2026 Cybersecurity Awareness Month: 5 questions to ask before sharing university data with a third-party app

The University of Utah is a 2026 Cybersecurity Awareness Month Champion.
A new app promises to summarize meetings, organize calendars, move files, or connect information between systems. Setup may appear to be as simple as clicking “Allow.” But that one click can give a third-party continuing access to email, calendars, meeting content, contacts, files, or other university information.
The correct response is not to reject every new tool. Useful applications and integrations support teaching, research, healthcare, and university operations every day. The goal is to pause before granting access, define the need and requested permissions, and route the request through the appropriate institutional review process so the university can make an informed decision.
The National Cybersecurity Alliance’s 2026 Cybersecurity Awareness Month theme, “Don’t Make It Easy for Them,” emphasizes that online safety comes from small habits repeated consistently. One valuable habit that University of Utah users can implement is asking themselves the five questions below before using a third-party application.
Learn more
October is Cybersecurity Awareness Month. For more information about the initiative and the university's IT security policies, rules, and more, please use the links below.
1. What problem does the app solve?
Start by describing the app’s intended use in one clear sentence. Who needs the application, what work will it support, and what information does it need to perform that work? A specific use case helps the requester and university reviewers distinguish necessary capabilities from optional features and determine whether an existing university-supported tool meets the need.
A clear purpose also defines the boundaries of the request. An app that’s useful to one person does not automatically mean it should be enabled for a department or across an entire platform. In some instances, a limited pilot can test the value of a tool without immediately creating broad access.
2. What permissions does the app want?
Permission requests describe what an app may be able to see or do. Depending on the integration, an app might request the ability to read files, modify calendar events, access meeting information, send messages, or continue accessing information after the initial setup is complete.
Read access is not the same as harmless access. Reading a mailbox, meeting transcript, or shared folder may expose sensitive information even when the app cannot change it. Likewise, write access can allow an app to create, alter, or delete content. The permissions should make sense for the stated purpose, and the requester should be able to explain that connection in plain language.
3. What university data could the app reach?
Consider more than the files someone intends to upload. An integration may reach information already present in email, calendars, cloud storage, collaboration sites, meetings, or connected accounts. That information could include student records, health information, employee information, payment card data, research data, credentials, or other confidential material.
The university’s Information Security Policy 4-004 requires users to protect restricted and sensitive information assets when they are created, stored, processed, or transmitted. Rule R4-004C provides the university’s data classification and handling requirements. Knowing the data involved helps determine the appropriate safeguards and reviews.
This is also an opportunity to minimize exposure. If an app does not require a full identifier, an entire data set, or other information to perform its task, do not provide it. Information that is never shared cannot be exposed through that connection.
4. How broad is the access?
Scope can transform the level of risk. Access to one person’s calendar is different from access to every calendar. Access to one designated folder is different from access to all files in a department or across the university. A one-time task is different from an integration that runs continuously in the background.
Use the principle of least privilege: Give an app only the access required to perform its approved function, for only as long as that access is needed. When possible, begin with fewer users, narrower data access, read-only permissions, or a defined pilot period. Access should also be reviewed and removed when the application is no longer needed.
5. Have the right people reviewed the connection?
A third-party app can raise technical, IT security, privacy, licensing, contractual, and operational questions. No single questionnaire or approval automatically answers all of them. Depending on the app and data involved, the review may require the platform owner, local IT team, the Information Security Office (ISO), Information Privacy Office, Financial Services, or legal and contracting personnel.
The review should occur before someone enables the connection or introduces sensitive data. Consumer or free licensing terms may not permit institutional use, and a vendor’s IT security measures may not address the university’s particular use case. Early review gives everyone more options and makes it easier to adjust the design without disrupting an active service.
Someone will remain responsible after implementation. That includes reviewing access, monitoring vendor or permission changes, knowing how to revoke the connection, and understanding whom to contact if the vendor or university experiences an IT security incident. IT security approval is a step in the process, not necessarily the beginning or the end of the app’s life cycle.
A small pause can prevent a large problem
The goal is not to make every U user an IT security analyst or place an obstacle in front of useful technology. It is to recognize when a convenient connection deserves a closer look. It is how the university adopts technology thoughtfully and protects the people who entrust the organization with their information.
If you are unsure whether an app or integration needs review, please submit an IT Generic Service Request or contact your respective help desk. The request will be assigned to UIT Product Management, which owns the review process and coordinates IT security reviews with ISO’s Governance, Risk & Compliance team. Questions are easiest to address before granting access.
Node 4
Our monthly newsletter includes news from UIT and other campus/ University of Utah Health IT organizations, features about UIT employees, IT governance news, and various announcements and updates.