Be cyber aware in orange text on a blue background above a mobile phone and padlock. Also the Data Protection Education logo

The time following a cyber attack can be very stressful, and in the heat of the moment it can be difficult to know what the best thing to do between working out what went wrong, how to recover and what went missing, it can be hard to know where to start first.

We provide some help and guidance in our Information and Cyber Security Best Practice Area, which also includes the checklist:  document What to do immediately after a Cyber Attack(58 KB) .

A smart mobile phone with emojis relating to social media coming out the surface on a white background.  Text: Data Protection Education Social Media Policy

We've created a model Social Media Policy.  The policy outlines guidelines and expectations for the use of social media platforms by individuals and employees associated with an organisation. 

The primary aim of the policy is to ensure responsible, respectful and effective use of social media while protecting the organisation's reputation and interests.
Robot pointing their finger on a computer screen in blue

For those outside the computing world, it feels as though AI (Artificial Intelligence) has suddenly appeared and having a huge impact on the rest of the world.  Artificial intelligence is intelligence demonstrated by computers, as opposed to human or animal intelligence.  'Intelligence' encompasses the ability to learn to reason, to generalise and to infer meaning. 

Freedom of Information text on a key on a white computer keyboard

The Information Commissioner's Office have recently put Leicester City Council forward as an FOI (Freedom of Information) best practice example. An FOI refers to a request under the Freedom of Information Act. The Act allows any individual or organisation to make a request to a public authority for information they have recorded. 
Ransomware Vice Society in pink writing

This article was originally published in January 2023, but has been updated with some additional information, following further ransomware attacks on schools in the UK. Highly confidential documents from 14 schools in the UK have been leaked online by hackers.  The Vice Society has been behind a high-profile string of attacks on schools across the UK and the USA in recent months.

Photo of a laptop logged into the Data Protection Education Knowledge Bank, showing the Dashboard

If you are a group of organisations such as a multi academy trust and a member of the central team,  it can be useful to view all of the organisations/schools and the main organisation/trust details all at once in several of the Knowledge Bank pages to give an overview.  When your organisation are added into the Knowledge Bank, we will have tagged them all appropriately.
Cartoons of many people on a poster with hidden data and cyber breaches

Here's a little fun. It's our not-so-good friend Harry the Hacker. He's all over the place...can you find him?
Be Cyber Aware in orange text on a blue computer with Data Protection Education Logo

This article is one in a series of articles about raising cyber awareness in an organisation.  We visit a number of organisations through our data walks and often discuss the use of USB sticks with staff and are told that they are not allowed.  Yet we will see them in use during the walk.  A verbal/written policy is not the same as prevention and detection.  This article will discuss methods for detection and why.

The word cyber insurance in blue on a computer screen with a finger pointing at it

This article is about cyber insurance in the public sector, particularly in relation to schools.  Cyber insurance is a special type of insurance intended to protect businesses from internet-based risks, and more generally risks relating to information technology infrastructure and activities.  It is also known as cyber liability insurance or cyber risk insurance. 

Cyber attack in red text on a computer screen with blue computer code

This article is an article about DDoS attacks and is part of a series of articles about different types of cyber attacks. Denial-of-service (DoS) attacks are a type of cyber attack targeting a specific application or website with the goal of exhausting the target system’s resources, which, in turn, renders the target unreachable or inaccessible, denying legitimate users access to the service.

Cyber attack written in computer text on a computer in red

This article is about a recent cyber attack on Leytonstone School.  The school in Waltham Forest has been closed since half term after it was targeted and a significant amount of personal data was accessed.

The school is still closed to all pupils other than those taking their GCSEs because the school currently does not have a single central record (SCR), sometimes referred to as a single central register.  An SCR is a statutory requirement for all schools and academies in England and Wales to keep and maintain one single record of pre-appointment vetting checks, regulated activity and recording information of all staff. The record is normally kept up to date by a member of the admin staff, but overall responsibility lies with governors (or equivalent) and delegated to headteachers.  It is an essential safeguarding document and must be maintained, reviewed and audited on a regular basis.  It will probably be one of the first documents that Ofsted will ask to see.  Any guidance relating to the SCR should also be read in conjunction with the current version of the Keeping Children Safe in Education (KCSIE) document.

There is no defined format for the SCR and most schools hold it electronically as a password protected Excel document.  As well as employees, it should also include:

  • any volunteer who is in regulated activity
  • people brought into the school to provide regular additional teaching or instruction but who are employed by another organisation such as peripatetic music teachers, sports coaches etc.
  • supply teachers
  • contract staff such as cleaners or caterers
  • Governors
  • Members of the proprietor body (trustees or directors) in independent schools including academies

As a result of the cyber attack at Leytonstone School there is also no WiFi and phone system, but it is the missing SCR that prevents the school from opening.  Our advice would be to always ensure there are secure offsite (cloud) backups of essential files, in addition to local backups.  The security of the SCR should be part of the school's business plan which should be discussed regularly at governing body meetings.  Review:  alongside Governors and Data Best Practice Area to understand how governor responsibilities relate to business continuity and cyber strategy.

