Working off-campus

Working off-campus securely

Working off-campus gives you flexibility, but it is important to protect your University account, devices, and information wherever you work. Whether you are working from home, travelling, or using a public workspace, following these simple practices can help keep University information secure.

1.  Protect your Notre Dame account and devices

Your University account and devices provide access to email, files, teaching systems, research information, and other University resources. Protecting both is one of the most important ways to keep University information secure.

Do:

  • Use a strong password that is different from your personal accounts.
  • Use Multi-Factor Authentication (MFA).
  • Keep your authentication methods up to date.
  • Enable automatic updates on all devices used for University work.
  • Lock your device whenever you step away.
  • Report lost or stolen devices promptly.
  • Install software only from trusted and approved sources.

Don't:

  • Share your password with anyone.
  • Set up automatic email forwarding unless it has been approved by your manager.
  • Approve an MFA request you did not initiate.
  • Reuse passwords from personal accounts.
  • Use your Notre Dame account to access non-University or personal services, such as Netflix.

Remember: an unexpected MFA request may indicate someone is attempting to access your account. If you receive a prompt that you did not initiate, deny the request and contact IT.

Remember to "Look, Lock and Leave" whenever you step away from your device.

2. Be alert to scams and phishing

Cybercriminals frequently target universities through email, text messages, phone calls, social media, and fake websites.

Be cautious of:

  • Emails requesting urgent action.
  • Requests to verify your account or password.
  • Unexpected file-sharing invitations.
  • QR codes that lead to unfamiliar websites.
  • Requests for payments, gift cards, or sensitive information.

Before clicking a link or opening an attachment:

Stop. Think. Verify.

If you are unsure whether a message is genuine, contact the sender using a trusted method. Staff are encouraged to regularly review cybersecurity awareness tips published in Staff News to stay informed about current threats and scams.

3. Protect University information

University information should be handled securely regardless of where you work.

Good practice:

  • Store files in OneDrive, Teams, SharePoint, or other approved University systems.
  • Use approved file-sharing methods when collaborating with colleagues.
  • Avoid downloading unnecessary local copies of University documents.
  • Be mindful of who can view your screen in public places.
  • Keep physical documents secure and out of sight when not in use.

OneDrive, Teams and SharePoint are the University's primary file storage and sharing platforms and should be used for storing and sharing University documents.

4. Use AI tools responsibly

Artificial Intelligence (AI) tools can improve productivity, research, and administrative tasks when used appropriately. At present, Microsoft Copilot in Office is the University's approved AI service.

When using AI tools:

  • Follow University policies and procedures.
  • Only use approved AI services for University work.
  • Never enter confidential, sensitive, personal, student, HR, financial, or research information into AI services that have not been approved by the University.
  • Consider whether information entered into an AI service could be retained, processed, or disclosed outside the University's control.

If you are uncertain whether information is appropriate to use with AI services, seek guidance before proceeding.

5. Working of public Wi-Fi

Public Wi-Fi networks may not be as secure as trusted home or workplace networks.

When working remotely:

  • Connect only to legitimate and trusted networks.
  • Avoid accessing sensitive information on networks you do not trust.
  • Be alert for fake Wi-Fi networks designed to imitate legitimate services.
  • Take care when working in public areas where others may see your screen.

Certain University systems require VPN access. VPN access is only provided where there is a business need and appropriate approval has been granted.

Report Cybersecurity Incidents

Reporting quickly can significantly reduce the impact of a cybersecurity incident.

Contact the IT Service Desk immediately if you:

  • Receive a suspicious email.
  • Accidentally clicked a suspicious link.
  • Approved an MFA request you don't recognise.
  • Believe your account has been compromised.
  • Lose a laptop, phone, or other device used for University access.
  • Suspect University information has been exposed.
  • Observe suspicious activity in a University system.

If you believe your account has been compromised, reset your password as soon as possible and contact IT immediately.

IT Support

  • Phone Support: Call us between 8:00 AM and 5:00 PM at 1800 878 903.
  • Service request: Log a support request through our IT Service Portal