You are obligated to report a security breach even if personal data is not invelved to your local IT-support or AU's Information Security Unit.
This procedure describes how reported security breaches that does not involve personal data are managed by Aarhus University:
Security breaches are reported to the local IT support team or to AU’s information security unit, but the incident will be set up and processed as a case in Cherwell (AU’s IT service management system).
Phising incidents are reported via the ‘report message’ (Rapportér meddelelse) button in Outlook, here is how you rapport phishing-mail.
The assigned unit is responsible for the incident. If the incident is assigned to a different unit according to type, content and solution of the incident, then the resposibility goes with.
The Information Security Unit gathers information regaring security breaches to ensure learning for recommending further appropiate measures organisational or technical to improve the university's level of security.
Is there personal data involved?
If there is personal data involved in the breach, please fill out this form.
A security breach is, e.g.
If criminal acts are suspected with an information security breach, the incident must always be reported to the police.