View our Information & Cyber Security Best Practice Library for cyber help and guidance.

Download our Business Continuity Template.

We would also recommend viewing the National Cyber Security's pages that provide cyber security advice for schools, which includes free training: NCSC Cyber Security training for schools.
We provide additional Cyber Security Training: How to avoid a data breach: Information and Cyber security.

Further details about what has happened at the school can be viewed in this article by the Evening Standard: Leytonstone School forced to close after IT system hacked.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Blue data breach text on blue cyber background,  and orange reprimand stamp

A reprimand has been issued by the ICO to Parkside Community Primary School in relation to the infringements of Article 5 (1)(f), Article 24 (1) and Article 32 of the UK GDPR. This article discusses the reprimand and looks and what schools can do to avoid this type of breach.

Some of the information in the reprimand document is redacted, but the main details are:

  • A safeguarding email was shared in the classroom via the electronic whiteboard.
  • The ICO has found that the school disclosed personal data inappropriately, including special category data, in a classroom environment.

The breach is in relation to the UK GDPRs security principle, meaning that the school failed to prevent unlawful disclosure of personal data.
The school also failed to implement appropriate technical and organisational measures to ensure personal data is kept secure under Article 32 of the UK GDPR.

The findings were that the school did not have:

  • Detail in the data protection policy of when it was appropriate to open emails containing personal data.
  • Policies relating to the use of the school's electronic safeguarding system.
  • Written guidance for staff on the classification of emails, i.e. there was no labelling or system to indication that an email contained sensitive information.
  • Procedures or guidance relating to when it is appropriate in the school day to open emails generated by the electronic safeguarding system.
  • Procedures or guidance in relation to the safe operating of electronic whiteboards,  especially when screen sharing.

There were several steps taken and further action recommended which all schools should take into consideration when using these kinds of systems and when handling special category data in a busy school environment:

  • The governor responsible for the strategic management of data protection reviewed current practices and made recommendations. Many schools we speak to do not have this type of governor in place.  Consider reviewing our Governance Best Practice Library.  This article discusses the governor responsibilities in more detail: Cyber responsibilities for Governors/Trustees in schools
  • Formal guidance was given to staff about how data breaches should be reported. This is something usually discussed with our customers during our consultations.  All staff should know how to recognise a data breach and the procedures for reporting one.  Consider reviewing our full How to avoid a data breach training course, or invite staff to view our 5-10 minute Data Breach Learning Nugget.
  • Staff have been instructed that all alerts sent by the electronic safeguarding system should be read at specific times of the day and never when children are present or in the vicinity of the classroom. 
  • All staff have been instructed to use data classification such as SENSITIVE/HIGHLY SENSITIVE in the subject line of an email. Such emails should only be read before and after the school day. Review our Information Classification Best Practice Library in line with your email policy.
  • Governors are to be alerted to an incident as soon as it is reported to the Head.  Our Knowledge Bank allows schools to add governors and trustees as users, so they can get an overview of data breaches: 
  • Cases of a complex and sensitive nature on the electronic safeguarding system can only be accessed by the Headteacher, Deputy Headteacher and Parental and Pastoral Officer and shared with relevant members of staff on a need-to-know basis at scheduled meetings. Consider access control procedures, review our Information and Cyber Security Best Practice Library.
  • All staff and governors are to receive data protection refresher training.  We provide a 20-minute GDPR Refresh Course which can be assigned to both staff and governors by an administrator: 
  • All staff are to be issued with the school's data protection policy and to be familiar with its content.
  • The data protection policy has been reviewed.  The updated policy instructs staff how to report a breach, what constitutes a breach, and who to report it to and what happens once this has been done. Review our template policies:  document Model Data Protection Policy(208 KB)  and  document Data Breach Procedure(5.18 MB) .
  • All staff to sign an electronic document to confirm they have read and understood the data protection policy.  The DPE Knowledge Bank has a Compliance Manager tool that allows documents to be uploaded and assigned to staff to be read and signed within a set time period: 


The further actions recommended were:

  • Refresher training on the operation of electronic whiteboards for relevant employees with the emphasis on security and the relevant steps for employees to take to avoid a personal data breach when operating an electronic whiteboard.  Often the reseller or the manufacturer will offer free training or training videos about how to operating the equipment.
  • Ensure there is sufficient written guidance on the use of the electronic safeguarding system.
  • Consideration of refresher data protection training for all members of staff.  Both members of staff had failed to report the breach. Staff should understand the consequences of failing to report a breach, as mitigating action can lessen the effects of a personal data breach. Review our Data Breach Learning Nugget and Recognise a personal data breach drip feed poster.
  • Adequate technical and organisational measures should be in place to ensure the security and confidentiality of emails sent internally which include personal data, particularly when these contain sensitive and special category. Review Information and Cyber Security Best Practice Library.
  • The policies and procedures should have prominent, sufficient and adequate practical guidance for employees, including regular reviews and work to increase staff awareness.
  • All new processes should be tested.


The key points to take from the recommendations are that you should always be aware of where you are and who might see what you're working on.  Data classification and access controls are vital.  Special category requires extra security.

Consider all the advice above with what other safeguarding and special category data that you may have displayed around your school?  Consider using our Making the Rounds tool to do your own data walk or get in touch with your Data Protection Education School Consultant to do the walk with your or have a follow-up feedback meeting.

Use our  pdf DPE Quick Reference Guide(1.64 MB)  for practical advice on what can be displayed around schools.

The full reprimand can be read here: https://ico.org.uk/action-weve-taken/enforcement/parkside-community-primary-school/


Be Cyber Aware orange text on blue background with cartoon computer devices

This article is about firewalls and how they can help in your plan towards being cyber resilient.

What is a firewall?  Think of a firewall as an intruder detection system for your organisation's network.   It is a virtual barrier between your computer or network and the internet. Its role is to keep an eye on all the incoming and outgoing data, like a security guard watching the entrance to your house or office.  The main purpose of a firewall is to protect your computer or network from harm.  It helps to prevent unauthorised access, like hackers. It also helps to stop viruses, malware or other malicious software from infecting your system.  It acts as a shield, keeping your personal and sensitive information safe.

Your firewall may be managed by your IT or internet provider.  Often they will be at default settings, so it is good to ask your provider about the following:

  • Have functions, accounts and services not needed been disabled or removed?
  • Has the default password been changed and only shared with authorised personnel?
  • Has access to the admin interface from the internet been prevented - unless there is a clear and documented business need?
  • Is the admin interface protected by multi factor authentication?

Setting up a firewall can be a complex task but is often provided by your IT support or internet provider.

What kind of rules should be set?

  • Outgoing connections should be allowed - this allows you to browse the internet.
  • Unauthenticated inbound connections should be blocked.
  • Firewall rules should be approved and documented by the authorised individual for specific services which should be regularly reviewed.
  • Permissive firewall rules should be removed or disabled when they are no longer needed.
  • Access should be restricted to certain ports and regularly reviewed.
  • Specific IP addresses or ranges should be filtered and regularly reviewed.
  • Logging should be enabled.


Further guidance for schools can be found in the DFE document: Cyber Security Standards for Schools and Colleges.  The document discusses the importance of firewalls and how they make scanning for suitable hacking targets much harder - hackers will always try to find the easiest route for an attack so making it difficult makes an attack less likely.

Further help and advice can be found in our Information & Cyber Security Best Practice Library and further questions to ask can be found in our Information/Cyber Security Checklist.  The checklist covers the following areas:

  • Governance and policies
  • IT checks
  • Physical Checks


Firewalls also have vulnerabilities and hackers will always try to exploit vulnerabilities as discussed in this Computing article: Major firewall maker alerts customers to vulnerabilities.

Consider the use of secure methods and organisational devices for staff required to work from home.  Review our Work out of school Best Practice Area. Ensure that there is secure remote access, especially if a school server needs to be accessed.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Blue cyber aware cartoon showing computer and network and Data Protection Education logo

This article is about cyber attacks and data breaches that may go unreported due to the misconceptions about how organisations might respond to them.  The NCSC recently published an article about why transparency around cyber attacks is a good thing for everyone.
The NCSC and the ICO may work on a cyber attack together if an incident brings down a business, severely impacts national services and infrastructure or massively disrupts people's data-to-day lives, however they consider that a large number of attacks may go unreported.  The article talks about a number of myths:

Myth 1 - If I cover up an attack everything will be OK - of course it won't.  Every successful cyber attack that is hushed up, with no investigation or information sharing, makes other attacks more likely because no one learns from it.  Keeping your cyber incident a secret doesn't help anyone except the criminals.

Myth 2 - Reporting to the authorities makes it more likely the incident will go public.  Your confidentiality will be respected and both the NCSC and ICO don't proactively make information public, or share it with regulators without your consent.  Remember your regulatory responsibilities.

Myth 3 - Paying the ransom quickly to get the decryption key and restore services doesn't always help.

Myth 4 - I've got offline backups, I won't need to pay a ransom.

Myth 5 - If there is no evidence of data theft, you don't need to report to the ICO.  You should always start from the assumption that it has been taken.

Myth 6 - You'll only get a fine if your data is leaked.  This isn't necessarily the case.  A personal data breach is more than just a loss of data.

The full report is here: Why more transparency around cyber attacks is a good thing for everyone

We would always encourage staff to report any cyber attacks and data breaches. Visit our Information & Cyber Security Best Practice Library for support and guidance. Raise awareness with staff through training, posters and discussion.  Having a 'no blame' culture will encourage staff to report issues.
Ensure you have a Cyber Response Plan: Cyber Response Processes.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

coloured computer textm spelling Cyber Attack

A Dorchester school has recently suffered a cyber attack in the form of a Ransomware attack.
Following the attack the school has been left unable to use email or accept payments.
The school is working with the National Cyber Security Centre and the police to resolve the issue. The full article can be read here: https://www.bbc.co.uk/news/uk-england-dorset-65685607
T
he school remains open, with teaching adapted as needed and exams continuing as planned.

