Librarians and Cybersecurity
Libraries hold large volumes of valuable data and play a key role in defending against cybercrime.
Librarians have always had a central role in institutional cybersecurity. They are champions of good security, protecting the privacy of patrons, and upholding the core values of their institutions. Academic librarians also work to ensure that resources are well-curated and come from credible sources.
Cybersecurity and academic libraries
SNSI conducted research into cybersecurity and academic libraries in 2025. This was based on a survey of 287 librarians and interviews with 20 Chief Information Security Officers (CISOs). We found that 85% of librarians agree that cybersecurity threats are increasing. More than a quarter (28%) saw the library's security risk as higher than other departments across their institution.
Encouragingly, most librarians report at least some understanding of cybercrime and data security. We work to build on that awareness with practical, relevant support.
As cyberthreats against institutions rise, campus-wide efforts to protect data are increasing. Librarians, along with other departments, have a key role to play in supporting digital literacy skills. They can educate patrons on how to:
protect institutional and personal information
spot predatory, fake, or pirate sites
access legitimate resources to support their research
use multi-factor authentication (MFA)
create strong passwords.
In addition, librarians can help integrate cybersecurity concepts into research skills and build strong relationships between the library and campus Information Security colleagues.
What are the cybersecurity threats facing libraries?
Library systems handle large volumes of sensitive data. This may include research, patron data, student records, and other personal information. Because academic libraries manage vast, valuable research databases and connect to broader university networks, they are prime targets for attacks from cybercriminals.
This is a significant challenge for librarians tasked with safeguarding sensitive data and restricted content. Cybersecurity threats facing libraries can take various forms, and may include:
Ransomware and malware. Malicious software can encrypt critical library management systems and databases. This can paralyze services until a ransom is paid.
Phishing. Cybercriminals use fraudulent emails to trick library staff and students into handing over institutional login credentials. This gives hackers a backdoor into broader university networks.
Intellectual property and data theft. Academic repositories house cutting-edge research, unreleased trial data, and large amounts of personal user data. These assets are highly prized for corporate espionage or identity theft.
Proxy and authentication hacking. Unauthorized users often hack proxy servers and stolen VPN (Virtual Private Network) credentials to bypass publisher access systems and illegally download licensed academic journals or books in bulk.
Off-campus and remote access to library resources is a frequent point of vulnerability. In addition to these direct threats, the use of pirate sites to access scholarly content poses a threat to research integrity. They are also a risk to institutional systems and licensing compliance. Librarians have an important role in discouraging their use.
How SNSI supports librarians
Our research indicates that there is often limited collaboration between central IT security and library IT services – even though closer coordination benefits both. SNSI exists to help close that gap to help build a stronger, more resilient research ecosystem.
We bring librarians together with publishers, IT and cybersecurity teams, and institutions working on the same problem. Among the things we do to support your work, we:
Convene key stakeholder groups to advance shared solutions to cybersecurity threats to libraries.
Conduct research to better understand the cybersecurity threats that librarians face as well as librarian cybersecurity awareness, attitudes, and priorities.
Share findings at conferences around the world and through our annual SNSI Security Summit.
Provide practical guidance and resources to support, educate, and empower librarians.
Cybersecurity tips for librarians
Create a Campaign for Information Security literacy
Refresh your knowledge of your institution’s information security and privacy policies. Research aspects of the policy, if necessary. Take advantage of any training resources available from the Information Security Office.
See long description associated with this image.
Connect with your institution’s Chief Information Security Officer or Director of Information Security and build a relationship to discuss ways that the library can participate in improving security and privacy culture on campus.
The library is a hub of learning for the campus community. Engage in teaching moments with students, faculty and staff that expand upon and extend normal password protection and phishing avoidance instruction taught by IT personnel to include responsibility for library resources.
Promote the use of confirmed, legitimate websites for collecting primary sources, including author and publisher sites. Discourage the use of pirate sites as the integrity of content coming from unofficial sources cannot be guaranteed.
Remind colleagues and students of the risks that come when sharing account passwords and campus credentials as they are likely tied to other personal information including HR or student grade information, and may unknowingly enable access well beyond the single system they are trying to share.
Provide clear, easy to understand and operate methods for securely accessing library resources from off campus.
Inform and educate faculty, staff and students on steps they should take if they discover that their credentials have been compromised or given to another individual.
Develop Mature Security Practices
Consult your institution’s IT or Information Security office to recommend scheduling a REN-ISAC Cybersecurity Peer Assessment. Start a conversation about how the library can support and assist with increasing the institution’s information security culture.
Partner with Campus IT or Information Security to promote available reading and videos on information security for self-service use by patrons at your institution. Examples and recommendations can be found on the SNSI Website.
Evaluate the library’s and campus’ requirements against the security capabilities of library-specific systems and applications and develop plans and pacing for timely software updates and patches.
Run and keep up-to-date endpoint protection and/or antimalware software on all library computers, both patron-facing and those that library staff use.
Back up important files and records for recovery in case of ransomware attack or system failure. If a campus-wide backup and recovery solution exists, begin to use it. SNSI recommends a 3-2-1 approach to backup: keep three distinct copies of the data, two of them local but on different mediums, and one additional copy being off-site (including cloud).
When looking into bringing on new electronic resources, make sure they comply with your institution’s security policies.
We recommend these rules of thumb for building stronger security practices in your institution. These recommendations can also be applied to most organizations. The investment of time, focus, and technology in prevention efforts is far more useful than the significant costs that result after a security intrusion or data breach.
Resources for librarians
Learn more with the following resources for librarians:
Cybersecurity tips sheet for librarians
SNSI Cybersecurity and Academic Libraries report (2025)
IP Address Management Best Practice guide
Shift Insight Library Survey Results (2021)
Our Scholarly Kitchen Guest Post ‘Cybersecurity and Academic Libraries: Findings from a Recent Survey’ (2022).
Explore our full library of guides, reports, and recordings.
These include our Security Summit sessions on library and institutional security.
SNSI University Relations Group Members
Juan P. Denzer, Engineering Librarian, Engineering Library, Cornell University.
Rick Anderson, University Librarian, Harold B. Lee Library, Brigham Young University.
Stacy Best Ruel, Director of Marketing, Key Accounts, Americas Springer Nature.
Sharon Mattern Büttiker, Director of Content Management, Research Solutions, Inc.
Sari Frances, Dir. of Content Protection Services, Elsevier (Co-Chair).
Jamen McGranahan, Associate Director of Library Technology & Assessment Services, Vanderbilt Library, Vanderbilt University.
Emily McElroy, Vice President for Academic Relations, Taylor and Francis
Robert Hilliker, Director, Library Relations (North America), Springer Nature
Amanda Ferrante, Principal Product Manager, EBSCO Information Services
SNSI invites librarians and publishers, along with other important stakeholders, to contribute their time, ideas, and experience to help maintain a safe, secure, and trustworthy information environment for all. Please contact us with your ideas, concerns, and requests for more information.