Schools & MATs

Cyber attack written in computer text on a computer in red

This article is about a recent cyber attack on Leytonstone School.  The school in Waltham Forest has been closed since half term after it was targeted and a significant amount of personal data was accessed.

The school is still closed to all pupils other than those taking their GCSEs because the school currently does not have a single central record (SCR), sometimes referred to as a single central register.  An SCR is a statutory requirement for all schools and academies in England and Wales to keep and maintain one single record of pre-appointment vetting checks, regulated activity and recording information of all staff. The record is normally kept up to date by a member of the admin staff, but overall responsibility lies with governors (or equivalent) and delegated to headteachers.  It is an essential safeguarding document and must be maintained, reviewed and audited on a regular basis.  It will probably be one of the first documents that Ofsted will ask to see.  Any guidance relating to the SCR should also be read in conjunction with the current version of the Keeping Children Safe in Education (KCSIE) document.

There is no defined format for the SCR and most schools hold it electronically as a password protected Excel document.  As well as employees, it should also include:

  • any volunteer who is in regulated activity
  • people brought into the school to provide regular additional teaching or instruction but who are employed by another organisation such as peripatetic music teachers, sports coaches etc.
  • supply teachers
  • contract staff such as cleaners or caterers
  • Governors
  • Members of the proprietor body (trustees or directors) in independent schools including academies

As a result of the cyber attack at Leytonstone School there is also no WiFi and phone system, but it is the missing SCR that prevents the school from opening.  Our advice would be to always ensure there are secure offsite (cloud) backups of essential files, in addition to local backups.  The security of the SCR should be part of the school's business plan which should be discussed regularly at governing body meetings.  Review:  alongside Governors and Data Best Practice Area to understand how governor responsibilities relate to business continuity and cyber strategy.

View our Information & Cyber Security Best Practice Library for cyber help and guidance.

Download our Business Continuity Template.

We would also recommend viewing the National Cyber Security's pages that provide cyber security advice for schools, which includes free training: NCSC Cyber Security training for schools.
We provide additional Cyber Security Training: How to avoid a data breach: Information and Cyber security.

Further details about what has happened at the school can be viewed in this article by the Evening Standard: Leytonstone School forced to close after IT system hacked.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Blue data breach text on blue cyber background,  and orange reprimand stamp

A reprimand has been issued by the ICO to Parkside Community Primary School in relation to the infringements of Article 5 (1)(f), Article 24 (1) and Article 32 of the UK GDPR. This article discusses the reprimand and looks and what schools can do to avoid this type of breach.

Some of the information in the reprimand document is redacted, but the main details are:

  • A safeguarding email was shared in the classroom via the electronic whiteboard.
  • The ICO has found that the school disclosed personal data inappropriately, including special category data, in a classroom environment.

The breach is in relation to the UK GDPRs security principle, meaning that the school failed to prevent unlawful disclosure of personal data.
The school also failed to implement appropriate technical and organisational measures to ensure personal data is kept secure under Article 32 of the UK GDPR.

The findings were that the school did not have:

  • Detail in the data protection policy of when it was appropriate to open emails containing personal data.
  • Policies relating to the use of the school's electronic safeguarding system.
  • Written guidance for staff on the classification of emails, i.e. there was no labelling or system to indication that an email contained sensitive information.
  • Procedures or guidance relating to when it is appropriate in the school day to open emails generated by the electronic safeguarding system.
  • Procedures or guidance in relation to the safe operating of electronic whiteboards,  especially when screen sharing.

There were several steps taken and further action recommended which all schools should take into consideration when using these kinds of systems and when handling special category data in a busy school environment:

