Open navigation

Library Cybersecurity Best Practices 101

Libraries rely heavily on computers, networks, internet access, email, and cloud-based services to serve their communities. Even a small library should maintain a basic cybersecurity program to protect staff, patrons, library data, and computer systems.

The following practices provide a basic security foundation for public libraries.

Note: Be sure to read the checklist at the bottom of this page.

1. Firewall Protection

Every library should have a business-class firewall protecting its internet connection.

The firewall should:

  • Have an active software/security subscription so it continues receiving security updates and threat-protection updates.
  • Be kept on a currently supported firmware version.
  • Block unnecessary inbound internet connections.
  • Only allow remote access when it is specifically required.
  • Have administrative access protected with strong passwords and, when available, multi-factor authentication (MFA).
  • Have its configuration backed up periodically.

A firewall should not simply be installed and forgotten. It needs to remain licensed, updated, monitored, and supported.

2. Antivirus and Endpoint Security

All library-owned Windows computers and servers should have active antivirus or endpoint security software.

This includes:

  • Staff computers
  • Public computers
  • Laptops
  • Servers
  • Administrative computers

Antivirus software should:

  • Update automatically.
  • Provide real-time protection.
  • Perform regular scans.
  • Report infections or security problems.
  • Be periodically checked to make sure it is actually running.

Having antivirus installed is not enough if it has expired, is disabled, or is no longer receiving updates.

3. Active Patch Management

Libraries should have an active patch-management process rather than relying entirely on individual employees to update their computers. Someone should be responsible for verifying that updates are installed.

At minimum, patch management should include:

Microsoft Windows Updates

Windows security updates should be installed monthly and critical security updates should be addressed promptly. Computers should be periodically checked to make sure they are successfully receiving and installing updates. Unsupported versions of Windows should not normally be used on the library network.

Third-Party Software Updates

Software other than Windows must also be kept updated. Examples include:

  • Web browsers such as Chrome, Edge, and Firefox
  • Microsoft Office
  • Adobe Acrobat and Adobe Reader
  • Zoom
  • Java
  • PDF software
  • Remote-access software
  • Other applications installed on library computers

Attackers frequently target vulnerabilities in common applications, not just Windows itself.

4. Firmware Updates

Security updates are also important for the hardware that operates the library network. Periodically check for security-related firmware updates for:

  • Firewalls
  • Network switches
  • Wireless access points
  • Routers
  • Servers
  • Desktop computers
  • Laptop computers
  • Printers and multifunction devices
  • Storage devices and backup appliances

Computer manufacturers may also release important:

  • BIOS updates
  • Firmware updates
  • Network adapter updates
  • Storage controller updates

Firmware should generally come directly from the equipment manufacturer or an approved management system.

5. Network Segmentation

Do not place every device in the library on the same network. At minimum, the network should separate staff systems from public systems.

Recommended network separation includes:

Staff Network

Staff computers and library business systems should operate on a network that is separated from patron/public computers.

Public Computer Network

Public-access computers should be isolated from staff computers and internal library resources. A compromised public computer should not provide an attacker with access to staff systems.

Public Wi-Fi

Public Wi-Fi should be separated from:

  • Staff computers
  • Staff Wi-Fi
  • Servers
  • Printers used for sensitive information
  • Library business systems

Staff Wi-Fi

Staff wireless devices should use a separate secured wireless network from public Wi-Fi.

HR and Financial Systems

If practical, computers used for sensitive functions should be further separated from normal staff computers. This may include:

  • Human Resources
  • Payroll
  • Accounting
  • Banking
  • Employee records

These computers contain information that could cause significantly greater harm if compromised.

6. Users Should Not Have Administrator Rights

Employees should normally have standard User Rights when using their computers, particularly while browsing the internet or reading email. Users should not routinely operate their computers using an administrator account.

Administrator credentials should only be used when required for tasks such as:

  • Installing approved software
  • Making system changes
  • Performing IT maintenance

Whenever possible, IT personnel should have separate accounts for:

  • Normal everyday computer use
  • Administrative functions

This reduces the amount of damage that malicious software can cause if a user account or web browser is compromised.

7. Passwords and Multi-Factor Authentication

Require strong passwords for library accounts. Employees should not reuse their library password for personal websites or other unrelated services.

Multi-factor authentication should be enabled whenever available, especially for:

  • Email
  • Microsoft 365 or Google Workspace
  • Administrative accounts
  • Cloud services
  • Remote-access systems
  • Firewall administration
  • Backup systems
  • Financial systems

MFA provides important additional protection if an employee's password is stolen.

Shared accounts should be avoided whenever possible. Each employee should have their own account so activity can be associated with the appropriate person.

8. Email and Phishing Protection

Email remains one of the most common ways attackers attempt to compromise an organization.

