UCOP Cybersecurity Mandate 2025

September 18, 2024
Elizabeth Watkins, Matthew Gunkel, and Dewight Kramer
September 18, 2024

Dear Campus Community, 

As we approach the 2024-25 academic year, I am writing to share information regarding new cybersecurity measures on our campus. The updates are part of a University of California system-wide initiative required by the UC Regents and led by the UC Office of the President, and involve crucial steps to protect our personal and institutional information.

Why is Change Needed Now?

Cyber threats pose a rapidly growing risk to the integrity of UCR’s research, teaching, and financial data, as well as the personal data of our community members. In addition to carrying extreme financial and legal repercussions, these threats can compromise the very foundation of academic freedom by putting our intellectual property and academic resources at risk. By strengthening our security protocols UC-wide, we aim to create a safer environment where academic pursuits and university operations can continue without disruption.

What Does This Mean for You?

Change can be challenging. We want to assure you that UCR’s plan to meet the new UCOP requirements is designed to support, not infringe upon, your work. We seek your partnership in the following areas:

1.   Complete Your Annual Cybersecurity Training: This training is required of all UC employees. It provides information on some of the most common threats facing the university and the actions you must take as an employee to protect yourself and our campus.

2.    Secure Your Devices: For those using university-managed devices, the necessary updates will be handled automatically. (Learn how to move to a university-managed device.) If you manage your own device, you will be required to install and use specific security tools to connect to UCR's secure networks and cloud resources, and are responsible for keeping your devices secure. 

3.    Verify Your Identity: Although already required to access most secure UCR resources, multi-factor authentication (MFA) will now be required of anyone using campus and heath email systems. To authenticate, users will need to use the university authenticator application

These are vital and urgent first steps we must take to enhance UCR’s security posture and align with UC cybersecurity expectations. The campus can expect that additional measures may be implemented as UCR works to come into full compliance.      

Resources and Support

There is a dedicated webpage with more detailed information, resources, and FAQs to assist you in this transition. We encourage you to refer to this webpage, as it will continue to be updated with information about UCR’s security plan and the important roles each of us play in ensuring we meet UC’s May 2025 compliance deadline.

Thank you for your understanding and your cooperation as we strive to better protect the remarkable work we do at UCR. 

Sincerely, 

Elizabeth Watkins

Provost and Executive Vice Chancellor

Matthew Gunkel 

Associate Vice Chancellor and Chief Information Officer

Dewight Kramer

Chief Information Security Officer