Operational Security for Research & Innovation
One platform for research security across your institution
OpSy brings together the tools researchers use, the training that builds a security culture, and the casework your Research Security Team relies on, so a risk raised anywhere is understood everywhere. Built by the Protective Security Lab for universities and research organisations.
OpSy Assist
Self-service tools
OpSy Learn
Training & assurance
OpSy Manage
Security team portal
Three connected platforms
What is OpSy?
OpSy is a connected research-security suite. Each platform serves a different audience, but they share one data layer, so a travel assessment completed in Assist and a course finished in Learn both appear in Manage without anyone re-keying a thing.
For researchers and staff
OpSy Assist
A self-service toolkit that lets any researcher assess travel, screen a project, report a contact, log an incident or register a visitor, with tailored, policy-grounded guidance at every step.
Learn moreFor training & assurance
OpSy Learn
Assign, deliver, author and evidence research-security training across the organisation, turning awareness into a measurable, auditable security culture.
Learn moreFor Research Security Teams
OpSy Manage
The central portal for the Research Security Team, drawing on every Assist submission and Learn record to give a complete understanding of institutional risk.
Learn moreA look inside
See OpSy in action
The same clean, consistent interface runs across all three platforms. These are representative views of how OpSy looks in day-to-day use.
OpSy Assist
Guided, policy-grounded assessments that give researchers a clear risk picture in minutes, with RAG-rated scores and recommended mitigations.
Travel Risk Assessment
VTA-2026-0428 · Generated 14 Aug 2026
Traveller
Dr A. Okafor
Destination
Beijing, China
Trip type
Conference
Dates
6 days
Country Risk Score
High Risk
Research Security Score
Moderate Risk
Elevated state-actor interest for this destination and research area.
Carry clean loan devices; encrypt and minimise data taken abroad.
Standard vigilance for unsolicited approaches at the event.
OpSy Learn
Completion and competence tracked across the whole organisation, with per-learner progress, overdue flags and downloadable certificates.
Training & Assurance
Organisation-wide completion
1,284
Assigned
Total records
146
In progress
Currently learning
23
Overdue
Past due date
1,052
Completed
82% completion
Dr A. Okafor
Research Security Essentials
J. Whitfield
Secure International Collaboration
S. Nguyen
Dual-Use & Export Control
OpSy Manage
Every submission and training record in one authoritative view for the Research Security Team, triaged by risk and department.
Overview
Casework
Assurance
Admin
Research Security Operations
Manage dashboard
37
Open cases
412 total
6
High-risk
Priority review
12
Incidents
All departments
82%
Training
23 overdue
Recent submissions
Travel · Beijing
Physics
Incident · Lab access
Estates
Due diligence · Partner Ltd
Research Office
Visitor · Delegation
Engineering
OpSy Assist · For researchers and staff
Self-service tools, organised by category of risk
19 tools cover the full spread of research-security risk a researcher encounters, from planning a trip to reporting an incident. Each is grouped below by the risk it helps you manage.
Every tool is configurable for your university. Adapt the questions and choose which tools appear so your team manages risk their way. OpSy fits your process, not the other way around. Need something that isn't here yet? We build new tools for you in days, not weeks.
Travel
Prepare staff and students for international travel and manage the security risks that follow them abroad.
Travel Risk Assessment
Generate a research-security risk assessment for upcoming international travel, covering country advice, devices, networking and research area.
Research Projects
Screen proposals, topics and technologies for national security, dual-use and export-control exposure before work begins.
Research Topic Screening
Submit a PhD or project research topic for assessment across technology, international, data-handling, dual-use and export-control risks.
National Security Risk Review
A comprehensive national-security review to run against each new research proposal and consultancy contract.
Sensitive Technology & Affiliations Check
Assess research involving sensitive technologies and international affiliations that may present national-security or export-control risks.
Dual-Use Assessment
Analyse research for potential dual-use military applications and civilian technologies with defence-related implications.
Governance Risks
Meet statutory and institutional obligations for declarations, foreign influence and export licensing.
