FY2026 Accomplishments

Expanding Privacy Awareness Programming
In FY26, the ITS Office of Privacy remained focused on education and outreach for the U-M community and the public. The 2026 Privacy@Michigan event series, co-sponsored with the School of Information, ran from January 28 through late March. The five speaker events featured academics, artists, activists and community organizers, litigators, authors, and leaders sharing their unique perspectives on pressing issues at the intersection of privacy, surveillance, technology, civil liberties and human rights.
Throughout the academic year, the office collaborated with students on new programming and exciting initiatives:
- Engagement toolkit for resident advisors, which was piloted at North Quad in April and is set for broader adoption in the fall.
- A concept for a privacy game app for pre-teen kids that is set to transition to development by summer interns.
We further expanded outreach to students by hosting an inaugural art contest: Unveil. The contest culminated with a celebration on March 27 of the winning artists and an exhibition of their works as they explored privacy, surveillance, civil liberties, and individual rights through literary and visual arts. Winners came from a wide variety of academic disciplines. Families, friends, and members of the U-M arts community attended the event (featured in the “Michigan Daily”). The Unveil Winners Gallery on Safe Computing showcases the winning artworks.
Helping Units Meet Compliance and Reduce Risk
The Information Assurance (IA) Responsive Information Security for Campus (RISC) team is committed to safeguarding information security and achieving regulatory compliance. RISC team members also serve as liaisons to U-M departments, assisting with security consulting, vendor and contract reviews, and risk remediation. In FY26, IA performed detailed risk assessments to help Inter-university Consortium for Political and Social Research (ICPSR) and other units to achieve an Authority to Operate (ATO) from relevant federal agencies. ICPSR hosts government information which requires compliance with the Federal Information Security Management Act (FISMA).
The IA team also helps units identify appropriate mitigations if they don’t meet regulatory requirements. For example, they worked closely with various Dentistry teams post-audit to mitigate findings for multiple systems. IA provided Dentistry with their risk assessment findings, helped them understand what needed to be addressed, and connected them with relevant resources.
In addition to their ongoing work with various units to help form and draft CUI-related programs and tasks, IA is spearheading AI compliance across the university through solutions being proposed by faculty, staff, and students to ensure university and student data is not misused or profited from.
Risk Management FY26 program metrics
- 45 Risk Assessments
- 20 completed
- 15 in progress
- 6 not started
- 4 under review by compliance partners (i.e., HIPAA-related reviews may require approval from Michigan Medicine Corporate Compliance)
- 313 risk registry items closed
- 127 additional risks identified and added
Maintaining a Credible, Implementable, Enforceable, and Sustainable IT Policy Environment
Several university policies and IT standards in FY26 were released by the Office of Privacy and Information Assurance:
- Institutional Data Stewardship Policy (SPG 601.12): Revised in August 2025 to reflect changes to technology and the U-M Data Governance Framework.
- Information Security Incident Reporting (SPG 601.25): Updated in August 2025 to make it clearer and more concise.
- Information Assurance Awareness, Training, and Education (DS-16): Updated in October 2025 to clarify annual training requirements for faculty, staff, and workforce members.
- Endpoint Security Administration (DS-23): Updated in November 2025 to include a requirement for information security support.
- Personally Owned Devices that Access or Maintain Sensitive Institutional Data (SPG 601.33): Updated in early 2026 to adjust the definition of sensitive university data in alignment with Institutional Data Stewardship Policy (SPG 601.12) and the university data classification levels.
- DS-21 Data Standard: Updated to make vulnerability reporting and remediation more manageable by prioritizing the most critical issues.
Providing Effective and Engaging Training Courses
In FY26, the ITS Office of Privacy team developed a new Information Assurance-driven cybersecurity and data protection training course for university faculty and staff. The training course, DCE 101: Cybersecurity and Data Protection at U-M, is designed to help every member of our campus community recognize evolving threats and strengthen their daily security habits. Today’s cyber threats are increasingly sophisticated, and incidents have the potential to disrupt teaching, research, university operations, and even personal privacy. The training underscores U-M’s commitment to safeguarding sensitive information and supporting uninterrupted academic and operational excellence.
- “This is one of the best-designed information security courses I have ever been required to complete.”
- “This was well designed and to-the-point, thanks for creating such a short and straightforward overview of data security for staff!”
DCE 101 empowers U-M employees to recognize risks early, respond effectively, and uphold the university's reputation as a leader in research, teaching, and stewardship of data.
The Office of Privacy also launched new courses for those with specific data protection responsibilities at the university:
- For Security Unit Liaisons — a new series of four self-directed, modular short training courses that provide key information and guidance about performing the SUL Role and Responsibilities at U-M.
- For Data Stewards and Custodians — a new “Introduction to Data Stewardship at U-M” course covering U-M’s data governance program, the data stewardship framework, and the roles and responsibilities of Data Stewards and Custodians.
- For faculty and staff who work with Protected Health Information (PHI) — a new, streamlined “HIPAA and Protected Health Information” course.
The team also refreshed the quiz-style Safe Computing challenge for students with updated, real-world scenarios featuring pithy tips and fun graphics to promote engagement. The students had positive feedback on the new experience:
- “I think the scenarios were very relevant (especially the football tickets and job offers) and I liked the animal puns :)”
- “I thought that it did a really good job of explaining all of the ways to prevent being hacked or being scammed. I am now much more informed about device security and will use all of these tips in the future.”
- “I really liked how the information and tips provided are relevant to common scam and issues students run into, especially when new to the university.”
Expanding security visibility into cloud, containers, and web
In FY26, IA paired Tenable web application scanning with an internally developed tool called Web Store. Web Store helps identify web servers across U-M campuses and cloud environments by using DNS data, scanning common web ports, and collecting HTTP responses. The process allows IA to:
- Identify where web servers are running across millions of IP addresses.
- Narrow the scope quickly to a much smaller number of active web servers.
- Determine which technologies are likely running based on HTTP headers and response content.
- Identify where a vulnerable technology may be present.
- Use web application scanning to verify whether systems have been fixed.
Without this system, identifying affected systems during a zero-day event could take days. With Web Store and scanning, IA can often reduce that work to roughly an hour.
Tenable also empowers units to conduct and manage their own scans, streamlining the process and reducing wait times for results. Web application scans help units meet their responsibilities for secure coding and vulnerability management. Web application scans are part of a larger toolkit of scanning capabilities that IA provides, which include network vulnerability scans and penetration tests.
The on-premises Splunk environment, including the existing data, was migrated to Splunk Cloud in FY26. This allowed IA to increase its ability to analyze and consume security logs from 1 terabyte per day to 1.5 terabytes per day. Moving to Splunk Cloud also reduced the physical footprint of campus machines by more than 50%.