Employees should be trained to recognize:

  • Phishing emails
  • Fake password-expiration notices
  • Fake Microsoft login pages
  • Unexpected attachments
  • QR-code phishing
  • Fake invoices
  • Gift-card scams
  • Requests to change banking information
  • Messages impersonating library directors or other employees

Employees should know who to contact when they receive something suspicious. Staff should never approve an unexpected MFA request. Important financial or account-change requests should be verified through a second method, such as calling a known telephone number.

9. Backups

Important library information should be backed up regularly. Backups should include critical information necessary to restore library operations.

Whenever possible, maintain:

  • Local or onsite backups
  • A separate offsite or cloud backup
  • A backup that cannot easily be deleted or encrypted by ransomware

Backups should be monitored for failures. A successful backup should not simply be assumed. Libraries should periodically verify that files can actually be restored from backup.

10. Public Computers

Public computers should receive the same security attention as staff computers.

Public computers should:

  • Receive Windows security updates.
  • Receive browser and application updates.
  • Run supported antivirus/endpoint protection.
  • Prevent patrons from obtaining administrator privileges.
  • Be separated from the staff network.
  • Automatically remove or reset patron information when practical.
  • Avoid storing patron usernames, passwords, documents, or browsing information longer than necessary.

Libraries should consider software that restores public computers to a known configuration after use or reboot. USB devices and downloaded files should be treated as potentially unsafe.

11. Remote Access

Remote access to library systems should only be provided when necessary. Avoid exposing services such as Windows Remote Desktop directly to the public internet.

Remote access should preferably require:

  • A secure VPN or approved remote-access service
  • Individual user accounts
  • Strong passwords
  • Multi-factor authentication
  • Logging of remote connections

Old remote-access accounts should be removed when they are no longer needed. Third-party vendors should only have remote access when necessary.

12. Employee Account Management

Create an account for each employee who requires access to library systems.

When an employee leaves the library:

  • Disable their account promptly.
  • Remove remote-access privileges.
  • Remove VPN access.
  • Remove access to email and cloud systems.
  • Change any shared passwords they knew.
  • Recover library-owned devices.

Accounts that have not been used for an extended period should be reviewed. Administrative accounts should also be reviewed periodically.

13. Protect Sensitive Information

Libraries should identify computers and systems containing sensitive information. Examples may include:

  • Employee records
  • Payroll information
  • Tax information
  • Banking information
  • Patron information
  • Administrative credentials
  • Vendor credentials

Only employees who need this information to perform their jobs should have access to it. Sensitive information should not be retained longer than necessary.

14. Wi-Fi Security

Staff wireless networks should use modern encryption and strong passwords. Public and staff wireless networks should be separated. Default passwords on wireless access points should always be changed. Administrative interfaces for wireless equipment should not normally be accessible from the public Wi-Fi network. Guest wireless users should not be able to communicate directly with staff computers or internal servers.

15. Secure Network Equipment

Change all manufacturer default passwords on:

  • Firewalls
  • Switches
  • Wireless access points
  • Routers
  • Printers
  • Cameras
  • Servers
  • Storage devices
  • Other network-connected equipment

Administrative interfaces should only be accessible from trusted networks whenever practical. Devices that are no longer supported by their manufacturer should be scheduled for replacement.

16. Monitoring and Logging

Someone should periodically review the health and security of library systems.

Libraries should monitor, when possible:

  • Antivirus status
  • Failed software updates
  • Firewall alerts
  • Failed login attempts
  • Backup failures
  • Server health
  • Disk-space problems
  • Hardware failures
  • Unusual network activity

Alerts are only useful if someone is responsible for receiving and responding to them.

17. Physical Security

Cybersecurity also includes physical protection of equipment. Servers, firewalls, switches, backup equipment, and other critical infrastructure should be located in areas that are not accessible to the general public. Server rooms and network closets should be locked. Unused network ports in publicly accessible areas should be disabled when practical.

18. Security Awareness Training

Employees should receive basic cybersecurity awareness training.

At minimum, staff should understand:

  • How to recognize phishing.
  • Why passwords should not be shared.
  • Why MFA is important.
  • Why administrator accounts should not be used for normal work.
  • Why unexpected attachments and links can be dangerous.
  • How to report suspicious activity.
  • Who to contact if they believe their computer or account has been compromised.

Cybersecurity is not solely an IT responsibility. Employees are an important part of the library's security program.

19. Have a Basic Incident Response Plan

Every library should know what to do before a cybersecurity incident occurs.

At minimum, employees should know: Who do I call if something happens?

Examples of incidents include:

  • Ransomware message
  • Suspected virus
  • Stolen password
  • Compromised email account
  • Lost or stolen computer
  • Unexpected MFA requests
  • Suspicious financial transaction
  • Large number of computers suddenly malfunctioning

If ransomware or another serious compromise is suspected, employees should know how to quickly contact the person or organization responsible for IT security.

The library should maintain current contact information for:

  • Library management
  • IT support
  • Internet/network provider
  • Cybersecurity provider
  • Backup provider
  • Important software vendors

Library Security Basics — Minimum Checklist

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article