Comment from the headteacher:

A message from the headteacher, Nick Rutherford, to parents said:

“We are in liaison with our school Data Protection Officer and this data breach has been reported to the Information Commissioners Office (ICO) in line with requirements of the Data Protection Act 2018/GDPR. Every action has been taken to minimise disruption and data loss.

“The school will be working with Wessex Multi-Academy Trust, IT team and other relevant third parties (Department for Education, National Cyber Security Centre and police) to restore functionality and normal working as soon as possible.

“I appreciate that this will cause some problems for parents/carers with regards to school communications and apologise for any inconvenience. Please use the telephone absence line to report student absence, as staff cannot currently receive emails. Please also telephone the school should you wish to report any concerns or speak to a member of staff."
Quote source: https://planetradio.co.uk/greatest-hits/dorset/news/dorchester-school-cyber-attack/

Prof Alan Woodward, from the University of Surrey, has previously said schools are a "soft target". 

"IT is not their core business, they don't have big IT teams, and if they're all using standard software and a vulnerability is found in it, then the criminals will quite quickly realise that.

"The advice is never to pay. It sounds like a quick way out, but the prices are extortionate, and you're painting a big target on your back.

"Hackers sell what they call 'suckers lists' on the dark web, where they say 'these people will pay up', and often it can lead to further attacks," he added.

Data Protection Education are working with schools and trusts to build cyber resilience with data protection in mind:

View our Information & Cyber Security Best Practice Library for cyber help and guidance.

Download our Business Continuity Template.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Hands typing in a password field, showing the password field as asterisks

Malicious threat actors (hackers) are always developing new techniques to breach passwords.  This article lists the different types of password attacks and some defences/counter-measures which can be used to enhance password security.  In our experience, hackers are most successful at accessing school systems unlawfully using these methods.  Passwords continue to be a primary target for cyber criminals seeking unauthorised access to accounts.

Password security is a shared responsibility and proactive measures can go a long way in preserving online safety.

  1. Brute Force Attacks - involve systematically attempting all possible combinations of characters until the correct password is discovered.  Ways to mitigate brute force attacks are account lockouts or measures like CAPTCHA to slow the repeated login attempts down.
  2. Dictionary Attacks - the attacker uses a precompiled list of commonly used passwords, dictionary words, and known phrases.  By systematically trying each entry, they can gain access to an account.  Counter measures would include enforcing strong password policies, such as password complexity requirements.
  3. Phishing Attacks - involve the hacker tricking users into revealing their passwords through fraudulent means.  Attackers typically send deceptive emails, masquerade as legitimate organisations or create fake login pages to steal user credentials. To combat phishing attacks, individuals should be cautious while opening emails, double-check the authenticity of the websites and enable multi factor authentication to add an extra layer of protection.  View our article: A guide to multi-factor authentication.  Run a phishing campaign through our Knowledge Bank (which all our customers have access to).
  4. Keylogger Attacks - are malicious software of hardware devices designed to record a user's keystrokes, including passwords.  These captured keystrokes are then transmitted to the attacker for analysis.  To prevent keylogger attacks maintain up-to-date antivirus software, avoid downloading files from untrusted sources and use virtual keyboards when entering passwords on public computers.
  5. Rainbow Table Attacks - attackers use precomputed tables containing a vast number of password hashes and their corresponding plain text passwords. by comparing the stolen password hashes with the entries in the table, they can rapidly discover the original passwords.  Implementing robust cryptographic techniques can effectively mitigate rainbow table attacks.
  6. Credential Stuffing - exploits the fact that many users reuse passwords across multiple platforms.  Attackers obtain username-password combinations from data breaches on other websites and systematically try them on other platforms.  To combat credential stuffing, users must adopt unique passwords for each service and utilise password managers to generate and store complex passwords securely.

Defences and Counter-Measures

  • Use a complex password and multi factor authentication
  • Lock accounts after a number of successful attempts
  • Check your physical hardware
  • Run a virus scan
  • Monitor your account compromises. Use haveibeenpawned.com to check whether your email address is connected to any recent leaks and so vulnerable.
  • Enable encryption on your router
  • Use a VPN

Use our Password Checklist to see how robust your password policies and procedures are.

Further guidance from the NCSC about passwords: Password Policy: updating your approach.

Visit our Password Best Practice Library for help and guidance.

Read our article about passwords: Passwords - simplifying the approach.

ICO Password guidance: Passwords in online services.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Be Cyber Aware: Why regular software updates are important

Hackers and cyber criminals are continuously searching for vulnerabilities in software and systems to exploit for their own malicious gains.  

What are Zero-Day Vulnerabilities

Zero-day vulnerabilities refer to software flaws or weaknesses that are unknown to the software vendor and, consequently, unpatched at the time of discovery by cyber criminals.  These vulnerabilities are security holes that malicious threat actors (hackers) can exploit to gain unauthorised access to systems, steal sensitive information, disrupt services, or execute malicious code.

