📢 It's important to be prepared for when a cyber incident happens to you. Part of that preparation should include having a Cyber Incident Response Plan, and part of that plan should include how to communicate, who does the communication and what they should say.
We are sharing some of blog posts by school ICT technicians and ICT managers that are giving their advice about keeping your school cyber secure and resilient.
🛡️✅ Gone are the days when cyber security issues meant accidentally downloading a virus, it has grown to mean so much more, where data and identities are stolen, fraud is committed and businesses can be shut down from a cyber attack. With that in mind we have created a cyber security best practice area to help guide and support your data protection compliance.
The data protection officer is mentioned many times in the DfE Digital Standards for Schools and Colleges as someone that should either be informed or consulted with. As part of that consultation process, we would like to announce our new DfE Digital Standards for Schools and Colleges Tracker.
We are launching a new best practice area which has all the policies, documents and posters in one place. You can find this page in our main best practice area:
We've updated our 'Making the Rounds', data walk, to include some central processes that should be included in data protection and cyber security compliance:
The recent news has been full of the global IT outage that affected many systems over the weekend, including airlines and patient access. Although the incident was not caused by a cyber attack, it is important to note that it was a cyber incident which affects everyone.
A cyber incident is an event with threatens the confidentiality, integrity or availability of information systems, networks or the information they contain.
Cyber incidents can be intentional or accidental and can cause major disruptions. The recently reported CrowdStrike incident caused significant global disruption. While there are huge impacts to the affected systems, for which there are now fixes available, there will be an aftermath of 'unrest' where threat actors will use people's vulnerability and concern to send phishing emails.
The NCSC has already reported an increased in phishing activity as opportunistic and malicious actors seek to take advantage of the situation. The emails could be aimed at organisations or individuals.
Article images created using Microsoft Copilot AI. Micro Learning video created using Vyond AI.
What to do in the event of a Cyber Attack
Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body.
TheSLTdigital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to:
Police investigations may find out if any compromised data has been published or sold and identify the perpetrator.
Preserving evidence is as important as recovering from the crime.
Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).