University of Helsinki IT Security Test | HELPDESK

University of Helsinki IT Security Test

The University of Helsinki IT Security Test aims to draw the attention of University staff and students to factors and procedures that matter in terms of information security. The short annual IT Security Test is mandatory for staff members and degree students. If you do not take the test by the deadline, your user account will be locked and you will no longer be able to log in to University services.

Take the IT Security test in Moodle

Take the University of Helsinki IT Security Test 2026-27 in Moodle.

    The short annual IT Security Test is mandatory for staff members and degree students. If you do not take the test by the deadline, your user account will be locked and you will no longer be able to log in to University services. If your user account is locked, please contact IT Helpdesk.

    The test will only take about 15 minutes of your time. Its content includes voluntary background learning material and a quiz with five multiple-choice questions. The questions are drawn from a broader question bank, the questions and themes of which are updated every year.

    You will receive test information and several reminders by email and as notifications in Flamma and the Studies Service. The times for taking the test are staggered throughout the academic year and are assigned based on your username.

    You can check your next deadline for the IT Security test in the MyAccount service (requires you to log in with your University username).

    Read more from Detailed Help tab.

    What is the University of Helsinki IT Security Test?

    Each of us can contribute to the University’s digital security with small everyday actions. The annual University of Helsinki IT Security Test focuses on factors and procedures that matter in terms of information security. Based on a decision by University management, the test is mandatory for staff members and degree students.

    You can use the IT Security Test material to review topics such as detecting scam messages and scam websites, various practices promoting safety in work and studies, and the safe use of generative AI at the University.

    If you do not take the test by the deadline, your user account will be locked and you will no longer be able to log in to University services.

    How do I take the test?

    The test is done in Moodle. Click on the link below and then register for the test on the Moodle page by selecting “Add me to the course”.

    The test will only take about 15 minutes of your time. The learning material for the test contains the University's key information security content, which you can review before taking the test. You can also go directly to the test, which consists of five multiple-choice questions. The test questions will be drawn from a broader question bank. The learning material and questions are updated with new content every year.

    You can retake the test as many times as necessary to pass it. To pass the test, you must earn a minimum score of 80/100 points, which means you must have at least 4 out of 5 questions completely correctly to pass the test. You can repeat the test as many times as you want.

    If you do not take the test by the assigned date, your user account will be locked.

    If your user account is locked and you have not taken the University of Helsinki IT Security Test, please contact IT Helpdesk:

    NB! If you want to remove yourself from the course area after taking the test, wait at least until the next day to do so. If you remove yourself from the area immediately after taking the test, information about your completed test will not be transmitted to the test's backend system.

    When do I take the test?

    The test is taken once an academic year. The times for taking the test are staggered throughout the academic year and are assigned on the initials of your username.

    You can check your next deadline for the IT Security test in the MyAccount service (requires you to log in with your University username) under View and manage account – Security test expiration.

    You will be informed about your test schedule via email. You will receive several email reminders to take the test, the first of which will arrive two months before the due date. The reminders will come from the address noreply@helsinki.fi in your language of interaction. If you feel you received the reminder in the wrong language, you can check your language of interaction and change it if required in the MyAccount service. You can read more about how to change the language of interaction in separate instructions.

    NB! If you are going abroad for more than two months, take the IT Security Test for the academic year in question in advance. The test for the new academic year will be available from 1 July.

    Frequently asked questions

    Why do I have to take the test?

    Answer: The University’s management has decided on the administration of the test because our information security has been seriously tested in recent years. Information security is the shared responsibility of all University staff and students so it is important to maintain their information security skills and knowledge of current information security threats.

    Who prepares the questions and the test? To whom can I give feedback? 

    Answer: Several University units have taken part in preparing the test and the questions. You can provide feedback by using the IT Security Test feedback form.

    My user account is locked! What should I do? 

    Answer: If your account has been locked, please contact IT Helpdesk. See the separate instructions for more detailed contact instructions.

    What if I don't pass the test? 

    You can retake the test as many times as necessary to pass it. Don’t worry. The test is not difficult. The main purpose of the test is to raise awareness and focus attention on important matters in terms of information security. If you do not take the test by the deadline, however, your University user account will be locked and you will not be able to access the University’s systems. In this case, you can contact IT Helpdesk by chat, by phone (029 41 55555) or by email (helpdesk@helsinki.fi) and request an extension for taking the test, if you have justified grounds to do so. The chat is often the fastest way to solve a problem if the Helpdesk is congested!

    I have already completed Student’s digital skills and/or other studies on the subject. Do I still have to take this test? 

    Yes, all the University's degree students and staff members take the University of Helsinki IT Security Test annually.

    I am an exchange student at the University of Helsinki. Do I need to take the test?

    The test is only mandatory for students completing a degree (bachelor’s, master’s and doctoral students). If you are an exchange student at the University of Helsinki or are completing other non-degree education, you do not need to take the test. Of course, you can take the test if you wish.

