Monitoring Privacy and Security Incident Reporting
The University respects appropriate privacy while retaining responsibility to operate, secure, maintain, support, investigate, and comply with legal obligations involving University systems. Users should not expect activity conducted through University systems, University networks, or University-owned devices to be completely private.
Authorized personnel may access, review, preserve, disclose, or monitor accounts, devices, communications, files, logs, network traffic, and system activity when reasonably necessary for cybersecurity, system administration, support, fraud prevention, backup, recovery, continuity, records management, audit, legal compliance, authorized investigations, or protection of people, property, and University operations. Access and monitoring must be limited to legitimate University purposes and information must be shared only with persons who have a legitimate need to know.
Actual or suspected security incidents must be reported promptly to helpdesk@buf.edu or through another method published by the Information Technology Department. Report unexpected MFA prompts, suspected password theft, phishing, malware, unauthorized access, accidental disclosure, lost or stolen devices containing University information, outages, equipment damage, and unusual conditions affecting campus infrastructure. Users must preserve relevant information and cooperate with authorized responders.
The University may immediately reset credentials, revoke sessions, disable accounts, isolate devices, block traffic, preserve records, restrict access, or temporarily interrupt services when reasonably necessary to protect people, information, evidence, systems, or University operations.