Sicherheitsvorfall melden
Report a security incident
What is an IT security incident?
An IT security incident is defined as an undesirable event (or a combination of several events) that compromises the confidentiality, availability, and integrity of information, business processes, IT services, IT systems, or IT applications to such an extent that significant damage may result. IT security incidents are typically characterized by the negative actions of third parties with criminal intent. Handling IT security incidents generally requires a comprehensive approach.
In the case of an IT security incident, the focus is usually on the information stored on the system rather than on the system itself. It is irrelevant whether the IT security incident has already caused an undesirable outcome or impact, or merely has the potential to cause damage.
Have you noticed an incident? Reporting it is more important than staying silent. Reporting it quickly helps limit the damage.
Follow these steps:
1. STAY CALM
- Do not take any countermeasures on your own.
- Immediately disconnect the computer from the network (e.g., disable Wi-Fi).
- In consultation with the sic, a scan with antivirus software can be performed if necessary.
- Notify your team, your supervisor or your IT representative.
2. REPORT
Immediately send an alert to the central contact point sic.
The following information is helpful:
- Who is reporting the incident?
- When did the incident occur?
- What happened?
- Which system is affected?
- Where is the affected system located? (Building, room, workstation)
Optionally, you can use our Online registration form (available only after logging in) for an IT security-related incident. Here, you also have the option to submit a quick report if you are unable to fully answer all questions on the report form at this time. Additional information can be submitted at any time to IT-Sicherheit@tu-dortmund.de.
WHAT YOU MUST NOT DO
- Attempt to “fix” the problem yourself – you could destroy evidence.
- Speak to the press or external parties – our PR department will handle communications.
Please follow our security guidelines for self-help under Dealing with Spam emails.
Always forward suspicious emails related to TU Dortmund as the original message in an attachment to
alarm.sic@tu-dortmund.de
If, in the case of a suspicious email,
- you clicked on a link and/or entered your login credentials, or
- opened an attachment,
please take immediate action.
Disconnect your device from the network (unplug the network cable, enable airplane mode).
In case 1, change your login credentials immediately from another computer.
In cases 1 and 2, have your device checked for possible malware infections.
Contact your IT respresentative (available only after logging in) or the Security Information Center sic (available only after logging in) to coordinate the next steps.
Confidentiality refers to protection against the unauthorized disclosure of information. Confidential data and information may only be accessible to authorized individuals in the permitted manner.
Integrity refers to ensuring the correctness (integrity) of data and the proper functioning of systems. When the term “integrity” is applied to “data,” it means that the data is complete and unaltered.
The availability of services, functions of an IT system, IT applications, or IT networks—or even of information—is ensured when users can always use them as intended.
Reporting procedures for potential threats and security incidents ensure a rapid response and are designed to minimize potential damage through immediate action. The Reporting procedures (German) describes the steps and responsibilities involved in reporting security incidents.
The Security Incident Reporting Card contains key contact information and brief instructions on what to do if you need to report a security incident. We recommend that you print out the card and keep it in a visible and easily accessible place at your workstation.
Download security incident reporting form (PDF, German)