    IT Security Test accessibility report

    This accessibility report applies to the University of Helsinki IT Security Test service and has been prepared on 19 January 2022 and updated on 8 July 2026. The service is subject to the legislation on the provision of digital services, which requires that public network services be accessible. The accessibility of the service has been assessed by an external expert organization.

    This accessibility report applies only to the Moodle area of the IT Security Test and the test's Webropol feedback form.

    The state of accessibility of the digital service

    Partially meets accessibility requirements.

    Inaccessible content

    The website is not yet fully compliant.

    Perceivable: Icons for links opening in a new tab

    Inaccessible content: In Moodle, icons indicating that a link opens in a new tab have no text alternative, so their meaning cannot be programmatically determined. Success criterion not met: WCAG 1.1.1 Non-text Content

    Perceivable: Image alternative text

    Inaccessible content: The image on the front page of IT Security test 2026−27 in Moodle has no text alternative. Success criterion not met: WCAG 1.1.1 Non-text Content

    Perceivable: Unclear structures in navigation

    Inaccessible content: The Moodle course area side navigation is two-level, and names for subgroups are generated automatically from the name of the upper level, e.g., “Collapse IT Security Test Status,” which is not descriptive. The second-level treeitem elements are placed within two nested groups. This causes screen readers to interpret the second level as a third level in total, even though the navigation should only contain two levels. Link elements should be marked directly with a treeitem role, whereas currently, the link element appears inside the treeitem element. Success criterion not met: WCAG 1.3.1 Info and Relationships

    Perceivable: Misleading naming

    Inaccessible content: On the IT Security test pages, the “Flag question” feature has an accessible name of “Flagged,” leading to incorrect interpretation when using a screen reader. Success criterion not met: WCAG 1.3.1 Info and Relationships

    Perceivable: Form field labels

    Inaccessible content: In the test's feedback form, fields like “When you want to continue, go to the link below” or “Your email address” are not programmatically associated with their labels. Success criterion not met: WCAG 1.3.1 Info and Relationships

    Perceivable: Naming form groups

    Inaccessible content: Form groups on the IT Security test pages are not labeled with the corresponding question text. Success criterion not met: WCAG 1.3.1 Info and Relationships

    Perceivable: Programmatic association of error messages

    Inaccessible content: Error messages in test's feedback form are not linked to their fields programmatically. Success criterion not met: WCAG 1.3.1 Info and Relationships

    Perceivable: Hidden text

    Inaccessible content: Under the H1 heading in the IT Security Test Learning material page there is hidden text “Completion requirements,” which is not relevant. Success criterion not met: WCAG 1.3.1 Info and Relationships

    Perceivable: List structures

    On the first page of the test's feedback form, there is a list structure around the “Next” button, but it only has one child element. This can render screen reader use more unclear. Success criterion not met: WCAG 1.3.1 Info and Relationships

    Perceivable: Links distinguished only by color

    Inaccessible content: In the breadcrumb navigation of the Moodle service (for example on the IT Security Test Learning material page), links are distinguished from surrounding text by color alone, as the contrast between blue and black is insufficient. In the test's feedback form, the “Click here” link is distinguished from the surrounding text by color alone, as the orange color does not provide sufficient contrast against the blue text. Success criterion not met: WCAG 1.4.1 Use of Color

    Perceivable: Layout on zoomed/narrow views

    Inaccessible content: The “Start attempt” modal dialog on the IT Security test page does not adapt to narrow or zoomed views in a way that allows all text to remain visible. When reviewing correct and incorrect answers, the added explanations cause horizontal scrolling in narrow or zoomed views. In the course area, the content of the breadcrumb navigation is truncated as the zoom level increases. Success criterion not met: WCAG 1.4.10 Reflow

    Perceivable: Focus contrast

    Inaccessible content: When the “I want to give feedback” dropdown menu in the test's feedback form receives keyboard focus, only the color of its outline changes. The blue color does not provide sufficient contrast against its background. In the “Save and continue later” modal dialog of the feedback form, the contrast between the close button and its background is insufficient. Success criterion not met: WCAG 1.4.11 Non-text Contrast

    Operable: Modal window keyboard navigation

    Inaccessible content: On some browsers, scrollable areas do not automatically receive keyboard focus. As a result, for example in Safari, users relying solely on keyboard navigation in a zoomed view may not be able to access the full message contained within the modal dialog. Success criterion not met: WCAG 2.1.1 Keyboard

    Operable: Keyboard trap

    Inaccessible content: If a radio button group on a IT Security test page in Moodle is empty and the user does not wish to make a selection, it is not possible to move forward from the group by pressing the Tab key. The user cannot reach the “Previous page” or “Next page” buttons, meaning that navigation on the page is only possible backwards. This issue occurs in Chrome and Firefox browsers (at least in Chrome version 147.0.7727.117 and Firefox version 150.0.3). Success criterion not met: WCAG 2.1.2 No Keyboard Trap

    Operable: Focus management and order

    Inaccessible content: When the user activates the “Take exam” button in Moodle, a modal dialog opens. If the dialog is closed, keyboard focus is not returned to the “Take exam” button. The modal dialog itself receives keyboard focus even though it is neither an interactive element nor a scrollable region. It should not be included in the focus order. If the user has selected an option in a radio button group on the IT Security test page in Moodle, the selection can be removed using the “Clear my choice” button. However, focus is not moved anywhere afterwards. While taking the test, keyboard and screen reader focus are not explicitly managed when a new view is loaded. As a result, the focus location is determined unpredictably depending on the browser and screen reader.

