Travel Security

Security Tips for Travel

Traveling for business, research, study, or personal reasons can increase the risk of cyber targeting, device loss, account compromise, insecure network use, phishing, and unauthorized access to SDSU data.

To help protect SDSU data, accounts, and devices, follow the safeguards below before, during, and after your trip.  Travelers should also review current travel advisories and SDSU travel guidance before departure.

Some destinations may present elevated risks related to cybersecurity, export controls, sanctions, surveillance, device inspections, or data protection.  Risk levels can change, so travelers should review current SDSU guidance, U.S. Department of State Travel Advisories, and applicable export control or sanctions requirements before departure.

Travelers should consult SDSU Export Control before traveling to destinations subject to sanctions, embargoes, or strict export restrictions, or before traveling with SDSU equipment, encrypted devices, controlled data, restricted technology, or research materials.

When traveling to a high-risk destination:

  • Request a loaner device when appropriate.
  • Do not bring devices containing high-risk or moderate-risk SDSU data unless approved.
  • Do not bring unnecessary SDSU data, research data, or sensitive personal information.
  • Be aware that encrypted devices may require advance review for some destinations.
  • Report lost, stolen, searched, damaged, or tampered devices immediately.
  • Upon return, stop using SDSU devices used during high-risk travel until IT has advised you.
  • Change passwords for accounts accessed during travel when advised or after higher-risk travel.  Please visit SDSUid Help to reset your password.

The list of high-risk countries is compiled from sources including the U.S. Department of State Travel Warnings, the Department of the Treasury's Office of Foreign Assets Control (OFAC), the Federal Bureau of Investigation (FBI), and the Office of the Director of National Intelligence (ODNI).  These countries include, but are not limited to, the following:

  • Russia
  • China
  • North Korea
  • Iran
  • Cuba
  • Syria
  • Crimea
  • Donetsk
  • Luhansk region of Ukraine

Before departure:

  • Coordinate with your department IT team or the IT Security Office if you need a loaner device.
  • Ensure all devices and data are encrypted.  Note: SDSU-managed computers are encrypted by default. 
  • Secure mobile devices with strong passcodes, biometrics where appropriate, and auto-lock.
  • Obtain a Duo MFA token if cellular service or push notifications may be unreliable.
  • Confirm that GlobalProtect VPN is installed and working before departure, and use a VPN for your personal cell phone.
  • Remove unnecessary SDSU data, personal data, saved passwords, and files from travel devices
  • Update operating systems, browsers, applications, and security software for your personal devices.
  • Turn on “Find My Device” tracking and/or remote wiping options on your phone.
  • Be aware of the latest travel advisories.
  • Consult SDSU Export Control when traveling internationally with SDSU equipment, encrypted devices, controlled data, restricted technology, or research materials.

While traveling:

  • Keep laptops, phones, tablets, storage media, and other devices with you.
  • Do not leave devices unattended in public spaces, hotel rooms, conference rooms, vehicles, or checked luggage.
  • Use GlobalProtect VPN when accessing SDSU systems.
  • Avoid public Wi-Fi unless using approved protections.
  • Do not use public computers or shared kiosks to access SDSU accounts.
  • Use browser-based access to email and cloud files when appropriate.
  • Avoid public charging stations and unknown USB cables.
  • Do not use unknown USB drives or removable media.
  • Disable Bluetooth, AirDrop, Near Field Communication, and other wireless features when not needed.
  • Do not download apps from unofficial app stores or unknown links.
  • Be alert for phishing, fake login pages, suspicious QR codes, and unusual MFA prompts.
  • Report lost, stolen, searched, damaged, or tampered devices immediately.

After your trip:

  • Return loaner devices, temporary phones, and removable media.
  • Coordinate with the IT Help Desk before reconnecting SDSU devices used during higher-risk travel.
  • Report lost, stolen, searched, damaged, or tampered devices.
  • Report suspicious account activity, unusual MFA prompts, phishing attempts, or potential data exposure.
  • Change passwords for accounts used during travel when advised or after higher-risk travel.
  • Review bank and credit card statements if you used personal financial accounts while traveling.
  • Follow any post-travel instructions from IT Security, Export Control, or your department's IT team.

Researchers and Sensitive Data

Researchers traveling with sensitive research data, controlled technical information, unpublished results, sponsor-provided information, source code, biological materials, prototypes, or research equipment should also review SDSU Research Security travel guidance.

Consult SDSU Export Control before international travel if your trip involves sanctioned destinations, export-controlled information, restricted technology, SDSU-owned equipment, controlled research materials, or international collaborators.

Get Help

For travel cybersecurity support, submit a ServiceNow ticket.

Report immediately if:

  • A device is lost, stolen, searched, damaged, or tampered with.
  • You suspect account compromise.
  • You receive unusual MFA prompts.
  • SDSU data may have been exposed.
  • You clicked a suspicious link or entered credentials into a suspicious site.

Get Help

To request a service, please submit a ticket via ServiceNow.

IT Security Office
Administration Building

Report an Incident

Please contact the Information Security team immediately if you experience or are aware of any of the following: