By Dr. Kamil Mizgier
The academic world is experiencing a paradigm shift. Researchers around the globe who are developing new technologies or materials are now confronted with compliance and export control questionnaires that were rarely seen in the past. International collaboration agreements require risk-based assessments that simply did not exist several years ago. What might seem like an added administrative burden reflects a much broader challenge for universities: managing how to conduct research in an interconnected yet “reglobalized” world. Given the novelty of the topic, successful implementation can be seen as a significant milestone for the higher education sector.
Research security, or the broader concept of knowledge security, has evolved from a compliance concern into a strategic risk that university boards can no longer delegate to administrative functions.
Tensions between academic freedom and research security
The fundamental challenge is to strengthen the protection of academic freedom and open science while also safeguarding intellectual property and strategic knowledge creation. Open science has been the bedrock of academic progress for generations. The free exchange of ideas, unrestricted collaboration across borders, and transparent publication of findings have accelerated innovation in ways that closed research systems never could. And, despite this remarkable scientific progress, geopolitical realities are forcing a reckoning, especially in sensitive areas connected to defense research and disciplines ranging from artificial intelligence to quantum computing and advanced materials science.

As transatlantic regulations keep changing and growing, universities must quickly adapt to new realities. For university boards and senior leadership, this presents a risk management challenge comparable to what financial institutions faced following Basel II/III, or what manufacturing firms encountered as supply chains globalized, becoming vulnerable to disruptions and sustainability concerns. Higher education needs to strike a delicate balance and adopt a new mindset to protect institutional assets and societal interests, while preserving the collaborative ecosystem that makes research productive.
At the same time, over-restriction is a genuine risk. If security measures become too burdensome, researchers may avoid international collaboration entirely and innovation will suffer. If talented international students and scholars feel unwelcome or excessively scrutinized, universities will lose crucial talent pipelines. If the administrative burden consumes resources that could support research, the cure becomes worse than the disease.
Yet insufficient protection also carries consequences. Institutions that fail to implement adequate protections may face regulatory sanctions, loss of research funding, reputational damage, or genuine harm to national security interests. And this is the area where a risk management toolkit can help balance risk and reward.
The risk management imperative: From compliance to strategy
What distinguishes effective risk management from pure compliance is the systematic approach to identifying, assessing, and mitigating risk in ways that support strategic decisions. Universities need frameworks that are analogous to those used in other sectors facing complex, multi-dimensional risks.
As research security touches almost every academic activity, enterprise risk management provides this much-needed capability. Rather than treating each risk in isolation, integrated frameworks allow institutions to understand aggregate exposure, allocate resources where they matter most, and make informed trade-offs between security measures and research opportunities.
The starting point is clarity around terminology and scope. Terms like "dual-use technology," "export control," and "research security" have specific meanings with legal and regulatory implications. For instance, advanced image recognition software developed for medical diagnostics could also be adapted for surveillance purposes, illustrating the dual-use dilemma. Yet many researchers encounter these concepts without sufficient context to understand what's truly at stake or why certain activities trigger enhanced scrutiny.
TABLE 1. Definitions of terms related to research security
|
Research Security | Refers to anticipating and managing risks related to research and innovation from undue foreign interference and other security threats infringing academic freedom and research integrity1 |
Knowledge Security | Prevention of unwanted transfer of sensitive information, know-how, and technology; mitigation of foreign interference in higher education and research; reduction of dependencies that could endanger national security and competitiveness2 |
Risk-Based Assessment | Systematic approach to evaluate risks based on likelihood and impact, allocating resources proportionate to risk levels rather than uniform requirements1,2 |
Risk Appetite | The amount and type of risk that an organization is willing to pursue, retain, or take in pursuit of its strategic objectives3 |
Open Science | Movement to make scientific research, data, and dissemination accessible to all levels of society; it encompasses open access to publications, data, software, and research processes4 |
Dual-Use Technology | Items, including software and technology, which can be used for both civil and military purposes, encompassing goods that can be used for nuclear, chemical, or biological weapons5 |
Export Control | Legal framework restricting the export of certain goods, software, and technology to prevent the proliferation of weapons of mass destruction and ensure compliance with international security obligations5 |
Foreign Interference | Refers to attempts by a foreign actor to influence the perceptions of staff, scholars, and students at [Higher Education and Research] institutions with the aim of aligning research, education, and the international academic debate with the strategic visions, opinions, interests, or political system of a foreign actor, which are not supported by the receiving side and/or are contrary to the receiving side's norms and values6 |
Risk management-thinking demands precision: What exactly are we protecting? From which threats? At what cost in terms of research freedom and productivity? Table 1 provides a basic set of definitions related to research security to establish a common nomenclature.
This clarity enables the second essential element: risk appetite statements. How much risk is the institution willing to accept in pursuit of its research mission? Without board-level articulation of risk appetite, every decision becomes ad hoc, creating inconsistency that frustrates researchers and leaves genuine vulnerabilities unaddressed. Researchers should proactively flag potential risks in their proposals, compliance officers should review them, and boards should set overarching risk appetite policies.
The third approach is investing in capability building. Training staff in risk-based assessment methodologies is of utmost importance. Creating communities of practice where institutions share insights on emerging risks is an effective mitigation strategy. Digital tools can also streamline risk processes, flag potential concerns for human review, and provide leadership with adequate information.
By following this approach, institutions can:
Establish robust monitoring and reporting mechanisms to ensure risks are continuously evaluated and managed.
Support clear communication and accountability throughout the research security framework.
Set room aside for risk strategy recalibration. Any risk framework implemented today will need to be adjusted as threats evolve and geopolitical dynamics shift. For example, organizations should periodically review and update their risk assessments to account for emerging cyber threats or changes in international sanctions.
For university boards and executive leadership, the imperative is clear: research security demands strategic engagement.
Bridging silos to increase research security
The bottom line is that universities must work together to find solutions that balance risk and reward. No single institution can deal with this challenge alone, and fragmented approaches create inefficiencies that unnecessarily burden researchers. Collective frameworks, shared threat intelligence, and collaborative advocacy (e.g., through university networks, such as LERU) for sensible regulation all serve institutional interests better than isolated responses. Utilizing external insights from industry sector leaders is another way to make informed and impactful decisions.
For university boards and executive leadership, the imperative is clear: research security demands strategic engagement. The decisions about risk appetite, resource allocation, cultural change, and balance between competing values aren't purely technical. They're strategic choices that will reshape institutional futures in an era where geopolitical tensions increasingly interfere with academic mission.
Council of the European Union (2024). Council Recommendation of 23 May 2024 on enhancing research security. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:C_202403510
swissuniversities (2025). Knowledge Security: Recommendations for Swiss Higher Education Institutions. Available at: https://www.swissuniversities.ch/fileadmin/swissuniversities/Dokumente/Komm/Empfehlungen/Bericht_KnowledgeSecurity_251127.pdf
International Organization for Standardization (2018). ISO 31000:2018 Risk management — Guidelines. Available at: https://www.iso.org/standard/65694.html
League of European Research Universities (LERU). Position papers on open science and research integrity. Available at: https://www.leru.org
European Union (2021). Regulation (EU) 2021/821 of the European Parliament and of the Council setting up a Union regime for the control of exports, brokering, technical assistance, transit, and transfer of dualuse items. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32021R0821
d’Hooghe, Ingrid, and Jonas Lammertink. "Towards sustainable Europe-China collaboration in higher education and research." Leiden Asia Center (2020).
Disclaimer: The views expressed in this paper are solely those of the author and do not necessarily reflect the views of his employer.