  • The governor responsible for the strategic management of data protection reviewed current practices and made recommendations. Many schools we speak to do not have this type of governor in place.  Consider reviewing our Governance Best Practice Library.  This article discusses the governor responsibilities in more detail: Cyber responsibilities for Governors/Trustees in schools
  • Formal guidance was given to staff about how data breaches should be reported. This is something usually discussed with our customers during our consultations.  All staff should know how to recognise a data breach and the procedures for reporting one.  Consider reviewing our full How to avoid a data breach training course, or invite staff to view our 5-10 minute Data Breach Learning Nugget.
  • Staff have been instructed that all alerts sent by the electronic safeguarding system should be read at specific times of the day and never when children are present or in the vicinity of the classroom. 
  • All staff have been instructed to use data classification such as SENSITIVE/HIGHLY SENSITIVE in the subject line of an email. Such emails should only be read before and after the school day. Review our Information Classification Best Practice Library in line with your email policy.
  • Governors are to be alerted to an incident as soon as it is reported to the Head.  Our Knowledge Bank allows schools to add governors and trustees as users, so they can get an overview of data breaches: 
  • Cases of a complex and sensitive nature on the electronic safeguarding system can only be accessed by the Headteacher, Deputy Headteacher and Parental and Pastoral Officer and shared with relevant members of staff on a need-to-know basis at scheduled meetings. Consider access control procedures, review our Information and Cyber Security Best Practice Library.
  • All staff and governors are to receive data protection refresher training.  We provide a 20-minute GDPR Refresh Course which can be assigned to both staff and governors by an administrator: 
  • All staff are to be issued with the school's data protection policy and to be familiar with its content.
  • The data protection policy has been reviewed.  The updated policy instructs staff how to report a breach, what constitutes a breach, and who to report it to and what happens once this has been done. Review our template policies:  document Model Data Protection Policy(208 KB)  and  document Data Breach Procedure(5.18 MB) .
  • All staff to sign an electronic document to confirm they have read and understood the data protection policy.  The DPE Knowledge Bank has a Compliance Manager tool that allows documents to be uploaded and assigned to staff to be read and signed within a set time period: 


The further actions recommended were:

  • Refresher training on the operation of electronic whiteboards for relevant employees with the emphasis on security and the relevant steps for employees to take to avoid a personal data breach when operating an electronic whiteboard.  Often the reseller or the manufacturer will offer free training or training videos about how to operating the equipment.
  • Ensure there is sufficient written guidance on the use of the electronic safeguarding system.
  • Consideration of refresher data protection training for all members of staff.  Both members of staff had failed to report the breach. Staff should understand the consequences of failing to report a breach, as mitigating action can lessen the effects of a personal data breach. Review our Data Breach Learning Nugget and Recognise a personal data breach drip feed poster.
  • Adequate technical and organisational measures should be in place to ensure the security and confidentiality of emails sent internally which include personal data, particularly when these contain sensitive and special category. Review Information and Cyber Security Best Practice Library.
  • The policies and procedures should have prominent, sufficient and adequate practical guidance for employees, including regular reviews and work to increase staff awareness.
  • All new processes should be tested.


The key points to take from the recommendations are that you should always be aware of where you are and who might see what you're working on.  Data classification and access controls are vital.  Special category requires extra security.

Consider all the advice above with what other safeguarding and special category data that you may have displayed around your school?  Consider using our Making the Rounds tool to do your own data walk or get in touch with your Data Protection Education School Consultant to do the walk with your or have a follow-up feedback meeting.

Use our  pdf DPE Quick Reference Guide(1.64 MB)  for practical advice on what can be displayed around schools.

The full reprimand can be read here: https://ico.org.uk/action-weve-taken/enforcement/parkside-community-primary-school/


coloured computer textm spelling Cyber Attack

A Dorchester school has recently suffered a cyber attack in the form of a Ransomware attack.
Following the attack the school has been left unable to use email or accept payments.
The school is working with the National Cyber Security Centre and the police to resolve the issue. The full article can be read here: https://www.bbc.co.uk/news/uk-england-dorset-65685607
T
he school remains open, with teaching adapted as needed and exams continuing as planned.

Comment from the headteacher:

A message from the headteacher, Nick Rutherford, to parents said:

“We are in liaison with our school Data Protection Officer and this data breach has been reported to the Information Commissioners Office (ICO) in line with requirements of the Data Protection Act 2018/GDPR. Every action has been taken to minimise disruption and data loss.

“The school will be working with Wessex Multi-Academy Trust, IT team and other relevant third parties (Department for Education, National Cyber Security Centre and police) to restore functionality and normal working as soon as possible.

“I appreciate that this will cause some problems for parents/carers with regards to school communications and apologise for any inconvenience. Please use the telephone absence line to report student absence, as staff cannot currently receive emails. Please also telephone the school should you wish to report any concerns or speak to a member of staff."
Quote source: https://planetradio.co.uk/greatest-hits/dorset/news/dorchester-school-cyber-attack/

Prof Alan Woodward, from the University of Surrey, has previously said schools are a "soft target". 

