Libraries rely heavily on computers, networks, internet access, email, and cloud-based services to serve their communities. Even a small library should maintain a basic cybersecurity program to protect staff, patrons, library data, and computer systems.
The following practices provide a basic security foundation for public libraries.
1. Firewall Protection
Every library should have a business-class firewall protecting its internet connection.
The firewall should:
- Have an active software/security subscription so it continues receiving security updates and threat-protection updates.
- Be kept on a currently supported firmware version.
- Block unnecessary inbound internet connections.
- Only allow remote access when it is specifically required.
- Have administrative access protected with strong passwords and, when available, multi-factor authentication (MFA).
- Have its configuration backed up periodically.
A firewall should not simply be installed and forgotten. It needs to remain licensed, updated, monitored, and supported.
2. Antivirus and Endpoint Security
All library-owned Windows computers and servers should have active antivirus or endpoint security software.
This includes:
- Staff computers
- Public computers
- Laptops
- Servers
- Administrative computers
Antivirus software should:
- Update automatically.
- Provide real-time protection.
- Perform regular scans.
- Report infections or security problems.
- Be periodically checked to make sure it is actually running.
Having antivirus installed is not enough if it has expired, is disabled, or is no longer receiving updates.
3. Active Patch Management
Libraries should have an active patch-management process rather than relying entirely on individual employees to update their computers. Someone should be responsible for verifying that updates are installed.
At minimum, patch management should include:
Microsoft Windows Updates
Windows security updates should be installed monthly and critical security updates should be addressed promptly. Computers should be periodically checked to make sure they are successfully receiving and installing updates. Unsupported versions of Windows should not normally be used on the library network.
Third-Party Software Updates
Software other than Windows must also be kept updated. Examples include:
- Web browsers such as Chrome, Edge, and Firefox
- Microsoft Office
- Adobe Acrobat and Adobe Reader
- Zoom
- Java
- PDF software
- Remote-access software
- Other applications installed on library computers
Attackers frequently target vulnerabilities in common applications, not just Windows itself.
4. Firmware Updates
Security updates are also important for the hardware that operates the library network. Periodically check for security-related firmware updates for:
- Firewalls
- Network switches
- Wireless access points
- Routers
- Servers
- Desktop computers
- Laptop computers
- Printers and multifunction devices
- Storage devices and backup appliances
Computer manufacturers may also release important:
- BIOS updates
- Firmware updates
- Network adapter updates
- Storage controller updates
Firmware should generally come directly from the equipment manufacturer or an approved management system.
5. Network Segmentation
Do not place every device in the library on the same network. At minimum, the network should separate staff systems from public systems.
Recommended network separation includes:
Staff Network
Staff computers and library business systems should operate on a network that is separated from patron/public computers.
Public Computer Network
Public-access computers should be isolated from staff computers and internal library resources. A compromised public computer should not provide an attacker with access to staff systems.
Public Wi-Fi
Public Wi-Fi should be separated from:
- Staff computers
- Staff Wi-Fi
- Servers
- Printers used for sensitive information
- Library business systems
Staff Wi-Fi
Staff wireless devices should use a separate secured wireless network from public Wi-Fi.
HR and Financial Systems
If practical, computers used for sensitive functions should be further separated from normal staff computers. This may include:
- Human Resources
- Payroll
- Accounting
- Banking
- Employee records
These computers contain information that could cause significantly greater harm if compromised.
6. Users Should Not Have Administrator Rights
Employees should normally have standard User Rights when using their computers, particularly while browsing the internet or reading email. Users should not routinely operate their computers using an administrator account.
Administrator credentials should only be used when required for tasks such as:
- Installing approved software
- Making system changes
- Performing IT maintenance
Whenever possible, IT personnel should have separate accounts for:
- Normal everyday computer use
- Administrative functions
This reduces the amount of damage that malicious software can cause if a user account or web browser is compromised.
7. Passwords and Multi-Factor Authentication
Require strong passwords for library accounts. Employees should not reuse their library password for personal websites or other unrelated services.
Multi-factor authentication should be enabled whenever available, especially for:
- Microsoft 365 or Google Workspace
- Administrative accounts
- Cloud services
- Remote-access systems
- Firewall administration
- Backup systems
- Financial systems
MFA provides important additional protection if an employee's password is stolen.
Shared accounts should be avoided whenever possible. Each employee should have their own account so activity can be associated with the appropriate person.
8. Email and Phishing Protection
Email remains one of the most common ways attackers attempt to compromise an organization.
Employees should be trained to recognize:
- Phishing emails
- Fake password-expiration notices
- Fake Microsoft login pages
- Unexpected attachments
- QR-code phishing
- Fake invoices
- Gift-card scams
- Requests to change banking information
- Messages impersonating library directors or other employees
Employees should know who to contact when they receive something suspicious. Staff should never approve an unexpected MFA request. Important financial or account-change requests should be verified through a second method, such as calling a known telephone number.
9. Backups
Important library information should be backed up regularly. Backups should include critical information necessary to restore library operations.
Whenever possible, maintain:
- Local or onsite backups
- A separate offsite or cloud backup
- A backup that cannot easily be deleted or encrypted by ransomware
Backups should be monitored for failures. A successful backup should not simply be assumed. Libraries should periodically verify that files can actually be restored from backup.
10. Public Computers
Public computers should receive the same security attention as staff computers.
