- Tammy Buchanan
Knowledge Bank Updates
This articles lists the latest updates and new documents to the Knowledge Bank.
This articles lists the latest updates and new documents to the Knowledge Bank.
Malware is malicious software designed to harm computer systems and is linked to data protection in several ways.
|
Malware can be used to steal or compromise sensitive data stored on a computer system or network. This data could include personal information, financial data, or confidential business information. In this sense, malware poses a significant threat to data protection, as it can lead to data breaches and other security incidents. |
|
|
Malware can be used to destroy or corrupt data, making it inaccessible or unusable. This can be particularly damaging if the data is important or essential for business operations, and can result in financial losses, reputational damage, and legal liabilities. |
|
|
Malware can be used to exploit vulnerabilities in computer systems or networks, potentially enabling attackers to gain unauthorized access to data or systems. This can result in data theft or other malicious activities, and can also compromise the security and privacy of individuals or organizations. |
| Name | What it is | What it Does & How it infects | Examples |
![]() |
A type of malicious software that rapidly replicates and spreads to any device on a network. Worms do not need a host program to spread. | A worm infects a device through a downloaded file or a network connection before it multiplies and spreads at an exponential rate. |
Famous worms: Conficker, CodeRed, Morris Worm, Stuxnet |
![]() |
A trojan virus is disguised as a helpful software program. | The user downloads it, then the Trojan can gain access to sensitive data and then modify, block or delete data. It can be extremely harmful to the performance of the device. They are not designed to self-replicate, | Zeus Gameover mostly used for stealing victim's bank information. |
![]() |
Spyware is malicious software that runs secretly on a computer in the background and reports back to a remote user. | It targets sensitive information and can grant remote access to predators. It is often used to steal financial or personal information | Keylogger - records your keystrokes to reveal passwords and personal information. |
![]() |
Adware is malicious software used to collect data on your computer usage and provide appropriate adverts to you. Adware is not always dangerous but can cause issues for your system. | Adware can redirect your browser to unsafe sites and it can even contain Trojan horses and spyware. Significant levels of adware can slow down your system noticeably. |
Appearch is a common adware program that acts as a browser hijacker. It is usually bundled with free software and inserts so many ads into the browser that it makes surfing almost impossible. |
![]() |
Ransomware is malicious software that gains access to sensitive information within a system, encrypts that information so that the user cannot access it, and then demands a financial pay-out for the data to be released. | Ransomware is usually part of a phishing scam. By clicking a link the user downloads the ransomware. The attacker then proceeds to encrypt specific information that can only be unlocked with a special code. | Cryptolocker was one of the first examples. Fake Windows Updates. The VICE Society attacks schools. |
Malware is closely linked to data protection, as it poses a significant threat to the confidentiality, integrity, and availability of sensitive data. Effective measures to prevent, detect, and respond to malware attacks are essential for ensuring data protection and maintaining the security of computer systems and networks.
Check your cyber resilience using our Information and Cyber Security Checklists
Visit our Information and Cyber Security Best Practice Area for support and guidance.
Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: You may also need to report to: You must act in accordance with: Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. Preserving evidence is as important as recovering from the crime.What to do in the event of a Cyber Attack
Forward suspicious emails to
The headteacher of a grammar school has left her role after sending parents a list of the teachers going on strike.
The Headteacher at King Edward VI Five Ways Grammar school in Birmingham had been headmistress for just 18 months when an email she sent to parents is alleged to have named some teachers who would be striking during the planned walkouts last month.
A number of schools have received the below email from a company called IPR Protection. It is a scam and should be ignored.
Further information can be found here: https://www.aptma.ie/news-and-events/beware-of-scam-emails
It may be advisable to ask your IT department to block any emails from
This article is a reminder that Microsoft will stop support for both Windows Server 2012 and Windows Server 2012 R2 after October 10th 2023. Keeping software up to date on devices is best practice to help prevent cyber attacks and data breaches.
This article lists the ways that Data Protection Education can be contacted for general data protection queries, data breaches, subject access requests and freedom of information requests.
While all our customers have a dedicated consultant who can be contact directly, if there is an urgent issue we would always advise emailing
When you email
If you email a reply to the original email notification or any updates you received, then the ticket will be automatically be updated and is something we would recommend. If you send a new email to
You could also login to the Knowledge Bank:
https://dataprotection.education/
and update your ticket directly with the information.
How to add a Subject Access Request:
By logging a subject access request on the Knowledge Bank as soon as you receive it, we can guide you through the process and give any additional support and advice.
Login to the Knowledge Bank and go to 'Data Rights Log', select the white text in the title bar. Choose on the next screen to add a new data breach log. Then complete as much detail as you can in the data breach form.
You can also report a subject access request by emailing
The ICO says you must keep a record of any personal data breaches, regardless of whether you are required to notify them. Logging those breaches in the DPE Knowledge Bank is a good way of keeping a record that your DPO can access and advise on.
Login to the Knowledge Bank and go to 'Breach Log', select the white text in the title bar. Choose on the next screen to add a new data breach log. Then complete the form with as much detail as you can.
You can can also report a data breach by emailing
By logging a freedom of information request on the Knowledge Bank as soon as you receive it, we can guide you through the process and give any additional support and advice.
Login to the Knowledge Bank and go to 'FOI Log', select the white text in the title bar. Choose on the next screen to add a FOI. Complete as much detail as you can in the form.