"IT is not their core business, they don't have big IT teams, and if they're all using standard software and a vulnerability is found in it, then the criminals will quite quickly realise that.

"The advice is never to pay. It sounds like a quick way out, but the prices are extortionate, and you're painting a big target on your back.

"Hackers sell what they call 'suckers lists' on the dark web, where they say 'these people will pay up', and often it can lead to further attacks," he added.

Data Protection Education are working with schools and trusts to build cyber resilience with data protection in mind:

View our Information & Cyber Security Best Practice Library for cyber help and guidance.

Download our Business Continuity Template.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

Cyber Attack: Wiltshire School

A Wiltshire secondary school has been severely affected by a targeted attack by hackers who demanded a ransom to restore access to its IT network.  The attack affected the school's local server, its website, internet access, Wi-Fi, printers and internal phone systems.

A full report can be read here: https://www.gazetteandherald.co.uk/news/23476464.hacker-demands-ransom-taking-control-wiltshire-schools/

The school's website was still down several days later.  An update a few days later was published here: https://www.gazetteandherald.co.uk/news/23484633.hardenhuish-school-cyber-attack-update-hackers-demand-ransom/

In the BBC report cyber expert, Prof Alan Woodward, from the University of Surrey, said schools are a "soft target". 

"IT is not their core business, they don't have big IT teams, and if they're all using standard software and a vulnerability is found in it, then the criminals will quite quickly realise that.

"The advice is never to pay. It sounds like a quick way out, but the prices are extortionate, and you're painting a big target on your back.

"Hackers sell what they call 'suckers lists' on the dark web, where they say 'these people will pay up', and often it can lead to further attacks," he added.

The full BBC Report can be found here: https://www.bbc.co.uk/news/uk-england-wiltshire-65411450

View our Information & Cyber Security Best Practice Library for cyber help and guidance.

Download our Business Continuity Template.

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Report Fraud on 0300 123 2040, or the Report Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

 

Types of Cyber Attacks: The Insider Threat

This article is linked to a series of articles about different types of Cyber Attacks. They can be viewed in the Information/Cyber Security News section of the Data Protection Education website or as part of the Information & Cyber Security Best Practice Area. Each article discusses a different type of cyber attack, steps to try to minimise the risk and guidance.

The Cybersecurity and Infrastructure Security Agency (CISA) defines insider threat as the threat that an insider will use their authorised access, intentionally or unintentionally to do harm to the organisation's mission, resources, personnel, information, equipment, networks or systems.  This can include theft or unauthorised access to sensitive data, installing malware or other malicious software, or disrupting normal operations.

They are people who have authorised and legitimate access to a company's assets and abuse it either deliberately or accidentally.

There are three insider threat sources:

  1. Negligent or inadvertent users
  2. Criminal or malicious insiders
  3. Attackers that stole user credentials

How might an insider threat attack happen?

  • People rushing to finish a task or project who have access to sensitive data or admin rights can cut corners.
  • Remote working opens the organisation to personal devices being used and data intervertently being downloaded.
  • People losing devices or having devices stolen.
  • Clicking on a phishing email.
  • Not installing regular updates.
  • Installing non-organisation approved software which has malware.
  • Leaving devices open to physical attacks such as a server not in a locked cupboard or room, is open to accidental spillages, USB devices being plugged in, turning off of all the organisation's systems by pressing the power button.
  • Lack of IT expertise in the organisation could mean that someone unwittingly does not have all the appropriate systems controls in place.
  • Deliberate sabotage.

How can you reduce the risk of a cyber attack?

Remember: insiders don't act maliciously most of the time - a cyber attack is sometimes caused by a disgruntled employee but it's mostly by accident or negligence.

The role of cyber negligence in insider threats

 What to do in the event of a cyber attack?

Tell someone!  Report to IT. Report to SLT. 

Unplug the computer from the internet by removing the ethernet cable or turning the Wi-Fi off.

If you are a victim of a ransomware attack we would recommend reporting this to Action Fraud: https://www.actionfraud.police.uk/ as well as your data protection officer so they can advise about the data loss.  Most cyber crimes like these will also need to be reported to the ICO by your data protection officer.

Isolate the infected device and pass to IT 

Always ensure there are backups you can restore from.

