Schools & MATs

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

In cybersecurity, access control for users is about ensuring that only authorised individuals can access specific systems, applications, and data, and only to the extent necessary for their role. This principle is often referred to as the "principle of least privilege"  – granting users the bare minimum permissions required to perform their job functions, and nothing more.

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

Your Wi-Fi network and broader internal networks are the digital gateways to all your connected devices, resources and data. Just as a physical building needs secure entrances, your networks require robust access controls to prevent unauthorised entry and protect everything within. Ignoring network security is like leaving your front door wide open.

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

The shift to remote work has transformed how we work, but also introduces new cyber security challenges, particarly around access control in a less structured environment, like a home office.  When working off site,  your personal network and devices become potential entry points into your organisation's systems, making robust access control crucial.

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

Multi factor authentication is considered the most impactful single step you can take to strengthen your access control to digital accounts, systems and data. While a strong password is your first line of defence, MFA adds a critical second (or more) layer of verification, making it much harder for cyber criminals to gain unauthorised entry, even if they've stolen your password.

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

Preventing ransomware attacks requires a multi-layered approach.  Regular backups are crucial - ensure they are isolated and tested. Employee training is paramount; staff must be able to recognise a phishing attempt.  All software and systems should be updated to patch vulnerabilities Strong access controls and MFA for all accounts will prevent up to 89% of data beaches.