The term 'zero-day' signifies that software developers have zero days to respond to the vulnerability before cyber criminals potentially exploit it.  Once a zero-day vulnerability is exploited, it becomes known to the software vendor, and they can begin developing a security patch or update to fix the flaw.

The Dangers of Zero-Day Vulnerabilities

  1. Undetectable Attacks: Since zero-day vulnerabilities are unknown to the software vendor, they lack the necessary security measures to detect or prevent such attacks. Cybercriminals can infiltrate systems undetected, increasing the potential for data breaches and compromising privacy.

  2. Targeted Exploitation: Zero-day vulnerabilities are highly sought after by skilled hackers and state-sponsored cyber espionage groups. These sophisticated attackers can exploit the vulnerabilities for targeted attacks against specific organizations or individuals, amplifying the potential damage.

  3. Expanding Attack Surface: With the increasing interconnectedness of devices and the rise of the Internet of Things (IoT), the attack surface for zero-day vulnerabilities is expanding rapidly. From smartphones and laptops to smart home devices and critical infrastructure, any system connected to the internet can be susceptible to such attacks.

The Importance of Updates

Software updates play a pivotal role in countering the risks posed by zero-day vulnerabilities. Here's why regular updates are crucial:

  1. Patching Vulnerabilities: Updates often contain security patches that address known vulnerabilities, including zero-day exploits. By promptly installing updates, users ensure that the latest protections are in place, reducing the likelihood of successful attacks.

  2. Enhanced Security Measures: Updates not only patch vulnerabilities but also improve overall security measures. Developers continually refine their software to strengthen defenses against emerging threats, ensuring users have access to the most robust security features available.

  3. Stay Ahead of Cyber Criminals: Software vendors constantly monitor and analyze threats to identify vulnerabilities. Regular updates allow vendors to respond swiftly to emerging risks, closing security gaps before cybercriminals can take advantage of them.

  4. Protecting Personal Data: Updating software helps protect sensitive information, including personal data, financial details, and login credentials. Neglecting updates could expose users to identity theft, financial fraud, and other forms of cybercrime.

  5. Maintaining System Stability: Updates not only address security concerns but also improve system performance and stability. Regular updates ensure that software operates efficiently, reducing the risk of crashes, freezes, or other malfunctions that could be exploited by attackers.

Important information for schools:  you may need to check with your IT provider that they are regularly updating your network and systems as part of their regular maintenance routines.  Ensure you have allowed enough time for them to do this each week.

Microsoft Patch Tuesday

Microsoft fixes three zero-days in May 2023 Patch Tuesday

Cyber Checks

Complete our Information/Cyber Security Checklist to get a graphical (RAG) view of where your organisation is with Cyber Security.

Further information about zero-day vulnerabilities can be found here: NCSC Understanding Vulnerabilities.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

 

 

Cyber Attack: Wiltshire School

A Wiltshire secondary school has been severely affected by a targeted attack by hackers who demanded a ransom to restore access to its IT network.  The attack affected the school's local server, its website, internet access, Wi-Fi, printers and internal phone systems.

A full report can be read here: https://www.gazetteandherald.co.uk/news/23476464.hacker-demands-ransom-taking-control-wiltshire-schools/

The school's website was still down several days later.  An update a few days later was published here: https://www.gazetteandherald.co.uk/news/23484633.hardenhuish-school-cyber-attack-update-hackers-demand-ransom/

In the BBC report cyber expert, Prof Alan Woodward, from the University of Surrey, said schools are a "soft target". 

"IT is not their core business, they don't have big IT teams, and if they're all using standard software and a vulnerability is found in it, then the criminals will quite quickly realise that.

"The advice is never to pay. It sounds like a quick way out, but the prices are extortionate, and you're painting a big target on your back.

"Hackers sell what they call 'suckers lists' on the dark web, where they say 'these people will pay up', and often it can lead to further attacks," he added.

The full BBC Report can be found here: https://www.bbc.co.uk/news/uk-england-wiltshire-65411450

View our Information & Cyber Security Best Practice Library for cyber help and guidance.

Download our Business Continuity Template.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

 

Keeping your IT systems safe and secure

The ICO recently published an updated article aimed at small business with tips for IT security - this advice would also be applicable for schools and colleges.  

This table shows the advice from the ICO and how areas of the Data Protection Education Knowledge Bank can help and guide you in those areas. 

ICO Recommendation DPE Knowledge Bank Links
 Back up your data
 

 How secure is your server?

