08
September
2026

Listening to the Community: The Origins of the Secure Research Environments Series

Subscribe for more like this

Share

By Jason Armbruster - CLASS Consultant for Internet2

The Internet2 CLASS Secure Research Environments series was born from recurring questions in the research and higher education (R&E) community: Why is it so hard to build a secure environment for regulated research, and why does so much of the hard part have almost nothing to do with technology? 

For years, those questions kept surfacing in the cloud and research-computing community that Internet2 convenes. Institutions were building “secure enclaves” with strict controls on how data could move in and out, and finding that the controls and the researchers were often at odds. The very people the enclave was meant to protect frequently found it too restrictive to use. 

Meanwhile, institutional support for research was scaling up fast, and federal compliance pressure — CUI handling, NIST SP 800-171, the arrival of CMMC (Cybersecurity Maturity Model Certification), and evolving National Institutes of Health data-sharing expectations — was turning a specialized concern into something nearly every research institution would have to face.

Peers were learning in parallel, pursuing CMMC, maturing their cloud teams, and moving from hand-built environments toward infrastructure-as-code. 

The knowledge existed. What was missing was a way to share it.

An idea crystallized at AWS IMAGINE 2024. Over lunch, people from Internet2, AWS, and the R&E community floated an appealing thought – CLASS already runs hands-on “barn-raising” events, so could we do one for secure research enclaves, with everyone leaving the room with a working environment? 

We concluded that a true cookie-cutter build wasn’t realistic; these environments depend too heavily on local policy, existing infrastructure, and technology choices. 

Through late 2024 and into early 2025, the topic kept resurfacing, most notably in the Cloud Services Technology Architecture Advisory Committee (CSTAAC), the community group that advises Internet2’s NET+ cloud program on where to invest next. 

CSTAAC is one of the clearest channels institutions have to steer Internet2 toward what the community actually needs. Its members, drawn from across R&E, help set the direction of the cloud program and secure research enclaves kept coming up there.

If your institution wants to play a larger role in shaping information-sharing at Internet2, advisory groups such as CSTAAC are where that happens.

Learn more about Internet2 community groups — and how you can get involved — on the Internet2 website.


Next Steps for the R&E Community and the Secure Research Environments Series

That input is a big part of why the Secure Research Environments series exists. By summer 2025, Internet2 committed to building the series and brought in a consultant to lead the work. 

The first job wasn’t to design sessions. It was to listen.

Those conversations kept returning to a hard truth. Plenty of institutions had attempted technical implementations of secure research environments, and many struggled. 

The technology usually wasn’t the problem; the organizational context around it wasn’t aligned. Ownership was unclear, governance was thin, and compliance responsibilities lived in offices that had never been brought to the table. 

The result, time and again, was an environment that got built but barely used.

That insight became the backbone of the series. Rather than jump straight to technical design, we designed the series to address organizational context first: 

  1. Strategy – Who owns research security, how to organize the right people, and what governance looks like
  2. Design – Technical patterns, controls, and provider approaches
  3. Implementation – Moving into action

Strategy comes first as a deliberate response to watching technically sound projects fail for organizational reasons.

We also chose not to ship a single “reference secure research environment” and tell everyone to copy it. 

As we consulted with regulators, community cybersecurity working groups, and established services, the real-world requirements proved too diverse for a one-size-fits-all solution. A minimal “toy” SRE would have looked tidy in a slide deck and helped almost no one. 

The more useful path was to share patterns institutions can adapt. That’s also why this is genuinely a community effort, facilitated in collaboration with the Regulated Research Community of Practice and the CaRCC Research Cybersecurity Interest Group

The series launched in early 2026, and Phase 1 carried the community through the strategic questions that had to come first. 

We recapped that phase in two posts, What We’re Up Against and How We Move Forward, and then moved into the Design phase, where strategy turns into architecture.

If you’re navigating these challenges at your own institution, the series is still going, and there’s still time to get involved.

ICYMI