[SEO-Updates] Library Cybersecurity Best Practices 101
dwinland at library.ohio.gov
dwinland at library.ohio.gov
Fri Aug 28 08:33:19 EDT 2026
This is a basic Security 101 document that will apply to most libraries. It covers many of the core components of a secure computer network, along with common cybersecurity terminology and practices.
The document includes 19 fundamental security practices that every library should review as part of its overall cybersecurity program.
You can also find this information on the SEO website here:
Library Cybersecurity Best Practices 101 : SEO Service Center<https://support.servingeveryohioan.org/support/solutions/articles/69000882025-library-cybersecurity-best-practices-101>
Please feel free to reach out to us if you have questions or would like a better understanding of any of the concepts covered in this document.
The document includes a 19-question security assessment.
If you answer NO or I Don’t Know to any of these questions, that would be a good area to discuss with your IT staff.
You are also welcome to contact SEO to discuss the security concepts involved and whether they apply to your library.
___________________________________________________
Library Security Basics — Minimum Checklist
Every library should be able to answer YES to these questions:
Assessment Question
YES
NO
Notes / Action Items
Do we have a supported firewall with an active security/software subscription?
Is antivirus or endpoint protection installed and active on our computers?
Are Windows security updates installed every month?
Are browsers, Office, Adobe, and other applications regularly updated?
Do we install important firmware and security updates on computers and network equipment?
Are staff computers separated from public computers?
Is public Wi-Fi separated from staff Wi-Fi and the staff network?
Are HR, payroll, banking, and other sensitive systems protected from unnecessary access?
Do employees normally use standard User Rights instead of Administrator Rights?
Do we use multi-factor authentication where available?
Are employees trained to recognize phishing?
Do we have reliable backups?
Have we verified that information can actually be restored from our backups?
Is remote access protected by VPN or another secure remote-access system?
Are accounts promptly disabled when employees leave?
Have default passwords been changed on network equipment?
Are servers and network equipment physically secured?
Does someone monitor antivirus, backups, updates, and security alerts?
Does everyone know who to contact if they suspect a cybersecurity incident?
Cybersecurity does not depend on any single product or setting. It works best when several basic protections are in place and maintained consistently. This checklist is intended to help libraries identify areas that may need additional attention before they become security problems.
1. Firewall Protection
Every library should have a business-class firewall protecting its internet connection.
The firewall should:
* Have an active software/security subscription so it continues receiving security updates and threat-protection updates.
* Be kept on a currently supported firmware version.
* Block unnecessary inbound internet connections.
* Only allow remote access when it is specifically required.
* Have administrative access protected with strong passwords and, when available, multi-factor authentication (MFA).
* Have its configuration backed up periodically.
A firewall should not simply be installed and forgotten. It needs to remain licensed, updated, monitored, and supported.
2. Antivirus and Endpoint Security
All library-owned Windows computers and servers should have active antivirus or endpoint security software.
This includes:
* Staff computers
* Public computers
* Laptops
* Servers
* Administrative computers
Antivirus software should:
* Update automatically.
* Provide real-time protection.
* Perform regular scans.
* Report infections or security problems.
* Be periodically checked to make sure it is actually running.
Having antivirus installed is not enough if it has expired, is disabled, or is no longer receiving updates.
3. Active Patch Management
Libraries should have an active patch-management process rather than relying entirely on individual employees to update their computers. Someone should be responsible for verifying that updates are installed.
At minimum, patch management should include:
Microsoft Windows Updates
Windows security updates should be installed monthly and critical security updates should be addressed promptly. Computers should be periodically checked to make sure they are successfully receiving and installing updates. Unsupported versions of Windows should not normally be used on the library network.
Third-Party Software Updates
Software other than Windows must also be kept updated. Examples include:
* Web browsers such as Chrome, Edge, and Firefox
* Microsoft Office
* Adobe Acrobat and Adobe Reader
* Zoom
* Java
* PDF software
* Remote-access software
* Other applications installed on library computers
Attackers frequently target vulnerabilities in common applications, not just Windows itself.
