How to Stay Safe Online at the University of Leeds


This article provides essential cyber security guidance for University of Leeds staff and students. Following these simple steps will help protect your personal information, University data, accounts, and devices from cyber criminals, fraudsters, and online threats.

Important: To access the University knowledge articles linked throughout this guide, make sure you are signed in to the IT website first.

1. Control What You Share

Be cautious when sharing information online. Cyber criminals often use emails, messages, and fake websites to trick people into revealing personal or sensitive information.

What you should do
  1. Check unexpected emails and messages carefully before responding.
  2. Confirm the sender is genuine before sharing information.
  3. Avoid clicking links or opening attachments if you are unsure of their source.
If you accidentally share information
  • Stop sharing the information immediately.
  • Remove access where possible, or ask the file owner to do so.
  • Contact the IT Service Desk as soon as possible to report a potential data breach.
Useful resources

2. Use Strong Passwords

Your password helps protect access to your University account and personal information.

Create stronger passwords

Use three random words to create a password that is:

  • Easy for you to remember
  • Difficult for others to guess
  • Unique to each account
Good password habits
  1. Use a different password for each account.
  2. Never share your password with anyone.
  3. Avoid obvious information such as names, birthdays, or common words.
  4. Consider using a password manager to store passwords securely.
If you forget your password

Follow the University's password reset guidance.

If you think your password has been compromised

Contact the IT Service Desk immediately.

3. Double Up Your Defence with Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA), sometimes called Two-Factor Authentication (2FA), provides an extra layer of protection by requiring an additional verification step when signing in.

Multi-Factor Authentication (MFA) at the University

The University uses Multi-Factor Authentication (MFA) to help protect accounts and services.

Important security advice

If a cyber criminal obtains your password, they may repeatedly send MFA approval requests hoping you will accept one.

Never approve an MFA request that you were not expecting.

If this happens:

  1. Reject the request.
  2. Change your password if possible.
  3. Contact the IT Service Desk immediately.

Use MFA on other accounts

Many services support MFA, including:
  • Email accounts
  • Social media platforms
  • Banking services
  • Online shopping websites
Using MFA significantly reduces the risk of unauthorised access.

4. Protect Your Devices

Keeping your devices updated is one of the most effective ways to stay secure.

Keep software up to date

Software updates often include:

  • Security improvements
  • Bug fixes
  • Protection against newly discovered threats
University-managed devices

University-managed computers:

  • Receive updates automatically
  • Include antivirus protection
  • Are monitored to help maintain security
Personal devices

If you use personal devices for University work or study:

  1. Install updates promptly.
  2. Use antivirus protection where appropriate.
  3. Enable device security features such as screen locks and encryption.
Software updates requiring administrator rights

If your University-managed computer requires administrator approval for an update, submit a request using the software update request form.

5. Improve Your Cyber Security Awareness

Cyber security is everyone's responsibility.

Report suspicious activity

You should:

  1. Use the reporting buttons in Outlook to report spam and phishing emails.
  2. Contact the IT Service Desk immediately if you believe your University account has been compromised.
  3. Report anything suspicious that may affect University systems or data.
Continue learning

Useful sources of cyber security advice include:

Staying informed helps protect both you and the wider University community.

Troubleshooting

I received a suspicious email
  • Do not click links or open attachments.
  • Use the Outlook reporting tools to report the email.
  • Delete the email if instructed to do so.
I accidentally shared a file with the wrong person
  • Remove access immediately if possible.
  • Contact the file owner if you cannot remove access yourself.
  • Report the incident to the IT Service Desk.
I forgot my password
  • Use the University's password reset process.
  • Contact the IT Service Desk if you cannot regain access.
I received an unexpected MFA request
  • Do not approve the request.
  • Change your password if you believe it may be compromised.
  • Contact the IT Service Desk immediately.
My device is asking for administrator rights to install updates
  • Do not attempt to bypass security controls.
  • Submit a request through the University's software update process.

Frequently Asked Questions❓

What should I do if I think an email is a phishing attempt?

Use the reporting buttons in Outlook and avoid clicking any links or attachments. If you have interacted with the email, contact the IT Service Desk immediately.

Why should I use a different password for every account?

Using unique passwords prevents a security breach on one account from giving attackers access to your other accounts.

What is Multi-Factor Authentication (MFA)?

MFA is an additional security check that requires you to confirm your identity using a second method, such as an authentication app or notification, after entering your password.

Do I need antivirus software on my personal device?

Yes. Antivirus software helps detect and prevent many common threats and should be used alongside regular software updates.

Who should I contact if I think my University account has been compromised?

Contact the IT Service Desk immediately so appropriate action can be taken to secure your account and protect University systems.