Declaration of Interests
Declare approaches or offers of positions with foreign universities, companies or organisations for security review.
Foreign Influence Registration
Register a foreign influence arrangement or activity under the UK FIRS via the official GOV.UK service.
Export Control Licensing
Apply for an export-control licence through SPIRE, the UK's online export-licensing system.
Due Diligence
Vet partners, collaborators and unsolicited approaches before committing to a relationship.
Research Partner Due Diligence
Review whether a potential research partner poses national-security, export-control or reputational risk.
Contact Reporting
Log an approach from a conference, potential collaborator or foreign entity, or debrief after an event.
Security Culture
Build individual awareness and a measurable, institution-wide research-security culture.
Research Security Self-Assessment
A structured self-assessment that surfaces research-security risks connected to you and your project.
Role-Based Risk Profile
Assess the risks you face in your role, with tailored guidance on travel, networking, IT security and social engineering.
Security Culture Assessment
Self-assess your understanding of research-security threats to build a picture of departmental and institutional culture.
Research Security Advisor
Ask questions and get live answers grounded in NPSA and NCSC guidance and University policy.
Incident Management
Capture, investigate and escalate research-security incidents and professional concerns.
Incident Reporting & Logging
Capture an incident, then manage it over time with an action log, evidence uploads, status tracking and escalation.
Incident Investigation
Run a comprehensive investigation using a 12-section structured framework with a findings log.
Professional Concern Reporting
Anonymously report professional concerns related to research security, with no personal information stored.
Visitors
Assess and manage international and long-term visitors coming to campus.
Visitor Security Review
Register international visitors and provide the detail needed for security review of campus visits.
Long-Term Visitor Management
Register long-term academic visitors and ensure compliance with the NPSA Visitor Security Policy.
OpSy Learn · For training and assurance
Turn awareness into an auditable security culture
OpSy Learn is where research-security capability is built and evidenced. It lets you deliver a ready-made curriculum, author your own courses, and prove completion across the organisation.
- 01
Deliver a research-security curriculum
Assign and deliver mandatory and optional courses, from Research Security Essentials to Dual-Use and Export Control Awareness, across the whole organisation.
- 02
Author your own courses
Build bespoke training with a guided authoring wizard, uploading documents and video and publishing straight to the catalogue. Select the audience you want to complete each course.
- 03
Test with real-world simulations
Put people in realistic scenarios they might actually face and let them respond by voice or text. OpSy scores each response and shows individuals exactly where they need to consider further.
- 04
Track completion and competence
Follow every learner's progress, see who is in-progress, completed or overdue, and issue certificates as evidence of completion.
- 05
Evidence assurance to leadership
Export completion reports and assurance data that feed directly into OpSy Manage, closing the loop between training and casework.
OpSy Manage · For Research Security Teams
A complete understanding of institutional risk
OpSy Manage is the portal built for the Research Security Team. It draws on every submission made in Assist and every record created in Learn, giving one authoritative view of casework, people, partners and assurance.
Communicate research-security messaging
Send research-security communications to an individual, a department or the whole institution. Messages are composed within OpSy Manage and delivered to each recipient's email inbox, where they can reply directly by email, enabling efficient communication when it is needed. Every message is recorded, giving the Research Security Team a complete audit trail of what was sent, to whom and when.
- An individualEmail inbox
- A departmentEmail inbox
- The institutionEmail inbox
Unified case inbox
Every submission from OpSy Assist, including travel assessments, contact reports, incidents, declarations and reviews, lands in one triage-ready inbox.
Researcher & organisation views
See a complete picture of risk by person and by partner organisation, drawing every related case and record together.
Training & assurance oversight
Monitor organisation-wide training completion from OpSy Learn alongside casework, so capability and compliance sit in one place.
Reporting & administration
Produce management reporting on risk, throughput and outstanding actions, and administer users, roles and workflow.
One data layer, no duplication. Because Assist, Learn and Manage share the same records, the Research Security Team sees risk as it emerges. Travel assessments, contact reports, incidents, declarations, visitor reviews and training status all flow into Manage automatically.