4. Firmware Updates
Security updates are also important for the hardware that operates the library network. Periodically check for security-related firmware updates for:
* Firewalls
* Network switches
* Wireless access points
* Routers
* Servers
* Desktop computers
* Laptop computers
* Printers and multifunction devices
* Storage devices and backup appliances
Computer manufacturers may also release important:
* BIOS updates
* Firmware updates
* Network adapter updates
* Storage controller updates
Firmware should generally come directly from the equipment manufacturer or an approved management system.
5. Network Segmentation
Do not place every device in the library on the same network. At minimum, the network should separate staff systems from public systems.
Recommended network separation includes:
Staff Network
Staff computers and library business systems should operate on a network that is separated from patron/public computers.
Public Computer Network
Public-access computers should be isolated from staff computers and internal library resources. A compromised public computer should not provide an attacker with access to staff systems.
Public Wi-Fi
Public Wi-Fi should be separated from:
* Staff computers
* Staff Wi-Fi
* Servers
* Printers used for sensitive information
* Library business systems
Staff Wi-Fi
Staff wireless devices should use a separate secured wireless network from public Wi-Fi.
HR and Financial Systems
If practical, computers used for sensitive functions should be further separated from normal staff computers. This may include:
* Human Resources
* Payroll
* Accounting
* Banking
* Employee records
These computers contain information that could cause significantly greater harm if compromised.
6. Users Should Not Have Administrator Rights
Employees should normally have standard User Rights when using their computers, particularly while browsing the internet or reading email. Users should not routinely operate their computers using an administrator account.
Administrator credentials should only be used when required for tasks such as:
* Installing approved software
* Making system changes
* Performing IT maintenance
Whenever possible, IT personnel should have separate accounts for:
* Normal everyday computer use
* Administrative functions
This reduces the amount of damage that malicious software can cause if a user account or web browser is compromised.
7. Passwords and Multi-Factor Authentication
Require strong passwords for library accounts. Employees should not reuse their library password for personal websites or other unrelated services.
Multi-factor authentication should be enabled whenever available, especially for:
* Email
* Microsoft 365 or Google Workspace
* Administrative accounts
* Cloud services
* Remote-access systems
* Firewall administration
* Backup systems
* Financial systems
MFA provides important additional protection if an employee's password is stolen.
Shared accounts should be avoided whenever possible. Each employee should have their own account so activity can be associated with the appropriate person.
8. Email and Phishing Protection
Email remains one of the most common ways attackers attempt to compromise an organization.
Employees should be trained to recognize:
* Phishing emails
* Fake password-expiration notices
* Fake Microsoft login pages
* Unexpected attachments
* QR-code phishing
* Fake invoices
* Gift-card scams
* Requests to change banking information
* Messages impersonating library directors or other employees
Employees should know who to contact when they receive something suspicious. Staff should never approve an unexpected MFA request. Important financial or account-change requests should be verified through a second method, such as calling a known telephone number.
9. Backups
Important library information should be backed up regularly. Backups should include critical information necessary to restore library operations.
Whenever possible, maintain:
* Local or onsite backups
* A separate offsite or cloud backup
* A backup that cannot easily be deleted or encrypted by ransomware
Backups should be monitored for failures. A successful backup should not simply be assumed. Libraries should periodically verify that files can actually be restored from backup.
10. Public Computers
Public computers should receive the same security attention as staff computers.
Public computers should:
* Receive Windows security updates.
* Receive browser and application updates.
* Run supported antivirus/endpoint protection.
* Prevent patrons from obtaining administrator privileges.
* Be separated from the staff network.
* Automatically remove or reset patron information when practical.
* Avoid storing patron usernames, passwords, documents, or browsing information longer than necessary.
Libraries should consider software that restores public computers to a known configuration after use or reboot. USB devices and downloaded files should be treated as potentially unsafe.
11. Remote Access
Remote access to library systems should only be provided when necessary. Avoid exposing services such as Windows Remote Desktop directly to the public internet.
Remote access should preferably require:
* A secure VPN or approved remote-access service
* Individual user accounts
* Strong passwords
* Multi-factor authentication
* Logging of remote connections
Old remote-access accounts should be removed when they are no longer needed. Third-party vendors should only have remote access when necessary.
12. Employee Account Management
Create an account for each employee who requires access to library systems.
