cs_CZ

Institutional Resilience
and Research Security
at the Biology Centre CAS

The Biology Centre CAS is an open research institution engaged in international cooperation. Openness, knowledge sharing and collaboration with partners from around the world are fundamental components of high-quality research.

Institutional resilience is not intended to restrict this openness. Its purpose is to help protect our employees, research, research results, data, know-how, biological material, intellectual property, infrastructure and the reputation of the Biology Centre (BC).

Put simply, it is about being able to recognise situations that may pose a risk and knowing when and whom to contact at BC.

Why do we address institutional resilience?

Research is becoming increasingly international, digital and interconnected. Alongside new opportunities, this also creates new risks – for example, unauthorised access to research results and data, misuse of know-how or technologies, cyber incidents, potentially risky collaborations, breaches of contractual obligations, international sanctions or export control rules.

Moreover, from 1 January 2027, the new Act No. 328/2025 Coll., on Research, Development, Innovation and Knowledge Transfer, requires recipients of institutional funding to systematically ensure institutional resilience and research security.

Similar systems are already being introduced by Czech universities and research organisations, while research security is also one of the priorities of the European Research Area.

The aim of BC is not to create additional administrative burdens for researchers. Expert assessment of risks, contracts, partners or incidents is the responsibility of the relevant support departments. What we expect from researchers is primarily basic awareness and timely consultation whenever they encounter a situation that is out of the ordinary.

When might institutional resilience concern me?

1. Research results, publications and intellectual property

Publishing and sharing research results is a natural part of scientific work. However, before disclosing unpublished results or providing them to an external party, it is advisable to consider whether they contain:

  • a new result with potential for practical application,
  • know-how or a methodological procedure,
  • a solution suitable for patent or other legal protection,
  • information protected by a contract or confidentiality obligation,
  • results or data that we are not fully authorised to disclose.

If a result may have application or commercial potential, please contact the BC Technology Transfer Office before its disclosure.

2. Data, software and digital tools

Store and share research data, documents and non-public information using tools and services approved by BC.

Follow the “Security Incident Response Directive” and, in particular, avoid:

  • using private email accounts and cloud storage services,
  • sharing login credentials,
  • working on private devices,
  • using external drives,
  • using generative artificial intelligence tools.

Do not enter unpublished results, personal data, contracts, confidential information or know-how into services where such use has not been approved.

3. International cooperation

International cooperation is a fundamental part of BC's activities, and the vast majority of international collaborations do not present any problems.

In some cases, however, it is advisable to verify in advance:

  • who exactly we are collaborating with,
  • what the collaboration involves,
  • what data, results, software or materials will be shared,
  • who will have access to them,
  • how rights to the results will be regulated,
  • whether the collaboration is subject to sanctions or other legal restrictions.

Checking a partner is not the responsibility of an individual researcher. If you have any doubts, please contact the relevant BC departments (Technology Transfer Office and Project Office), and we will arrange any further assessment.

4. Biological material, samples and technologies

Before transferring biological material, samples, unique methodologies, software, technologies or other research assets outside BC, it is advisable to verify the conditions governing their use and further transfer.

Depending on the specific situation, an MTA, NDA or another agreement may be required.

Certain technologies may also be subject to dual-use or export control regulations.

5. Conferences, visits and international travel

Conferences, international travel and professional visits are a normal part of scientific work.

Pay particular attention to what non-public information you share and with whom. This may concern, for example:

  • unpublished research results,
  • detailed methodological procedures,
  • access to research data,
  • biological material,
  • access credentials for information systems,
  • information obtained from project or commercial partners.

The same principle applies when external visitors enter laboratories and other BC facilities.

6. Unusual requests and security incidents

Be particularly alert if someone:

  • requests information that is not necessary for the stated purpose of the collaboration,
  • requests access to non-public data, a laboratory, equipment or an information system,
  • asks you to bypass standard contractual or approval procedures,
  • pressures you to transfer results or materials quickly,
  • requests an unusual degree of secrecy regarding the collaboration itself,
  • asks you to use a private email account or another non-standard communication channel.

Such a situation does not automatically mean that a security incident is taking place. However, it is a good reason to seek advice.

