π§Έ πΌ As digital technology continues to increase in our educational settings, Early Years settings are increasingly integrating digital tools into their operations. While this might enhance efficiency and communication, it also raises concerns and challenges about cyber security and data protection.
πWe've updated our end of term and end of year guidance, alongside advice for privacy considerations for special occasions (which also normally occur at the end of term, such as Christmas).
π’ It's important to be prepared for when a cyber incident happens to you. Part of that preparation should include having a Cyber Incident Response Plan, and part of that plan should include how to communicate, who does the communication and what they should say.
π A digital technology contracts register is a lit of all the contracts in your organisation with external suppliers for the supply of digital technology products and services.
We are sharing some of blog posts by school ICT technicians and ICT managers that are giving their advice about keeping your school cyber secure and resilient.
π The DfE have published several updates to the DfE Digital Standards, updating the Filtering and Monitoring Standards, the Digital Leadership & Governance Standards and the Broadband Internet Standards for Schools and Colleges. We give our view on what that means and more details about the updates.
π¦ CCTV systems play a critical role in maintaining safety and security in organisations. In schools, for example, it might help deter inappropriate behaviour, prevent unauthorised access and damage to property.
πποΈπ» Dark data is data that is unused but still might be stored somewhere in an organisation, usually kept in unstructured and unsecured repositories or storage.
While we are focusing on cyber security and cyber resilience in October, Ofqual is reminding schools and colleges of the importance of cyber security after a poll highlighted the risks associated with poor cyber hygiene.
We are often asked for advice on where to search for information and data when you receive an information request. The ICO has published a checklist with guidance.
π’ We would like to announce that Data Protection Education are sponsoring the data protection discussion forum with the Association of Network Managers in Education.
A high school in south London was closed for the first part of this term due to a ransomware attack. Students were sent home advising parents that the school would be closed for three days while all staff devices were 'cleansed'.
Follow us on social media for the latest updates, exclusive content, and insights into data protection best practice, cyber security and online safety.
π‘οΈβ Gone are the days when cyber security issues meant accidentally downloading a virus, it has grown to mean so much more, where data and identities are stolen, fraud is committed and businesses can be shut down from a cyber attack. With that in mind we have created a cyber security best practice area to help guide and support your data protection compliance.
The data protection officer is mentioned many times in the DfE Digital Standards for Schools and Colleges as someone that should either be informed or consulted with. As part of that consultation process, we would like to announce our new DfE Digital Standards for Schools and Colleges Tracker.
We are launching a new best practice area which has all the policies, documents and posters in one place. You can find this page in our main best practice area:
The recent news has been full of the global IT outage that affected many systems over the weekend, including airlines and patient access. Although the incident was not caused by a cyber attack, it is important to note that it was a cyber incident which affects everyone.
A cyber incident is an event with threatens the confidentiality, integrity or availability of information systems, networks or the information they contain.
Cyber incidents can be intentional or accidental and can cause major disruptions. The recently reported CrowdStrike incident caused significant global disruption. While there are huge impacts to the affected systems, for which there are now fixes available, there will be an aftermath of 'unrest' where threat actors will use people's vulnerability and concern to send phishing emails.
The NCSC has already reported an increased in phishing activity as opportunistic and malicious actors seek to take advantage of the situation. The emails could be aimed at organisations or individuals.
Article images created using Microsoft Copilot AI. Micro Learning video created using Vyond AI.
What to do in the event of a Cyber Attack
Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body.
TheSLTdigital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to:
Police investigations may find out if any compromised data has been published or sold and identify the perpetrator.
Preserving evidence is as important as recovering from the crime.
Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).