 Use strong passwords and multi-factor authentication

 Password Best Practice Library

 A Guide to Multi Factor Authentication

 Password Security Learning Nugget

  Be aware of your surroundings

 Information & Cyber Security Best Practice Library

 How to avoid a data breach: Information and Cyber Security Training Course

 Be way of suspicious emails

 Phishing Simulation

 Types of Phishing News Articles

 NCSC Cyber Security Training for School Staff

 Install anti-virus and malware protection

 Information & Cyber Security Best Practice Library

 Protect your device when it's unattended

 Information & Cyber Security Best Practice Library

 Physical Security

 Physical Security Learning Nugget

 Make sure your Wi-Fi connection is secure  Info/Cyber Security Checklist
 Limit access to those who need it

 Info/Cyber Security Checklist

Acceptable Use

 Take care when sharing your screen

 Working At Home Learning Nugget

 Working Out of School Best Practice Library

 Don't keep data for longer than you need it

 Records Management Best Practice Library

 Dispose of old IT equipment and records securely

 Info/Cyber Security Checklist

The full ICO article is here:  11 Practical Ways to Keep Your Systems Safe And Secure

Further ICO Password guidance: Passwords in online services

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

 

 

Types of Cyber Attacks: DDoS Attacks

This article explains what a DDoS attack is and how to manage if your organisation is attacked.

A DoS attack is a denial of service attack.  It occurs when users are denied access to computer services or resources, usually by overloading the service with requests.  Your server or your website will be repeatedly bombarded with requests for information or resources.  This overwhelms the system making it unusable and unavailable.

An attack becomes a 'distributed denial of service' (DDoS) when it comes from multiple devices.  This is the most common form of DoS attack on websites.

Further information from the NCSC about DDoS attacks can be found here: DoS Guidance NCSC

How does this affect schools/organisations?

Your organisation may be attacked even if you do not have a high profile website.  Your organisation's website might be attacked or your server or systems.

Hampshire Alert recently posted an increase in the volume of attacks: Increase in DDoS attacks

DDoS-for-hire services are now openly available online, which makes it a relatively cheap and easy type of cyber attack.

View our Cyber/Information Security Best Practice Area for more guidance and checklists about Information and Cyber security.

How do we know if we are being attacked?

  • If your website is suddenly unavailable.
  • Small attacks over time (check system event logs).
  • The attack may be a distraction for other cyber crimes or fraud.  Attackers may use this as a way to check your system's vulnerabilities as a way to prepare for another type of attack at a later date.

Further information can be found at: Action Fraud

How to prevent a DDoS attack?

Generally, these types of attacks are prevented by having modern and robust cyber security tools in place.

The NCSC have a downloadable document explaining how to prepare for such attacks: Prepare for denial of service (DoS) attacks

Aside from the technical aspects of protecting systems, it is always recommended to have a cyber response and business continuity plan in place.  Ensure all staff know what to do in the even of a cyber attack. 

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Types of Cyber Attacks: Phishing

This article is linked to a series of articles about different types of Cyber Attacks. They can be viewed in the Information/Cyber Security News section of the Data Protection Education website or as part of the Information & Cyber Security Best Practice Area. Each article discusses a different type of cyber attack, steps to try to minimise the risk and guidance.

Phishing is a type of cyber attack in which an attacker tries to trick the victim into giving away sensitive data, such as passwords, credit card numbers, or other personal data.  This is typically done by posing as a legitimate organisation, such as a bank, a social media platform, or an email service provider.

Phishing attacks can take many forms, but they often involve the use of emails or messages that appear to be from a trusted source, but are actually designed to lure the victim into clicking on a link or downloading an attachment that contains malware or other malicious code.  The attacker may also use social engineering tactics to convince the victim to provide sensitive information, such as by posing as a customer service representative or a technical support agent.

The Anti Phishing Working Group's latest report analyses phishing attacks: APWG Summary third quarter 2022

The DfE reports: Of the 39% of UK businesses who identified an attack, the most common threat vector was phishing attempts (83%). Full survey is here:

DfE Cyber Security Breaches Survey 2022

Office for National Statistics - Phishing attacks - who is most at risk?

 

 

How can you protect  yourself and your organisation?

The National Cyber Security Centre (NCSC) – a part of GCHQ – has published practical advice on how to spot phishing attempts and report suspicious messages.

If you have any doubts about a message, contact the organisation directly.  If you think an email could be a scam, you can report it by forwarding it to: This email address is being protected from spambots. You need JavaScript enabled to view it.

How do you train your staff to spot phishing emails article:

Raise awareness of staff through training (also NCSC cyber security training for staff) and posters

Remind staff about the importance of passwords. View our password checklist.

Ensure virus software is running.

Be wary of public Wi-Fi.

Keep software up to date. View our Cyber/Information Security Best Practice Area.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

 

Types of Cyber Attacks: The Insider Threat

This article is linked to a series of articles about different types of Cyber Attacks. They can be viewed in the Information/Cyber Security News section of the Data Protection Education website or as part of the Information & Cyber Security Best Practice Area. Each article discusses a different type of cyber attack, steps to try to minimise the risk and guidance.

The Cybersecurity and Infrastructure Security Agency (CISA) defines insider threat as the threat that an insider will use their authorised access, intentionally or unintentionally to do harm to the organisation's mission, resources, personnel, information, equipment, networks or systems.  This can include theft or unauthorised access to sensitive data, installing malware or other malicious software, or disrupting normal operations.

They are people who have authorised and legitimate access to a company's assets and abuse it either deliberately or accidentally.

