How to Guide: Report a Suspected Cybersecurity Incident

Summary

This guide provides instructions for the campus community on how to identify, prepare for, and report a suspected cybersecurity incident at UNLV.

Body

ALERT!

For incidents involving threats to life, imminent physical danger or there has been a direct threat of physical violence or to campus security, please contact the police:

  • On Campus (UPD) - Emergency: 911 (or 702-895-3669 from a cell phone)
  • Off Campus (LVMPD) - Emergency: 911
  • Resources: Campus Safety and Emergency

Jump to Section

Incident Impact and Categories

A cybersecurity incident is defined as a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices. These incidents can range from unintentional acts by internal personnel to deliberate criminal activity. For more information, refer to What is a Cybersecurity Incident.

Incidents are prioritized based on the following 3 categories; however, the final severity classification is determined by the Information Security Office (ISO) upon formal review.

  • Major: Acquisition of critical data (SSNs, medical records), theft >$10k, or widespread disruption (>10% of units).
  • Moderate: Potential acquisition of sensitive documents, theft <$10k, or impact to mission-critical services.
  • Minor: Any incident not meeting Major or Moderate criteria but still violating security policy.

Reporting Instructions

Form Instructions (Preferred)

  1. Go to the UNLV IT Cybersecurity Page > Navigate to the Service Catalog portal.

  1. Click "Request Service" and complete the "Report a Suspected Cybersecurity Incident" form.

  1. Provide details: Your Contact info, Incident Title, Department, detailed technical description, and attachments (if available).
    • Requestor: (Your Name)
    • Preferred Email: (Your email)
    • Preferred Phone Number: (Your phone number)
    • Cybersecurity Incident Date: (mm/dd/yyyy) (Show date format and keyboard instructions)
    • Department of Suspected Incident: (Your department or asset department)
    • Description (May include the following details):
      • WHAT HAPPENED: (Describe the event. Examples: did you click a link? Is your computer locked? Are weird emails being sent?)
      • WHEN IT HAPPENED: (Provide the date and approximate time the incident occurred or was noticed.)
      • DETAILS/INDICATORS: (Include email addresses of attackers, specific URL's clicked, or error messages seen.)
      • IMPACTED ASSETS: (List your ACE username, email address, or the Asset Tag/Serial Number of the computer.)
      • ACTIONS TAKEN: (Examples: Did you change your password? Disconnect from Wi-Fi? Turn off the machine?)
    • Does this incident involve research data?: Yes or No
    • Sensitive/Protected Data: (ie. Personal Identifiable Information (PII) or FERPA, HIPAA, etc.)
    • Type of Information or Activity:
    • Other Relevant Information
    • Attachments

  1. Review and click "Request" to submit.

Phone Reporting

  1. Call the IT Help Desk at 702-895-0777.
  2. Provide details to the support agent so they can fill out the form. The details should include your name, contact information, and a brief description of the incident.

Pre-Reporting Preparation

To ensure investigation integrity and a rapid response, please preserve all evidence and gather the following details before reporting:

  • Brief description of what happened.
  • Systems, accounts, or services affected.
  • Date and time of discovery.
  • Any evidence or documentation available.
  • Provide digital evidence: Take screenshots of error messages or suspicious activity; including full email headers for phishing attempts for example. NEVER CLICK ON THE SUSPICIOUS activity.

Need Help?

For additional assistance, you may contact the following support channels:

  • IT Help Desk Email: ithelp@unlv.edu
  • ISO Contact: informationsecurityoffice@unlv.edu

Confidentiality & Support

Support Channel Availability:

  • Phone Support: 8am–8pm daily, including holidays.
  • Walk-In Services: 8am–5pm, Monday–Friday, excluding holidays.

What to Expect After Reporting

Once a report is submitted, the Information Security Office (ISO) initiates the following triage process:

  • Initial Review: The ISO performs a preliminary assessment to verify the incident.
  • Assignment and Severity Determination: The ISO will assign/coordinate the response as needed and the official severity level is established based on impact and urgency.
  • Communication: The ISO will communicate next steps and remediation instructions to relevant stakeholders as needed.

Information: Real-Time Updates/Sources

Real-Time Updates will come from UNLV sources via:

  • UNLV Status: For information on impacted services, users should refer to the official UNLV IT system status page.
  • UNLV/Rebelmail announcements
  • Or other UNLV official communications methods (such as the designated social media feeds)

Details

Details

Article ID: 2323
Created
Wed 7/22/26 6:22 PM
Modified
Wed 7/22/26 7:44 PM

Related Services / Offerings

Related Services / Offerings (1)

Use this service to report suspected cybersecurity threats or incidents, including malware, data breaches or compromised accounts.