems or that are not patched with the most recent security updates will now be blocked from accessing services until they are deemed compliant through a quick posture check delivered by our MFA platform, Cisco Duo.

Additional services