There are three insider threat sources:

  1. Negligent or inadvertent users
  2. Criminal or malicious insiders
  3. Attackers that stole user credentials

How might an insider threat attack happen?

  • People rushing to finish a task or project who have access to sensitive data or admin rights can cut corners.
  • Remote working opens the organisation to personal devices being used and data intervertently being downloaded.
  • People losing devices or having devices stolen.
  • Clicking on a phishing email.
  • Not installing regular updates.
  • Installing non-organisation approved software which has malware.
  • Leaving devices open to physical attacks such as a server not in a locked cupboard or room, is open to accidental spillages, USB devices being plugged in, turning off of all the organisation's systems by pressing the power button.
  • Lack of IT expertise in the organisation could mean that someone unwittingly does not have all the appropriate systems controls in place.
  • Deliberate sabotage.

How can you reduce the risk of a cyber attack?

Remember: insiders don't act maliciously most of the time - a cyber attack is sometimes caused by a disgruntled employee but it's mostly by accident or negligence.

The role of cyber negligence in insider threats

 What to do in the event of a cyber attack?

Tell someone!  Report to IT. Report to SLT. 

Unplug the computer from the internet by removing the ethernet cable or turning the Wi-Fi off.

If you are a victim of a ransomware attack we would recommend reporting this to Action Fraud: https://www.actionfraud.police.uk/ as well as your data protection officer so they can advise about the data loss.  Most cyber crimes like these will also need to be reported to the ICO by your data protection officer.

Isolate the infected device and pass to IT 

Always ensure there are backups you can restore from.

Little Guide to ACTION FRAUD

Why your data is profitable to cyber criminals

This article covers ways in which cyber criminals profit from their cyber crimes.  Often we might think our data, if it is not financial, is not interesting or profitable to hackers, so this article discusses the different types of data that are stolen and why.

Financial data is the main data type that we all think of when considering why a hacker might steal information.  Financial data can be sold to various individuals for different purposes. It is not uncommon for thousands of records to be sold within 24 hours, making this a lucrative endeavour for the attacker and market owner.  More about this can be read in this blog by a reformed black hat hacker: Cybercriminals, Debit Cards, Credit Cards, and Underground Markets

Personal data is relatively easy to steal and will be information such as names, addresses, phone numbers, email addresses and national insurance numbers.  They can use this information to create fake identities or commit identity theft, which can then allow them to access bank accounts, credit cards and other financial resources.  This is why hackers find school MIS data attractive. WH Smith Recent Cyber Attack is a recent personal data attack.  The NCSC have written a paper about the cyber threat to Universities: https://www.ncsc.gov.uk/report/the-cyber-threat-to-universities

Intellectual property is when hackers steal such things as patents, trademarks, copyrights and trade secrets.  They can sell this information to competitors or use it to create their products.  This often happens between governments.  MI5 report a new body has been created to help the UK combat national security threats. - See more at: https://www.mi5.gov.uk/news/new-body-will-help-the-uk-combat-national-security-threats#sthash.hgLZxMI8.dpuf

Ransomware is when hackers encrypt data on a victim's computer and demand payment in exchange for the decryption key. This can be especially lucrative for hackers who target businesses or organisations that rely on their data to operate, such as schools.  See our previous article about schools that have been targeted in this way recently: VICE SOCIETY -  Ransomware attacks on schools.

Health data is stolen such as medical records or insurance information.  This information is used to commit identity theft or insurance fraud.  NHS Ransomware Attack.

Hackers profit from the data they steal in various ways, including:

  1. Selling the data on the dark web: The data can be sold to other cybercriminals who can use it for their nefarious purposes.

  2. Using the data themselves: Hackers can use the data to access accounts, commit identity theft, or create fake identities to commit further fraud.

  3. Ransomware payments: If the hacker uses ransomware, they can demand a ransom payment in exchange for the decryption key.

  4. Blackmail or extortion: In some cases, hackers may threaten to release sensitive information unless the victim pays a ransom or takes some other action.

In conclusion, hackers steal a variety of data from their victims, and they profit from this data in different ways, depending on the type of information stolen and the hacker's goals. To protect against these threats, it is essential to take cybersecurity seriously and implement appropriate security measures.

Visit our Info/Cyber Security Best Practice Area for help, guidance and support for cyber cyber security and data protection.

This website lists all the cyber crime statistics for the UK: https://proprivacy.com/blog/latest-uk-cybersecurity-cybercrime-statistics-2020-2022

What to do in an attack:

Tell someone!  Report to IT. Report to SLT. 

Unplug the computer from the internet by removing the ethernet cable or turning the Wi-Fi off.

If you are a victim of a ransomware attack we would recommend reporting this to Action Fraud: https://www.actionfraud.police.uk/ as well as your data protection officer so they can advise about the data loss.  Most cyber crimes like these will also need to be reported to the ICO by your data protection officer.

Isolate the infected device and pass to IT 

Always ensure there are backups you can restore from.

Remember – ‘Hackers don’t break in they login’!