    When filling in the test's feedback form, keyboard and screen reader focus are not managed consistently, for example to the next question. Instead, the user must navigate to the question from an arbitrary location on the newly loaded view. Success criterion not met: WCAG 2.4.3 Focus Order

    Operable: Link naming

    Inaccessible content: In the test's feedback form, there is a link labelled “Click here”, which does not describe its destination or purpose. Success criterion not met: WCAG 2.4.4 Link Purpose (In Context)

    Operable: Visible focus

    Inaccessible content: In the test's feedback form, the “Click here” link does not receive any visible focus indicator during keyboard navigation. Success criterion not met: WCAG 2.4.7 Focus Visible

    Operable: Visible name not included in accessible name

    Inaccessible content: In the Moodle course area navigation, there is a small “x” button whose name is shown on hover and focus as “Close course content”. However, the visible label is not included in the button’s accessible name. On the IT Security test pages, there is a function labelled “Flag question”. However, the accessible name of the element is “Flagged”, meaning that the visible label is not included in the accessible name. In the block drawer navigation, there is a small “x” button whose name is shown on hover and focus as “Close block drawer”. However, the visible label is not included in the button’s accessible name.

    When the test's feedback form is in an error state, an error summary element is displayed. It contains links whose visible labels are not included in their accessible names. Success criterion not met: WCAG 2.5.3 Label in Name

    Understandable: English element in Finnish UI

    Inaccessible content: In the “Save and continue later” modal dialog of the test's feedback form, the close button label is in English (“Close”) within an otherwise Finnish-language user interface, without a separate language attribute. In practice, the label should be translated into the language of the user interface. Success criterion not met: WCAG 3.1.2 Language of Parts

    Robust: Incorrect ARIA attributes

    Inaccessible content: In the Moodle course area page navigation, the selected page is indicated with the aria-selected attribute, which does not work correctly in the current structure. Success criterion not met: WCAG 4.1.2 Name, Role, Value

    Robust: Unnamed landmarks

    Inaccessible content: In the Moodle course area, there are multiple navigation landmarks, but they have not been given distinct accessible names for users to be able to differentiate them from one another. Success criterion not met: WCAG 4.1.2 Name, Role, Value

    Robust: Unnamed buttons

    Inaccessible content: In the Moodle course area page navigation, there is a small “x” button that does not have any accessible name. In the block drawer navigation, there is a small “x” button that does not have any accessible name. Success criterion not met: WCAG 4.1.2 Name, Role, Value

    Robust: Unnamed form elements

    Inaccessible content: In the test's feedback form, either the “When you want to continue, go to the link below” or the “Your email address” field does not have a programmatically associated name. Success criterion not met: WCAG 4.1.2 Name, Role, Value

    Robust: Missing feedback

    Inaccessible content: If the user has selected an option in a radio button group in the test's feedback form, the selection can be removed using the “Clear my choice” button. However, focus is not moved anywhere afterwards, and the action is not confirmed for screen reader users either. Success criterion not met: WCAG 4.1.3 Status Messages

    Robust: Misleading feedback

    Inaccessible content: When filling in the test's feedback form, the error summary updates as the user corrects identified errors. After the user has corrected the final error, the screen reader still announces the message “The following questions need to be checked before proceeding:” even though no list of errors remains below it. This gives a misleading impression of the form’s status, particularly for screen reader users. Success criterion not met: WCAG 4.1.3 Status Messages

    Did you notice an accessibility issue in our digital services?

    Let us know using the online form in the Webropol service. We will do our best to correct the issue.

    The regulatory authority

    If you notice accessibility issues on the site, please first provide feedback to us, the administrator of the website. Responding may take up to 14 days. If you are not satisfied with the answer or do not receive an answer within two weeks, you may file a complaint with the Finnish Transport and Communications Agency Traficom Digital Accessibility Supervision Unit. Traficom’s accessibility requirements website (saavutettavuusvaatimukset.fi) has detailed instructions on how to file a complaint and how the issue will be handled. 

    Contact information of the supervisory authority 

    Finnish Transport and Communications Agency Traficom
    Digital Accessibility Supervision Unit
    www.webaccessibility.fi
    saavutettavuus@traficom.fi
    telephone switchboard 029 534 5000

    Give feedback

    The instructions site of the University of Helsinki's IT Helpdesk helps you with IT-related issues related to your work. Let us know how we can improve our instructions. We greatly appreciate your feedback!

    How would you improve these instructions?
    Back to top