Librarians and Cybersecurity 

Libraries hold large volumes of valuable data and play a key role in defending against cybercrime. 

Librarians have always had a central role in institutional cybersecurity. They are champions of good security, protecting the privacy of patrons, and upholding the core values of their institutions. Academic librarians also work to ensure that resources are well-curated and come from credible sources.  

illustration of a man reading a book with foliage behind him

Cybersecurity and academic libraries 

SNSI conducted research into cybersecurity and academic libraries in 2025. This was based on a survey of 287 librarians and interviews with 20 Chief Information Security Officers (CISOs). We found that 85% of librarians agree that cybersecurity threats are increasing. More than a quarter (28%) saw the library's security risk as higher than other departments across their institution.  

Encouragingly, most librarians report at least some understanding of cybercrime and data security. We work to build on that awareness with practical, relevant support. 

 As cyberthreats against institutions rise, campus-wide efforts to protect data are increasing. Librarians, along with other departments, have a key role to play in supporting digital literacy skills. They can educate patrons on how to: 

  • protect institutional and personal information 

  • spot predatory, fake, or pirate sites 

  • access legitimate resources to support their research 

  • use multi-factor authentication (MFA) 

  • create strong passwords.  

In addition, librarians can help integrate cybersecurity concepts into research skills and build strong relationships between the library and campus Information Security colleagues. 

Shield icon with connected circles representing cybersecurity or data protection.

What are the cybersecurity threats facing libraries? 

Library systems handle large volumes of sensitive data. This may include research, patron data, student records, and other personal information. Because academic libraries manage vast, valuable research databases and connect to broader university networks, they are prime targets for attacks from cybercriminals.

This is a significant challenge for librarians tasked with safeguarding sensitive data and restricted content. Cybersecurity threats facing libraries can take various forms, and may include: 

  • Ransomware and malware. Malicious software can encrypt critical library management systems and databases. This can paralyze services until a ransom is paid.  

  • Phishing. Cybercriminals use fraudulent emails to trick library staff and students into handing over institutional login credentials. This gives hackers a backdoor into broader university networks. 

  • Intellectual property and data theft. Academic repositories house cutting-edge research, unreleased trial data, and large amounts of personal user data. These assets are highly prized for corporate espionage or identity theft.  

  • Proxy and authentication hacking. Unauthorized users often hack proxy servers and stolen VPN (Virtual Private Network) credentials to bypass publisher access systems and illegally download licensed academic journals or books in bulk. 

Off-campus and remote access to library resources is a frequent point of vulnerability. In addition to these direct threats, the use of pirate sites to access scholarly content poses a threat to research integrity. They are also a risk to institutional systems and licensing compliance. Librarians have an important role in discouraging their use. 

How SNSI supports librarians 

Our research indicates that there is often limited collaboration between central IT security and library IT services – even though closer coordination benefits both. SNSI exists to help close that gap to help build a stronger, more resilient research ecosystem.

We bring librarians together with publishers, IT and cybersecurity teams, and institutions working on the same problem. Among the things we do to support your work, we: 

  • Convene key stakeholder groups to advance shared solutions to cybersecurity threats to libraries. 

  • Conduct research to better understand the cybersecurity threats that librarians face as well as librarian cybersecurity awareness, attitudes, and priorities. 

  • Share findings at conferences around the world and through our annual SNSI Security Summit. 

  • Provide practical guidance and resources to support, educate, and empower librarians. 

Infographic titled “Cybersecurity tips for librarians,” outlining practical guidance for improving information security literacy and developing mature security practices across academic libraries. Link to long description provided below.

Cybersecurity tips for librarians

Create a Campaign for Information Security literacy 

Lightbulb icon inside a circle

Refresh your knowledge of your institution’s information security and privacy policies. Research aspects of the policy, if necessary. Take advantage of any training resources available from the Information Security Office. 

See long description associated with this image.

Circular icon with a person swimming in water, surrounded by arrows indicating rotation.

Connect with your institution’s Chief Information Security Officer or Director of Information Security and build a relationship to discuss ways that the library can participate in improving security and privacy culture on campus. 

