Schools & MATs

AI Due Diligence: DfE Standard announced. Generative AI safety standards in education.

The DfE previously issued training and guidance about the use of AI in Education - this has now changed to standards.  Standards define minimum requirements that must be met, whereas a guideline offers recommended best practice or advice. The standards outline the safety standards that generative AI products and systems should meet to be used in educational settings.

Know your IT Support Provider graphic. IT Support Due Diligence Directory for schools and colleges.

Finding the right IT partner and support provider is a big decision.  Due diligence for IT Support isn't just about who can 'fix computers', it's about ensuring standards are followed and they work with you to meet your organisation's strategy. Data Protection Education has a DfE IT Support Tracker and Supplier Due Diligence Directory to provide support and guidance as well as tracking your progress.

The Government Cyber Action Plan 2026 document. UK public sector cyber security strategy.

The Government Cyber Action Plan, published in January 2026, sets out a radical shift in how the UK public sector manages cyber security and digital resilience. It moves away from fragmented, siloed defences toward a "Defend as One" model led by a new Government Cyber Unit within the Department for Science, Innovation and Technology (DSIT).

Higham Lane School cyber attack in Nuneaton keeps 1500 students home. School's digital systems are down.

NUNEATON, January 7, 2026 — Higham Lane School in Nuneaton has been forced to remain closed this week following a "significant" cyber attack that has crippled its entire digital infrastructure. The incident, which was discovered over the weekend just as students were set to return from the Christmas break, has left approximately 1,500 pupils unable to attend classes.

 A promotional image for new digital standards in education.  The top half shows four primary school-age children sitting at a desk, looking down and focusing on work. The child closest to the camera on the right is smiling.  The bottom half has an orange and blue graphic overlay that reads: "New standard announced! MEETING DIGITAL STANDARDS IN SCHOOLS AND COLLEGES." In the bottom left corner is a circle image showing students working on laptops. The text "IT Support" is written in a yellow box below the circle. In the bottom right corner is a logo for the "DATA PROTECTION EDUCATION" initiative.

The government has announced an additional Digital Standard to help with planning, commissioning and reviewing their IT support services.  The services can be internal, external or a hybrid.  Effective IT support is essential for maintaining technology, planning improvements and mitigating risks like outages and cyber incidents, and sits alongside the other 11 standards.

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

As Cyber Security Awareness Month draws to a close, it's important to recognise that cybersecurity isn't a destination; it's a continuous journey. For organisations, particularly those in the education sector, this journey often involves working towards recognised standards and certifications. In the UK, Cyber Essentials and Cyber Essentials Plus are government-backed schemes designed to help organisations protect themselves against common cyber threats. For schools, the Department for Education (DfE) Digital Standards provide additional, tailored guidance.  The Government has recently published their Cyber Assessment Framework for further best practice guidance.

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

Administrator accounts (often called "privileged accounts") are the most powerful and, so, the most sought-after targets for cybercriminals. These accounts hold the "keys to the kingdom," possessing extensive permissions to configure systems, access sensitive data, manage users, and make critical changes across an entire network or application. A single compromised admin account can lead to a catastrophic data breach, widespread system paralysis, or complete organisational takeover by attackers. Therefore, making these accounts cyber resilient through controls, processes, and procedures is crucial.

