December 2025
Our cybersecurity teams continue to be on high alert following recent data breaches at universities across the country. We appreciate your help to immediately improve our security posture.
Please consider the following recommendations:
Remind your teams and customers, no one from Johns Hopkins will ever call or email you to ask for your password or multi-factor authentication (MFA) code. For more information on phishing and how to stay safe, visit our phishing prevention tips page.
Second, we recommend you review and update your multi-factor authentication (MFA) policies. These policies apply to how you log into websites and applications via your Johns Hopkins devices.
There are four MFA policies you can select from. To see your MFA policies:
If you are not yet enrolled in the first two policies, please do so by clicking the appropriate button. The third and fourth are helpful to elect if you are not traveling outside of the US. If you have any questions about MFA policies or need assistance enrolling in them, please contact [email protected].
We have established the Enterprise IT Application Inventory to document all applications across Johns Hopkins. If you have not yet worked with the cybersecurity team to provide your inventory, please email [email protected].
Review the Application and Data Security Checklist for a list of security controls you must consider for all your applications and data assets. The cybersecurity team will conduct training sessions with IT managers and directors in early 2026. In the meantime, these are the things you can do immediately:
We know some of these requests may not apply to everyone, but we very much appreciate your continued assistance with improving our security posture.