Beyond Regulated Data: Preparing for NSPM-33 Research Cybersecurity Requirements

Thursday, October 01, 2026 | 1:00PM–1:45PM MT
Session Type: Breakout Session
Delivery Format: Presentation
Research cybersecurity requirements under NSPM-33 are being finalized, and covered institutions will have limited time to respond once final expectations are in place. For higher education leaders, that makes advance planning essential. This session explains why NSPM-33 research cybersecurity should be treated as an institutional challenge, not just a technical or compliance issue. Unlike many research compliance regimes, these requirements are not primarily scoped by a specific regulated data type. Instead, they are tied to federally funded research at covered institutions, which has important implications for institutional governance, shared services, and research-supporting infrastructure. That broader scope may reach beyond traditionally regulated projects into open science and other federally funded research environments that have not historically operated under this kind of cybersecurity requirement. Participants will get a concise overview of the policy background, the current status of the requirements, and practical guidance for institutional readiness. The session will help leaders assess whether their institution is likely to be in scope, understand where impact may fall across the research enterprise, and identify concrete steps they can take now to prepare. The focus throughout will be on building a research cybersecurity program that supports researchers, strengthens institutional readiness, and helps the research mission move forward safely.

Presenters

  • Tim Daniel

    Security Information Analyst, Indiana University
  • Will Drake

    Principal Security Analyst, Indiana University