You can also raise a ticket to ask for advice about an FOI by emailing
https://dataprotection.education/news-top/news
It is also possible to contact us on: 0800 0862018
The first child protection complain ever made against Big Tech under UK Law.
The following article talks about how a school thwarted a cyber attack, more through luck than judgement. Our advice is for the whole organisation to be cyber aware and review how your organisation might respond when attacked. The article gives ideas on how to begin making a cyber ready plan.
In October 2020 Kellett School was subject to a ransomware denial-of-service (DoS) attack orchestrated by a Russian criminal hacker group. After the attack, a post mortem diagnostic showed that they had most likely got into the school's system through a member of staff clicking on a link in a phishing email, which, because staff had admin rights to their school devices, installed malware on the school system. The full article can be read here:
Things to note from this attack:
Recommendations:
Further resources can be found in our Information Security best practice area:
https://dataprotection.education/index.php/best-practice-library/best-practice/information-security
and our Cyber Security checklist:
https://dataprotection.education/component/tjucm/itemform/cyber-security?id=90881&cluster_id=114
Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body.
The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to:
You may also need to report to:
You must act in accordance with:
Police investigations may find out if any compromised data has been published or sold and identify the perpetrator.
Preserving evidence is as important as recovering from the crime.
Forward suspicious emails to
This article is linked to a series of articles about different types of Cyber Attacks. They can be viewed in the Information/Cyber Security News section of the Data Protection Education website or as part of the Information & Cyber Security Best Practice Area. Each article discusses a different type of cyber attack, steps to try to minimise the risk and guidance
With the increase in Cyber crime against schools in the UK we are focusing in on what can be done to help prevent cyber crime in a way mangeable for school budgets.
To assign courses to your staff, we should use the to-do functionality via the Course Assignment and Progress Report.
When we assign a to-do via this report, and the user completes the course, the to-do will be automatically marked as complete in the to-do list.
The Record of Processing can often seem like a daunting process to undertake- but it’s important to view it as exactly that- a process. Documenting the processes your organisation carries out is an ongoing project that you continue to evolve and develop as those processes change. The value you can get out of spending some time and care by completing various ones shouldn’t be underestimated. We’ve spoken to some of the people who have used the RoP tool on the Knowledge Bank, and asked them what they found challenging, and what they found the most useful parts of the tool, in the hope that it will help some of you who may feel that carrying out the Record of Processing is a daunting task.
VPN’s have become commonplace over the past couple of years, with every content creator out there having at some point been sponsored by Nord VPN (other VPN providers are available). VPN's are mostly used so that we can watch content on streaming platforms that would otherwise be blocked in the UK. However, as well as allowing you to watch Pulp Fiction on Canadian Netflix, VPN’s have excellent security benefits that can help prevent data breaches and cyber attacks.
Under UK GDPR, Public Authorities or Bodies, as well as businesses carrying out certain processes are required to appoint a Data Protection Officer (DPO). This article will explain why you need a DPO and what a DPO does for your organisation.
Recently there has been an annual study published by Ponemon Institute (sponsored by Experian) entitled “Is Your Company Ready for a Big Data Breach?”. The study looks at the state of breach preparedness across organisations over a period of a year,
At Data Protection Education, we have an ongoing project to assess potential organisations that our schools are either currently contracted with to supply a product or service, or may in the future be in contract with.
For most organisations, a lot of thought and care goes into ensuring that when you’re collecting data, you are complying with the relevant data protection legislation- that it’s being collected with consent where required, that you have a lawful basis etc. However,
A recent study conducted by Check Point Research which can be found at the bottom of this article has found that there has been a 29% increase in cyberattacks on organisations in the education sector since 2020, the highest increase of any sector.
Cyber attacks are on the up, and with the education sector seeing the highest number of cyber attacks of any sector since the start of the pandemic, as well as the highest increase in attacks in that same period
With biometric technology becoming more and more prevalent in society, the governance of the personal data that organisations collect from using this technology has recently been a topic of discussion.
The Children’s Code
The first update from the ICO is that the transition year for the introduction of The Children’s Code (also known as The Age Appropriate Design Code) has passed, with the code having come into effect on September 2nd.
Schools in Brighton and Hove have received the following Freedom of Information request:
1. Please send me copies/scans/digital files that record individual racist/religious incidents/bullying incidents in terms of numbers of incidents and their
The National Cyber Security Centre has today upgraded it's advice to schools relating to the prevalence of cybers attacks in the sector:
These protocols aim to ensure that online lessons with pupils when working from home, are safe, secure and continue to provide high-quality education using a virtual platform.
This is guidance for setting up and managing online lessons using the school’s chosen platform ie Zoom; Google or Microsoft teams.
Users of Class Dojo will recently have noticed that a requirement to provide consent for international data transfers was included to the login screen.
It is a requirement under the Freedom of Information Act and ICO to set out your commitment to making certain classes of information routinely available, such as policies and procedures, minutes of meetings, annual reports and financial information.
Updated 22 March 2021
The ICO gives the following advice when communicating privacy matters to children:
What information should we give to children?
Transparency is about being clear, open and honest with your users about what they can expect from you.
We've recently had more than one breach reported where physical files have got lost in the post.
In such cases, the sender remains the data controller and is responsible for ensuring that the optimum data security measures are in place during transfer. Where possible, consider whether a physical drop-off (and get a receipt) is a more secure option.
Do I need consent for emergency contacts?
Actually no, and here's why.
We know that we must have a lawful basis for processing any data, and consent is one of the six lawful bases that can be used.
©2026 Data Protection Education Ltd.