Using WhatsApp in Schools

This article is about the use of WhatsApp as a communication tool in schools and recent vulnerabilities. It discusses school staff using WhatsApp as a communication method for school business.

We are sometimes asked by staff whether it is OK for staff to be in a WhatsApp group for important school messages. Staff often wish to use it because it is an easy way to communicate and a platform that a lot of people are familiar with.  It is also free. There are issues around this:

  • Non staff members can easily be added
  • All personal mobile numbers can be seen by everyone in the group
  • Someone needs to take responsibility for removing staff from the group that have left school
  • There is no user access control
  • Use of personal devices for school business

The ICO called for a review into the use of private email and messaging apps within government as there is a lack of controls: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/07/behind-the-screens-ico-calls-for-review-into-use-of-private-email-and-messaging-apps-within-government/

WhatsApp says is should not be used for business; it is against their terms and conditions. Although WhatsApp have a business app, this is for businesses to link with their customers (ie the public), not designed for private chat within an organisation: https://support.safeguardinginschools.co.uk/article/36-why-schools-shouldnt-use-whatsapp

This article highlights the lack of user management that can create security issues: https://www.beekeeper.io/blog/why-you-shouldnt-use-whatsapp-for-business-communication/

WhatsApp has previously been fined for data breaches: https://www.fieldfisher.com/en/insights/privacy-notices-post-whatsapp

More recently there has been a warning from Action Fraud about a takeover scam of Whatsapp accounts : https://www.actionfraud.police.uk/alert/warning-issued-to-whatsapp-users-over-account-takeover-scam

Our advice would be to always try to minimise any risk, so consider the following:

  • Systems owned by an organisation would have the relevant security measures in place to protect against hackers and cyber attacks. See our best practice area: Information & Cyber Security.
  • An organisation would have the appropriate user controls measures in place for accessing the data appropriate to a person's role in the organisation. See our Info/Cyber Security Checklist.
  • An organisation would have a backup of any data.
  • An organisation is required to have access to all data in the event of a Subject Access Request. This is much simpler when all business communication is either in the organisation's cloud or devices.  See our best practice area: Subject Access Requests.
  • Organisational systems are monitored and so any inappropriate use can be checked and controlled.
  • WhatsApp may not be the best tool for more formal communication of for conveying official school policies or announcements and could lead to confusion or miscommunication.
  • There is a risk of an individual's private information or confidential data being on everyone's personal device that are in the group - an organisation has control over it's own devices.

Internet Matters offers a WhatsApp social media guide.

Information about whether WhatsApp is safe for children is covered by the NSPCC: Is WhatsApp safe for my child?

If you have been a victim of fraud or cyber crime, report it to Action Fraud or 0300 123 2040, and possibly your DPO, depending on the cyber crime.

 

 

union jack flag next to big ben with the data protection logo as a watermark

On July 18, 2022, the U.K. government introduced the Data Protection and Digital Information Bill to Parliament. Previously known as the Data Reform Bill, it is the result of a consultation from 2021 and its aim is to update and simplify the U.K.’s data protection framework. According to the U.K. government, the new legal framework created by the DPDI Bill will reduce burdens on organizations while maintaining high data protection standards.

  1. Knowledge Bank Updates
  2. Types of malware and how they are linked to data protection
  3. Striking Data Breach
  4. IPR Protection Email Scam
  5. Windows Server 2012 & 2012 R2 Retirement
  6. How to contact us for support, subject access requests, data breaches and FOI's
  7. YouTube breached child protection laws
  8. How a school fought back after a cyberattack
  9. Types of Cyber Attacks - Credential Stuffing
  10. January Cyber update - How Can Schools Help Prevent Cyber Attacks?
  11. Assigning courses to staff using to-dos
  12. How the Record of Processing Can Help You
  13. Information Security Basics: What are VPN's?
  14. What does a Data Protection Officer Do?
  15. Are you ready for a Data Breach?
  16. Carrying out Supplier Due Diligence
  17. How Long Should You Keep Personal Data For?
  18. The Education sector now at highest risk of cyber attacks
  19. How to Assess your Data Security
  20. Schools Blocked from Using Facial Recognition Systems
  21. The Children's Code
  22. B&H FoI: Racist/religious incidents/bullying
  23. Cyber Attacks
  24. Protocol for Setting Up and Delivery of Online Teaching and Learning
  25. Class Dojo International Data Sharing
  26. Model Publication Scheme: Amendments, Improvements and Updates
  27. Child friendly privacy notices
  28. Transparency
  29. Secure file transfer of files using Royal Mail
  30. Emergency contacts and consent
  31. Key elements of a successful DPIA
  32. FOI Publication Schemes
  33. SHARE: Avoid disinformation online
  34. Best Practice for Managing Photos and Video
  35. New Drip Feeds: Recognise and Respond to Subject Access Request
  36. When to contact the Data Protection Officer?
  37. National child measurement programme
  38. Compliance Manager released
  39. Headteacher fined for breach of data protection legislation
  40. Emails – good practice and minimising the risk of a data breach

Search

Keep in the Know!

Get our latest news directly to your inbox

Privacy notice