When an employee leaves the library:
* Disable their account promptly.
* Remove remote-access privileges.
* Remove VPN access.
* Remove access to email and cloud systems.
* Change any shared passwords they knew.
* Recover library-owned devices.
Accounts that have not been used for an extended period should be reviewed. Administrative accounts should also be reviewed periodically.
13. Protect Sensitive Information
Libraries should identify computers and systems containing sensitive information. Examples may include:
* Employee records
* Payroll information
* Tax information
* Banking information
* Patron information
* Administrative credentials
* Vendor credentials
Only employees who need this information to perform their jobs should have access to it. Sensitive information should not be retained longer than necessary.
14. Wi-Fi Security
Staff wireless networks should use modern encryption and strong passwords. Public and staff wireless networks should be separated. Default passwords on wireless access points should always be changed. Administrative interfaces for wireless equipment should not normally be accessible from the public Wi-Fi network. Guest wireless users should not be able to communicate directly with staff computers or internal servers.
15. Secure Network Equipment
Change all manufacturer default passwords on:
* Firewalls
* Switches
* Wireless access points
* Routers
* Printers
* Cameras
* Servers
* Storage devices
* Other network-connected equipment
Administrative interfaces should only be accessible from trusted networks whenever practical. Devices that are no longer supported by their manufacturer should be scheduled for replacement.
16. Monitoring and Logging
Someone should periodically review the health and security of library systems.
Libraries should monitor, when possible:
* Antivirus status
* Failed software updates
* Firewall alerts
* Failed login attempts
* Backup failures
* Server health
* Disk-space problems
* Hardware failures
* Unusual network activity
Alerts are only useful if someone is responsible for receiving and responding to them.
17. Physical Security
Cybersecurity also includes physical protection of equipment. Servers, firewalls, switches, backup equipment, and other critical infrastructure should be located in areas that are not accessible to the general public. Server rooms and network closets should be locked. Unused network ports in publicly accessible areas should be disabled when practical.
18. Security Awareness Training
Employees should receive basic cybersecurity awareness training.
At minimum, staff should understand:
* How to recognize phishing.
* Why passwords should not be shared.
* Why MFA is important.
* Why administrator accounts should not be used for normal work.
* Why unexpected attachments and links can be dangerous.
* How to report suspicious activity.
* Who to contact if they believe their computer or account has been compromised.
Cybersecurity is not solely an IT responsibility. Employees are an important part of the library's security program.
19. Have a Basic Incident Response Plan
Every library should know what to do before a cybersecurity incident occurs.
At minimum, employees should know: Who do I call if something happens?
Examples of incidents include:
* Ransomware message
* Suspected virus
* Stolen password
* Compromised email account
* Lost or stolen computer
* Unexpected MFA requests
* Suspicious financial transaction
* Large number of computers suddenly malfunctioning
If ransomware or another serious compromise is suspected, employees should know how to quickly contact the person or organization responsible for IT security.
The library should maintain current contact information for:
* Library management
* IT support
* Internet/network provider
* Cybersecurity provider
* Backup provider
* Important software vendors
-------------------------
Let us know if you have any questions
[cid:d68e7129-077b-456f-90ac-3298eca1a932]
Donald M Winland Jr
Infrastructure & Security Specialist II
CISSP<https://www.youracclaim.com/badges/646728e0-086e-4371-a903-7e12be452454/public_url>, CEH, CCNA, MCSA, MCSE, NETWORK+, A+
State Library of Ohio
SEO Service Center
40780 Marietta Rd.
P.O. Box 185
Caldwell, OH 43724
Phone: 1-877-552-4262 x205
Email:dwinland<mailto:dwinland at library.ohio.gov>@library.ohio.gov<mailto:dwinland at library.ohio.gov>
https://servingeveryohioan.org/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.oplin.org/pipermail/seo-updates/attachments/20260828/863cd876/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Outlook-3a5zh0ka.png
Type: image/png
Size: 39108 bytes
Desc: Outlook-3a5zh0ka.png
URL: <http://lists.oplin.org/pipermail/seo-updates/attachments/20260828/863cd876/attachment.png>
More information about the SEO-Updates
mailing list