Little Guide to ACTION FRAUD

Why your data is profitable to cyber criminals

This article covers ways in which cyber criminals profit from their cyber crimes.  Often we might think our data, if it is not financial, is not interesting or profitable to hackers, so this article discusses the different types of data that are stolen and why.

Financial data is the main data type that we all think of when considering why a hacker might steal information.  Financial data can be sold to various individuals for different purposes. It is not uncommon for thousands of records to be sold within 24 hours, making this a lucrative endeavour for the attacker and market owner.  More about this can be read in this blog by a reformed black hat hacker: Cybercriminals, Debit Cards, Credit Cards, and Underground Markets

Personal data is relatively easy to steal and will be information such as names, addresses, phone numbers, email addresses and national insurance numbers.  They can use this information to create fake identities or commit identity theft, which can then allow them to access bank accounts, credit cards and other financial resources.  This is why hackers find school MIS data attractive. WH Smith Recent Cyber Attack is a recent personal data attack.  The NCSC have written a paper about the cyber threat to Universities: https://www.ncsc.gov.uk/report/the-cyber-threat-to-universities

Intellectual property is when hackers steal such things as patents, trademarks, copyrights and trade secrets.  They can sell this information to competitors or use it to create their products.  This often happens between governments.  MI5 report a new body has been created to help the UK combat national security threats. - See more at: https://www.mi5.gov.uk/news/new-body-will-help-the-uk-combat-national-security-threats#sthash.hgLZxMI8.dpuf

Ransomware is when hackers encrypt data on a victim's computer and demand payment in exchange for the decryption key. This can be especially lucrative for hackers who target businesses or organisations that rely on their data to operate, such as schools.  See our previous article about schools that have been targeted in this way recently: VICE SOCIETY -  Ransomware attacks on schools.

Health data is stolen such as medical records or insurance information.  This information is used to commit identity theft or insurance fraud.  NHS Ransomware Attack.

Hackers profit from the data they steal in various ways, including:

  1. Selling the data on the dark web: The data can be sold to other cybercriminals who can use it for their nefarious purposes.

  2. Using the data themselves: Hackers can use the data to access accounts, commit identity theft, or create fake identities to commit further fraud.

  3. Ransomware payments: If the hacker uses ransomware, they can demand a ransom payment in exchange for the decryption key.

  4. Blackmail or extortion: In some cases, hackers may threaten to release sensitive information unless the victim pays a ransom or takes some other action.

In conclusion, hackers steal a variety of data from their victims, and they profit from this data in different ways, depending on the type of information stolen and the hacker's goals. To protect against these threats, it is essential to take cybersecurity seriously and implement appropriate security measures.

Visit our Info/Cyber Security Best Practice Area for help, guidance and support for cyber cyber security and data protection.

This website lists all the cyber crime statistics for the UK: https://proprivacy.com/blog/latest-uk-cybersecurity-cybercrime-statistics-2020-2022

What to do in an attack:

Tell someone!  Report to IT. Report to SLT. 

Unplug the computer from the internet by removing the ethernet cable or turning the Wi-Fi off.

If you are a victim of a ransomware attack we would recommend reporting this to Action Fraud: https://www.actionfraud.police.uk/ as well as your data protection officer so they can advise about the data loss.  Most cyber crimes like these will also need to be reported to the ICO by your data protection officer.

Isolate the infected device and pass to IT 

Always ensure there are backups you can restore from.

Remember – ‘Hackers don’t break in they login’!

Striking Data Breach

The headteacher of a grammar school has left her role after sending parents a list of the teachers going on strike.

The Headteacher at King Edward VI Five Ways Grammar school in Birmingham  had been headmistress for just 18 months when an email she sent to parents is alleged to have named some teachers who would be striking during the planned walkouts last month.

FOI: Vaccination Justifications

You may have received an email or letter requesting information on the research and justification of the administration of vaccines, such as:

Dear Sir/Madam,
RE: SCHOOL VACCINE POLICY.


In relation to UK Government COVID-19 'Vaccine' Policy and Childhood Immunization ‘Vaccine’ Policy which includes INFLUENZA, HPV, MEASLES AND POLIO, under the protection of the People's Union of Britain, you are hereby served notice of conditional acceptance that you are lawfully entitled to 'vaccinate' children, whilst in the care of the headteacher at the school, whether on school premises or elsewhere, provided you deliver to me the following:

Search