Yesterday we looked at why cyber security matters. Today we look at the people who protect personal data every day, and why an annual training module on its own rarely changes what they do.
Most cyber attacks involve a person: a link clicked, a login shared, a request approved. In a school, the data behind that click is usually personal data about children and staff, so one mistake can become a data breach and a safeguarding issue. Phishing was by far the most common threat facing schools in the government's latest survey, and attackers are increasingly using AI to make phishing messages more convincing and harder to spot. That means the old advice to look for spelling mistakes and odd wording is no longer enough on its own. Data Protection
Awareness and training are not the same thing
Awareness is the "what" and the "why": what phishing is, and why a strong password matters. Training is the "how": how to spot a suspicious message, how to report it, how to set up multi-factor authentication. You need both, but neither changes behaviour until people practise it.
From passive training to active vigilance
- Passive: a once-a-year module completed to tick a box. Active: short, regular reminders, such as a five-minute slot in a staff meeting, a poster or a newsletter tip, that keep security in people's minds.
- Passive: generic examples. Active: examples that fit the role. Finance and office staff face invoice fraud and impersonation, teachers face fake login pages, and leaders face fake requests from "the headteacher" or "the trust".
- Passive: "Don't click suspicious links." Active: a simple habit anyone can follow. Pause when a message creates urgency, check it another way (for example, phone the person on a number you already have), and report it.
- Passive: embarrassment when someone is caught out. Active: thanks for reporting, including near misses and mistakes.
- Passive: measuring who has completed the course. Active: measuring behaviour, such as how many suspicious emails are reported, how quickly, and how many people click in a phishing simulation.
Reporting is also a data protection issue. If a mistake involves personal data, the school may need to report a notifiable breach to the ICO within 72 hours. Staff who feel safe to speak up quickly give you the best chance of acting in time. DPE customers should report the data breach on the Knowledge Bank platform.
What the DfE expects
The DfE's cyber security standard includes "Create and implement a cyber awareness plan for students and staff". In summary:
- Cyber training should be given at least annually, or more often if there is a known cyber risk.
- It covers students, staff, at least one governor or trustee, and anyone else with a login, such as supply teachers and agency workers, who should be trained as soon as feasible. Ideally anyone who has access the organisation's systems.
- It should be age-appropriate and suited to your risks. Topics include phishing and social engineering, password security, multi-factor authentication, the physical security of devices, removable media, online safety, how to report a cyber incident or a personal data breach, and data protection.
- Everyone with access to the network should sign up to an acceptable use policy.
- The headteacher is accountable, and the SLT digital lead coordinates the work with IT support, the DPO and the designated safeguarding lead.
- If you are a member of the risk protection arrangement (RPA), you must evidence that relevant users complete the free NCSC training every year.
This sits within schools' statutory duty in KCSIE to keep children safe online, which includes having appropriate cyber security measures in place. Read the full standard here: DfE Cyber security: core standard.
Try this in your school this week
- Book a five-minute cyber slot in your next staff meeting and share one real example (look on our News page for ideas).
- Make reporting easy. Tell everyone who to contact, in one sentence, and make sure they know they won't be blamed.
- Run a phishing simulation and use the results to guide your next reminder, not to name individuals.
- Include your governors. The DfE expects at least one governor or trustee to complete cyber training.
💡 Today's Cyber Tip: Pause, check, report
If an email or message creates a sense of urgency, pause before you act. Check the sender another way, such as calling them on a number you already have, before you click, pay or share anything. If you think you've already clicked, report it straight away. A quick report limits the damage.
Free training and resources
DfE and NCSC
- DfE Cyber security: core standard
- NCSC Cyber Security Training for School Staff (free; the RPA training that must be evidenced annually)
- NCSC Top Tips for Staff interactive video
- NCSC cyber security information cards for schools
- DfE Cyber Security Hub
- NCSC questions for school governors
- NCSC Exercise in a Box (practise your response to an incident)
Data protection
- ICO: Training and awareness (part of the Accountability Framework)
- ICO short training videos
- DfE guidance: managing breaches of data
Data Protection Education
- Where's Harry the Hacker? (a free, interactive spot-the-risk resource)
- Drip feed posters
- Data Protection and Cyber Security (Inset Day) training ideas
- How KCSIE is linked to cyber strategy
- Training courses
DPE Knowledge Bank Guidance and Support
Our DfE Digital Standards Tracker helps you track your cyber resilience and your progress against the standards: DfE Digital Standards Tracker
If you're a Knowledge Bank customer, you can add all your staff, including governors and trustees, and assign courses: Assigning courses to staff using to-dos. You can also include a phishing campaign as part of your training.
Review our Cyber Security Best Practice Area for micro learning, support, guidance and policies.