  1. October 28. Phishing: Don't Take the Bait!
  2. October 27. Passwords
  3. October 26. Physical Security of Digital Assets
  4. October 25. Server Security: Protecting Your Digital Core
  5. October 24. Backups: Your Recovery Safety Net
  6. October 23. Filtering and Monitoring
  7. October 22. Hardware: Printers
  8. October 21. Hardware: Asset Management
  9. October 20. Hardware: Safe disposal
  10. October 19. Anti-virus/anti-malware
  11. October 18. Regular Updates: Patching Against Threats
  12. October 17. Access Control: Managing User Privileges
  13. October 16. Access Control: Securing Your Digital Gateways (Wi-Fi & Networks)
  14. October 15. Access Control: Securing Your Home Office (Working From Home)
  15. October 14. Access Control : (Multi-factor authentication)
  16. We've teamed up on a podcast with the Small Business Cyber Security Guy
  17. October 13. Cyber Security Awareness
  18. October 12. Training: Empowering your human firewall
  19. October 11. Policies and Procedures: Cyber Blueprint
  20. October 10. Understanding Your Cyber Posture
  21. Time's Ticking: Windows 10 support ends in October 2025!
  22. October 9. A Guide for Education Providers
  23. October 8. How Can Your Organisation Prevent Ransomware Attacks?
  24. October 7: Under Attack: The Reality of Ransomware
  25. October 6: Cyber Action Plan and A Roadmap to Resilience
  26. October 5: Cyber Responsibilities - We're All in This Together
  27. October 4: When a Cyber Attack Hits
  28. October 3: Data Security, the Core of Protection
  29. October 2: Privacy Protection & Safeguarding Personal Data
  30. October 1: Welcome to Cyber Security Awareness Month!
  31. Nursery Cyber attack
  32. Fraud awareness from the DfE
  33. The Classroom's Dark Side: Cyber crime from the Classroom
  34. Data Breach: School sends out names and contact details in a spreadsheet.
  35. KCSIE 2025: Data Protection, AI, and Cyber Security
  36. The Online SCR Data Breach: What You Need to Know
  37. Back to School Basics for Data Protection and Cyber Security Compliance
  38. The Latest Cyber Threat: The "Murky Panda"
  39. Building a Secure School: Using the ICO Accountability Framework to Meet DfE Digital Standards
  40. Why Physical and Data Security Must Go Hand-In-Hand
  41. Digital Safeguarding: DfE announces statutory DfE Digital Standards
  42. The Data Protection Lead/Champion Role
  43. Changes to the Academy Trust Handbook 2025
  44. School closes for two days after cyber incident
  45. Social Media Day 2025
  46. How Ofsted looks at AI during inspection and regulation
  47. Data Breaches 2025 Report Highlights
  48. Not everyone needs access: The Key to Protecting Sensitive Data
  49. School cyber attack: Outwood Academy, Middlesbrough
  50. Alert: Schools receiving Microsoft File Sharing Phishing Emails
  51. School cyber attack: Framlingham College, Suffolk
  52. West Lothian Schools in Cyber Attack
  53. A Wake-Up Call for Cyber Vigilance - Danger in the Threat Landscape for Everyone
  54. New Governor Resources
  55. Are teachers using AI? 83% say its a time-saver
  56. DfE Digital Standards - narrowing the digital divide
  57. Arbor AI - On By Default
  58. DfE Guidance: Choosing a new MIS
  59. Short Guide to AI Video
  60. Safer Internet Day, Cyber Security & Data Protection
  61. The Cyber Resilience Championship
  62. The Multiple Dimensions of Supplier Due Diligence
  63. School shares sensitive pupil information as part of an FOI response
  64. Blacon High School Cyber Attack
  65. WhatsApp and FOI's: ICO Warnings
  66. New AI Guidance from the DfE
  67. What the proposed Government legislative proposal around cyber crime means
  68. DfE update to record keeping and management
  69. Update to data sharing for school immunisation programmes
  70. SLT Digital Lead Profile
  71. The role of governors in cyber security and data protection
  72. Navigating Privacy at the End of Term , Special Occasions and End of Year
  73. South East Technological University has experienced a cyber incident
  74. Safeguarding Identity in Microsoft 365: Protecting the UK Education Sector Against Cyber Threats
  75. Cyber Attack on a Special School
  76. Stealing children's data
  77. Ofqual highlights the value of cyber security training in schools
  78. Fylde Coast Academy Trust Cyber Attack This Week
  79. Calling all IT leads in schools and mult academy trusts!
  80. Ransomware cyber attack on a school in Bromley
  81. School hit by Cyber Attack
  82. DfE Digital Standards for Schools and Colleges Tracker
  83. Schools and Trusts Best Practice Area
  84. ESFA Cyber Essentials Requirement for Colleges from 2024/2025
  85. ICO Reprimands a School
  86. Out of date technology
  87. Data Retention and the Pupil File
