If you are aware of a privacy or security breach, report it immediately. Don't wait until every detail is known.
If you suspect or witness any incident related to cybersecurity, cardholder data, or privacy breaches, or obtained information from a third party, use the reporting channels below. Our vigilance is crucial to maintaining a secure environment.
Prompt reporting enables King's to respond, contain and mitigate potentially damaging outcomes, and determine if sensitive data is at risk.
Do not delay in reporting an incident or breach even if you do not have all the information!

A privacy breach is an incident involving the unauthorized collection, use, access, disclosure, retention or disposal of personal information. There can be internal breaches (within King's) or external breaches (with third-party service providers).
"Personal Information" is defined as recorded information such as home address, medical history, education history, identifying numbers (e.g., social insurance number [SIN], employee number, student number, etc.), race, gender, financial or employment information, personal opinions, completed assignments and exams, and grades, comments and evaluations provided by an instructor.
N.B. Preserve any evidence you have, and do not delete logs/email unless you are instructed to do so.
A cybersecurity incident involves either the loss of data or unauthorized access to data and systems because of actions by a threat actor, malware, or security gaps. Cybersecurity incidents also include compromised accounts, suspicious system behaviour and cloud/vendor compromise.
These incidents intentionally compromise solutions at King's or within our cloud service providers. When such incidents occur, it is crucial to escalate them promptly to ITS:
Use the same reporting channels as for a cybersecurity incident:
As with any other privacy or security incident, it's important to report it promptly.