What do we expect from you?

Just three simple steps:

1. Consider

Before sharing non-public information, results, data or materials, briefly ask yourself:

Is it appropriate for me to share this with this particular recipient?

2. Verify

Is the information public? Am I authorised to share it? Is it subject to a contract, confidentiality obligation, intellectual property protection or any other restriction?

3. Ask for advice

If you are unsure, you do not have to assess the situation on your own.

Seeking advice early is usually simple. Resolving a problem afterwards can be considerably more complicated.

When should you definitely contact us?

Please contact us, for example, if:

  • you want to provide an external party with non-public data, results, software, biological material or know-how and are unsure about the applicable conditions,
  • you are preparing to disclose a result that may have significant application or commercial potential,
  • you are starting an unusual or potentially sensitive international collaboration,
  • you are unsure about a new partner or the terms of a collaboration,
  • you encounter possible sanctions or export control restrictions,
  • you receive an unusual request for information or access,
  • you accidentally send sensitive information to the wrong recipient,
  • you lose a work device or suspect a cyber incident,
  • you simply feel that a particular situation is out of the ordinary.

You do not need to have evidence that there is a problem. Even a concern or uncertainty is sufficient reason to seek advice.

Who should I contact?

Institutional Resilience / Research Security

iod@bc.cas.cz

Assistance with assessing a situation, potentially risky collaboration or partner, and referral to the appropriate specialist department.

Technology Transfer Office

Research results, know-how, intellectual property, patents, licences, commercialisation, NDAs, MTAs and cooperation with companies.

Information Technology Department

Cybersecurity, devices, access rights, accounts, information systems and security incidents.

Legal Support

Contracts, confidentiality, legal terms of cooperation, sanctions and regulatory matters.

Project Support

Project conditions, international consortia and funding provider requirements.

If you are unsure which department to contact, you do not need to find the right one yourself – contact us at iod@bc.cas.cz, and we will forward your enquiry to the appropriate department.

Training at BC

BC is preparing a short e-learning course entitled Institutional Resilience and Research Security.

Its purpose is not to turn researchers into security or legal specialists. Through short practical scenarios, it will explain:

  • what risks may arise during everyday research activities,
  • how to protect research results, data and know-how,
  • when a partner check may be appropriate,
  • what to do if you suspect an incident,
  • whom to contact at BC.

The e-learning course will be intended for current employees and will subsequently also be incorporated into the onboarding process for new BC employees.

Sanctions lists for individuals and companies, export control

Financial Analytical Office – International Sanctions
https://www.fau.gov.cz/cs/rozcestnik/mezinarodni-sankce

EU Sanctions Map
https://www.sanctionsmap.eu/

USA OFAC – Office of Foreign Assets Control
https://ofac.treasury.gov/sanctions-programs-and-country-information

USA BIS – Bureau of Industry and Security
https://www.bis.gov

CALTECH – Country Lists and Programs
https://researchpolicy.caltech.edu/research-security/export-compliance/sanctions_embargoes#bis-d98a4601-tab

Ministry of Industry and Trade – Dual-Use Items and Export Control
https://mpo.gov.cz/cz/zahranicni-obchod/licencni-sprava/mezinarodni-kontrolni-rezimy-
zbozi-dvojiho-pouziti/

Ministry of Foreign Affairs – Czech National Sanctions List
https://mzv.gov.cz/jnp/cz/zahranicni_vztahy/sankcni_politika/sankcni_seznam_cr/vnitrostatni_
sankcni_seznam.html

Sanctions List of Universities (NDAA Section 1286 List – Seven Sons), U.S. Department of Defense
https://www.cto.mil/fy25-ndaa-section-1286-list

Cybersecurity

National Cyber and Information Security Agency (NÚKIB)
https://nukib.gov.cz/

Handbooks and guidance

European Commission – Research Security
https://research-and-innovation.ec.europa.eu/strategy/strategy-research-and-innovation/europe-world/international-cooperation/strategic-autonomy-and-european-economic-and-research-security_en

Trusted Research – Practical Guidance for Academia
https://www.npsa.gov.uk/specialised-guidance/trusted-research

chevron-down