Public computers should:
- Receive Windows security updates.
- Receive browser and application updates.
- Run supported antivirus/endpoint protection.
- Prevent patrons from obtaining administrator privileges.
- Be separated from the staff network.
- Automatically remove or reset patron information when practical.
- Avoid storing patron usernames, passwords, documents, or browsing information longer than necessary.
Libraries should consider software that restores public computers to a known configuration after use or reboot. USB devices and downloaded files should be treated as potentially unsafe.
11. Remote Access
Remote access to library systems should only be provided when necessary. Avoid exposing services such as Windows Remote Desktop directly to the public internet.
Remote access should preferably require:
- A secure VPN or approved remote-access service
- Individual user accounts
- Strong passwords
- Multi-factor authentication
- Logging of remote connections
Old remote-access accounts should be removed when they are no longer needed. Third-party vendors should only have remote access when necessary.
12. Employee Account Management
Create an account for each employee who requires access to library systems.
When an employee leaves the library:
- Disable their account promptly.
- Remove remote-access privileges.
- Remove VPN access.
- Remove access to email and cloud systems.
- Change any shared passwords they knew.
- Recover library-owned devices.
Accounts that have not been used for an extended period should be reviewed. Administrative accounts should also be reviewed periodically.
13. Protect Sensitive Information
Libraries should identify computers and systems containing sensitive information. Examples may include:
- Employee records
- Payroll information
- Tax information
- Banking information
- Patron information
- Administrative credentials
- Vendor credentials
Only employees who need this information to perform their jobs should have access to it. Sensitive information should not be retained longer than necessary.
14. Wi-Fi Security
Staff wireless networks should use modern encryption and strong passwords. Public and staff wireless networks should be separated. Default passwords on wireless access points should always be changed. Administrative interfaces for wireless equipment should not normally be accessible from the public Wi-Fi network. Guest wireless users should not be able to communicate directly with staff computers or internal servers.
15. Secure Network Equipment
Change all manufacturer default passwords on:
- Firewalls
- Switches
- Wireless access points
- Routers
- Printers
- Cameras
- Servers
- Storage devices
- Other network-connected equipment
Administrative interfaces should only be accessible from trusted networks whenever practical. Devices that are no longer supported by their manufacturer should be scheduled for replacement.
16. Monitoring and Logging
Someone should periodically review the health and security of library systems.
Libraries should monitor, when possible:
- Antivirus status
- Failed software updates
- Firewall alerts
- Failed login attempts
- Backup failures
- Server health
- Disk-space problems
- Hardware failures
- Unusual network activity
Alerts are only useful if someone is responsible for receiving and responding to them.
17. Physical Security
Cybersecurity also includes physical protection of equipment. Servers, firewalls, switches, backup equipment, and other critical infrastructure should be located in areas that are not accessible to the general public. Server rooms and network closets should be locked. Unused network ports in publicly accessible areas should be disabled when practical.
18. Security Awareness Training
Employees should receive basic cybersecurity awareness training.
At minimum, staff should understand:
- How to recognize phishing.
- Why passwords should not be shared.
- Why MFA is important.
- Why administrator accounts should not be used for normal work.
- Why unexpected attachments and links can be dangerous.
- How to report suspicious activity.
- Who to contact if they believe their computer or account has been compromised.
Cybersecurity is not solely an IT responsibility. Employees are an important part of the library's security program.
19. Have a Basic Incident Response Plan
Every library should know what to do before a cybersecurity incident occurs.
At minimum, employees should know: Who do I call if something happens?
Examples of incidents include:
- Ransomware message
- Suspected virus
- Stolen password
- Compromised email account
- Lost or stolen computer
- Unexpected MFA requests
- Suspicious financial transaction
- Large number of computers suddenly malfunctioning
If ransomware or another serious compromise is suspected, employees should know how to quickly contact the person or organization responsible for IT security.
The library should maintain current contact information for:
- Library management
- IT support
- Internet/network provider
- Cybersecurity provider
- Backup provider
- Important software vendors
Library Security Basics — Minimum Checklist
Every library should be able to answer YES to these questions:
| Assessment Question | YES | NO | Notes / Action Items |
|---|---|---|---|
| Do we have a supported firewall with an active security/software subscription? | |||
| Is antivirus or endpoint protection installed and active on our computers? | |||
| Are Windows security updates installed every month? | |||
| Are browsers, Office, Adobe, and other applications regularly updated? | |||
| Do we install important firmware and security updates on computers and network equipment? | |||
| Are staff computers separated from public computers? | |||
| Is public Wi-Fi separated from staff Wi-Fi and the staff network? | |||
| Are HR, payroll, banking, and other sensitive systems protected from unnecessary access? | |||
| Do employees normally use standard User Rights instead of Administrator Rights? | |||
| Do we use multi-factor authentication where available? | |||
| Are employees trained to recognize phishing? | |||
| Do we have reliable backups? | |||
| Have we verified that information can actually be restored from our backups? | |||
| Is remote access protected by VPN or another secure remote-access system? | |||
| Are accounts promptly disabled when employees leave? | |||
| Have default passwords been changed on network equipment? | |||
| Are servers and network equipment physically secured? | |||
| Does someone monitor antivirus, backups, updates, and security alerts? | |||
| Does everyone know who to contact if they suspect a cybersecurity incident? |