Security emergency

Active incident, compromised account, or urgent threat?

Contact Help Desk: 610-758-HELP (4357)

Report an incident

Report a phish

Forward the suspicious email to spam@lehigh.edu. Our AI analyst reviews it and replies with a determination.

How to report a phish

Connect on LinkedIn

Glad to connect with Lehigh students, faculty, and staff. Students especially: if a career in security or IT interests you, reach out.

Connect with me

Book time with me

Pick the format that matches your question. The short intake form on each booking page means we can skip the background and get straight to answers.

Meeting typeBest forLink
Quick consult · 15 min A new tool, a vendor question, or a quick sanity check before you commit to something. Book
Project consult · 30 min Research data security, grant requirements, or a project that touches regulated data. Book
Office hours · weekly Open block, first come. Bring a question, a concern, or just curiosity about how security works here. Book
Class visit or talk Guest lectures, department meetings, student group presentations, and media inquiries. Book

Answers without a meeting

Most questions that reach my calendar are answered here faster.

  • Data classification quick reference What counts as Class I data, and what you can store where.
  • AI tool risk check Thinking about using an AI tool for coursework, research, or administration? Use this tool to help your department or class consider dimensions of risk in using AI.
  • Vendor contracts and security review (LUCA) Security review happens inside Lehigh's contract review process. Submit contracts, agreements, and terms through LUCA before signing. Reviews typically take 2 to 6 weeks, so build that into your timeline.
  • Data Use Agreements (LIRA) Data Use Agreements (DUA) and other data agreements that are not part of a larger research agreement need to be submitted in LIRA for review, approval, and CISO signature.
  • Security policies and standards The current, published versions. If a document is not here, it is not policy.

Before you book, three quick answers

The questions I hear most often, answered in advance. If yours is here, you just got 30 minutes back.

Can I use this new app or AI tool with university data?
It depends on the data, not the tool. Check the data classification reference first. Class I data requires an approved platform and a signed agreement. If you are unsure after that, book a quick consult and bring the tool's name and the data involved.
I clicked a link and I am worried. What now?
Change your Lehigh password immediately from a device you trust, then forward the message to spam@lehigh.edu. Fast reporting is the difference between a non-event and an incident. Nobody has ever gotten in trouble for reporting too quickly.
My grant or sponsor has security requirements. Where do I start?
Start with a project consult before you accept the terms, not after. Security requirements priced into a proposal are manageable. The same requirements discovered at award time are a fire drill. Bring the solicitation or the data management plan.

Information Security

The Information Security office works across every corner of Lehigh. On any given week we are:

  • Protecting Lehigh accounts and stopping phishing before it lands
  • Reviewing vendors and contracts so new tools arrive safely
  • Helping researchers meet the security terms in grants and sponsorships
  • Advising departments on handling regulated and sensitive data
  • Responding when something goes wrong, at any hour

What we are working on now

Updated quarterly. If one of these touches your work, that is a good reason to book time.

  • Enabling secure, approved AI tools for teaching, research, and administration
  • Modernizing Lehigh's Privacy Policy with the Office of General Counsel and a university sub-committee
  • Strengthening how we protect regulated data in research and student systems
  • Preparing the university to keep operating through disruption, whatever the source
A note on contact: security concerns should always go through the reporting links above rather than to any individual inbox. The team channels are monitored continuously. My calendar is not. Last reviewed: 8.6.26.