The library is a hub of learning for the campus community. Engage in teaching moments with students, faculty and staff that expand upon and extend normal password protection and phishing avoidance instruction taught by IT personnel to include responsibility for library resources. 

Icon of a person with a headset speaking, with sound waves indicating communication or customer support.

Promote the use of confirmed, legitimate websites for collecting primary sources, including author and publisher sites. Discourage the use of pirate sites as the integrity of content coming from unofficial sources cannot be guaranteed. 

Icon of a computer monitor with a shield and a check mark inside it, representing security or cybersecurity.

Remind colleagues and students of the risks that come when sharing account passwords and campus credentials as they are likely tied to other personal information including HR or student grade information, and may unknowingly enable access well beyond the single system they are trying to share. 

Icon of a smartphone with a Wi-Fi signal and a location pin

Provide clear, easy to understand and operate methods for securely accessing library resources from off campus. 

Circular icon with a smiley face and the numbers 1, 2, 3 inside it.

Inform and educate faculty, staff and students on steps they should take if they discover that their credentials have been compromised or given to another individual. 

Icon of a clipboard with a checklist

Develop Mature Security Practices

Consult your institution’s IT or Information Security office to recommend scheduling a REN-ISAC Cybersecurity Peer Assessment. Start a conversation about how the library can support and assist with increasing the institution’s information security culture. 

Speech bubble icon with a chat message and a person speaking

Partner with Campus IT or Information Security to promote available reading and videos on information security for self-service use by patrons at your institution. Examples and recommendations can be found on the SNSI Website.

Icon of a handshake inside a blue circle

Evaluate the library’s and campus’ requirements against the security capabilities of library-specific systems and applications and develop plans and pacing for timely software updates and patches.

A circular logo with a globe and digital nodes connected by lines, representing technology or connectivity.

Run and keep up-to-date endpoint protection and/or antimalware software on all library computers, both patron-facing and those that library staff use. 

Computer monitor with shield icon indicating security or cybersecurity.

Back up important files and records for recovery in case of ransomware attack or system failure. If a campus-wide backup and recovery solution exists, begin to use it. SNSI recommends a 3-2-1 approach to backup: keep three distinct copies of the data, two of them local but on different mediums, and one additional copy being off-site (including cloud). 

Cloud with a folder and an upward arrow, representing cloud data upload or storage.

When looking into bringing on new electronic resources, make sure they comply with your institution’s security policies. 

A stylized target with a checkmark at the center and concentric circles, indicating achievement or accuracy.

We recommend these rules of thumb for building stronger security practices in your institution. These recommendations can also be applied to most organizations. The investment of time, focus, and technology in prevention efforts is far more useful than the significant costs that result after a security intrusion or data breach.  

Resources for librarians

Learn more with the following resources for librarians: 

Toolkit for librarians

Cybersecurity tips sheet for librarians

SNSI Cybersecurity and Academic Libraries report (2025)

IP Address Management Best Practice guide

Shift Insight Library Survey Results (2021)

Our Scholarly Kitchen Guest Post ‘Cybersecurity and Academic Libraries: Findings from a Recent Survey’ (2022).

Explore our full library of guides, reports, and recordings.
These include our Security Summit sessions on library and institutional security. 

SNSI University Relations Group Members

  • Juan P. Denzer, Engineering Librarian, Engineering Library, Cornell University.

  • Rick Anderson, University Librarian, Harold B. Lee Library, Brigham Young University.

  • Stacy Best Ruel, Director of Marketing, Key Accounts, Americas Springer Nature.

  • Sharon Mattern Büttiker, Director of Content Management, Research Solutions, Inc.

  • Sari Frances, Dir. of Content Protection Services, Elsevier (Co-Chair).

  • Jamen McGranahan, Associate Director of Library Technology & Assessment Services, Vanderbilt Library, Vanderbilt University.

  • Emily McElroy, Vice President for Academic Relations, Taylor and Francis

  • Robert Hilliker, Director, Library Relations (North America), Springer Nature

  • Amanda Ferrante, Principal Product Manager, EBSCO Information Services

SNSI invites librarians and publishers, along with other important stakeholders, to contribute their time, ideas, and experience to help maintain a safe, secure, and trustworthy information environment for all. Please contact us with your ideas, concerns, and requests for more information.