  88. Have you assigned your SLT Digital Lead yet?
  89. What's a Cyber Incident and what should we do?
  90. Getting Started with AI (Artificial Intelligence)
  91. Cyber attack on a school during half term
  92. The rise of cyber attacks in schools are causing pupils to miss classes
  93. Cyber attack on a Trust; the aftermath
  94. School Focus: The Vale Federation | Aylesbury
  95. DfE Dealing with Subject Access Requests (SARs) Guidance
  96. Update to the Guidance on Information Sharing from the DfE
  97. Product Focus on Checklists : Initial Trust Plan
  98. Product Focus on Checklists : End of Term Checklist
  99. Product Focus on Checklists : Social Media
  100. Product Focus on Checklists : Lettings
  101. Milk Island: The secret location that allows children to view restricted content on Google Maps
  102. Free Cyber help, advice and training with the Cyber Resilience Centres
  103. The Perils of Paper: The Printing Vulnerability
  104. Product Focus on Checklists : Governors and Data
  105. Product Focus on Checklists : Site Moves
  106. Cyber attack on a University
  107. Product Focus on Checklists : Bring your own device
  108. Product Focus on Checklists : Working out of school/offsite
  109. Cyber Attack on a School
  110. Major cyber-criminal gang Lockbit brought down by UK Law Enforcement
  111. Product Focus on Checklists : Photos and video
  112. Safer Internet Day 2024
  113. Kent Councils Data Breach
  114. Free cyber training for staff
  115. DfE Digital Standards Update
  116. ClassCharts Possible Data Breach
  117. School Focus: St Bernadette's Catholic Primary School | Brighton
  118. Guardians of Privacy: 16. Social Media Checklist
  119. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  120. Guardians of Privacy: 14. Social Media and Cyber Bullying
  121. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  122. Guardians of Privacy: 12. Social Media and Going Viral
  123. Guardians of Privacy: 11. Staff Social Media Accounts
  124. Guardians of Privacy: 10. Social Media and Cookies
  125. Guardians of Privacy: 9. Social Media and Morality
  126. New Resources for Schools from the ICO
  127. Guardians of Privacy: 8. Social Media Policies
  128. Guardians of Privacy: 7. Social Media Data Retention
  129. Guardians of Privacy: 6. Posting Safely
  130. Guardians of Privacy: 5. Social Media and Consent
  131. Guardians of Privacy: 4. Social Media Access Control
  132. Guardians of Privacy: 3. Social Media Channels
  133. Guardians of Privacy: 2. Law and Regulations
  134. Phishing attacks targeting schools - alert from City of London Police
  135. The ICO reprimands a Multi Academy Trust
  136. Guidance for the use of school email and applying email retention in schools
  137. Data Protection Tips for Early Years Settings
  138. Trust Initial Plan Checklist Update
  139. Update on Advisory for Rhysida Ransomware
  140. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  141. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  142. Lettings Best Practice and Guidance
  143. The UK Online Safety Bill becomes an Act (Law)
  144. Considerations when migrating to a new MIS
  145. The importance of software updates (PaperCut vulnerability and Rhysida ransomware)
  146. Public bodies and sensitive data
  147. ICO: 10 Step guide to sharing information to safeguard children
  148. Email and Security: ICO recent guidance
  149. Social Media Policy
  150. Data Protection and Cyber Security (Inset Day) Training Ideas
  151. Changes to Microsoft Free Licensing for Schools
  152. What to do in the event of a Cyber Attack
  153. How KCSIE is linked to Cyber Strategy
  154. VICE SOCIETY - Ransomware attacks on schools
  155. Using Tags if you are a group of organisations in the DPE Knowledge Bank
  156. Cyber Insurance in the Public Sector
  157. Cyber Attack: Leytonstone School
  158. The ICO Reprimands a school
  159. Cyber Attack: Dorchester School
  160. Knowledge Bank Role Types: Admin, Staff and Trustee
  161. Cyber Attack: Wiltshire School
  162. Types of Cyber Attacks: The Insider Threat
  163. Why your data is profitable to cyber criminals
  164. Striking Data Breach
  165. January Cyber update - How Can Schools Help Prevent Cyber Attacks?
  166. FOI: Vaccination Justifications
  167. The Education sector now at highest risk of cyber attacks
  168. Schools Blocked from Using Facial Recognition Systems
  169. The Children's Code
  170. Cyber Attacks
  171. Protocol for Setting Up and Delivery of Online Teaching and Learning
  172. Class Dojo International Data Sharing
  173. Secure file transfer of files using Royal Mail
  174. Emergency contacts and consent
  175. Best Practice for Managing Photos and Video
  176. Headteacher fined for breach of data protection legislation

Search