  1. October 7: Under Attack: The Reality of Ransomware
  2. October 6: Cyber Action Plan and A Roadmap to Resilience
  3. October 5: Cyber Responsibilities - We're All in This Together
  4. October 4: When a Cyber Attack Hits
  5. October 3: Data Security, the Core of Protection
  6. October 2: Privacy Protection & Safeguarding Personal Data
  7. October 1: Welcome to Cyber Security Awareness Month!
  8. Nursery Cyber attack
  9. Fraud awareness from the DfE
  10. The Classroom's Dark Side: Cyber crime from the Classroom
  11. Data Breach: School sends out names and contact details in a spreadsheet.
  12. KCSIE 2025: Data Protection, AI, and Cyber Security
  13. The Online SCR Data Breach: What You Need to Know
  14. Back to School Basics for Data Protection and Cyber Security Compliance
  15. The Latest Cyber Threat: The "Murky Panda"
  16. Building a Secure School: Using the ICO Accountability Framework to Meet DfE Digital Standards
  17. Why Physical and Data Security Must Go Hand-In-Hand
  18. Digital Safeguarding: DfE announces statutory DfE Digital Standards
  19. The Data Protection Lead/Champion Role
  20. Changes to the Academy Trust Handbook 2025
  21. School closes for two days after cyber incident
  22. Social Media Day 2025
  23. How Ofsted looks at AI during inspection and regulation
  24. Data Breaches 2025 Report Highlights
  25. Not everyone needs access: The Key to Protecting Sensitive Data
  26. School cyber attack: Outwood Academy, Middlesbrough
  27. Alert: Schools receiving Microsoft File Sharing Phishing Emails
  28. School cyber attack: Framlingham College, Suffolk
  29. West Lothian Schools in Cyber Attack
  30. A Wake-Up Call for Cyber Vigilance - Danger in the Threat Landscape for Everyone
  31. New Governor Resources
  32. Are teachers using AI? 83% say its a time-saver
  33. DfE Digital Standards - narrowing the digital divide
  34. Arbor AI - On By Default
  35. DfE Guidance: Choosing a new MIS
  36. Short Guide to AI Video
  37. Safer Internet Day, Cyber Security & Data Protection
  38. The Cyber Resilience Championship
  39. The Multiple Dimensions of Supplier Due Diligence
  40. School shares sensitive pupil information as part of an FOI response
  41. Blacon High School Cyber Attack
  42. WhatsApp and FOI's: ICO Warnings
  43. New AI Guidance from the DfE
  44. What the proposed Government legislative proposal around cyber crime means
  45. DfE update to record keeping and management
  46. Update to data sharing for school immunisation programmes
  47. SLT Digital Lead Profile
  48. The role of governors in cyber security and data protection
  49. Navigating Privacy at the End of Term , Special Occasions and End of Year
  50. South East Technological University has experienced a cyber incident
  51. Safeguarding Identity in Microsoft 365: Protecting the UK Education Sector Against Cyber Threats
  52. Cyber Attack on a Special School
  53. Stealing children's data
  54. Ofqual highlights the value of cyber security training in schools
  55. Fylde Coast Academy Trust Cyber Attack This Week
  56. Calling all IT leads in schools and mult academy trusts!
  57. Ransomware cyber attack on a school in Bromley
  58. School hit by Cyber Attack
  59. DfE Digital Standards for Schools and Colleges Tracker
  60. Schools and Trusts Best Practice Area
  61. ESFA Cyber Essentials Requirement for Colleges from 2024/2025
  62. ICO Reprimands a School
  63. Out of date technology
  64. Data Retention and the Pupil File
  65. Have you assigned your SLT Digital Lead yet?
  66. What's a Cyber Incident and what should we do?
  67. Getting Started with AI (Artificial Intelligence)
  68. Cyber attack on a school during half term
  69. The rise of cyber attacks in schools are causing pupils to miss classes
  70. Cyber attack on a Trust; the aftermath
  71. School Focus: The Vale Federation | Aylesbury
  72. DfE Dealing with Subject Access Requests (SARs) Guidance
  73. Update to the Guidance on Information Sharing from the DfE
  74. Product Focus on Checklists : Initial Trust Plan
  75. Product Focus on Checklists : End of Term Checklist
  76. Product Focus on Checklists : Social Media
  77. Product Focus on Checklists : Lettings
  78. Milk Island: The secret location that allows children to view restricted content on Google Maps
  79. Free Cyber help, advice and training with the Cyber Resilience Centres
  80. The Perils of Paper: The Printing Vulnerability
  81. Product Focus on Checklists : Governors and Data
  82. Product Focus on Checklists : Site Moves
  83. Cyber attack on a University
  84. Product Focus on Checklists : Bring your own device
  85. Product Focus on Checklists : Working out of school/offsite
  86. Cyber Attack on a School
  87. Major cyber-criminal gang Lockbit brought down by UK Law Enforcement
  88. Product Focus on Checklists : Photos and video
  89. Safer Internet Day 2024
  90. Kent Councils Data Breach
  91. Free cyber training for staff
  92. DfE Digital Standards Update
  93. ClassCharts Possible Data Breach
  94. School Focus: St Bernadette's Catholic Primary School | Brighton
  95. Guardians of Privacy: 16. Social Media Checklist
  96. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  97. Guardians of Privacy: 14. Social Media and Cyber Bullying
  98. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  99. Guardians of Privacy: 12. Social Media and Going Viral
  100. Guardians of Privacy: 11. Staff Social Media Accounts
  101. Guardians of Privacy: 10. Social Media and Cookies
  102. Guardians of Privacy: 9. Social Media and Morality
  103. New Resources for Schools from the ICO
  104. Guardians of Privacy: 8. Social Media Policies
  105. Guardians of Privacy: 7. Social Media Data Retention
  106. Guardians of Privacy: 6. Posting Safely
  107. Guardians of Privacy: 5. Social Media and Consent
  108. Guardians of Privacy: 4. Social Media Access Control
  109. Guardians of Privacy: 3. Social Media Channels
  110. Guardians of Privacy: 2. Law and Regulations
  111. Phishing attacks targeting schools - alert from City of London Police
  112. The ICO reprimands a Multi Academy Trust
  113. Guidance for the use of school email and applying email retention in schools
  114. Data Protection Tips for Early Years Settings
  115. Trust Initial Plan Checklist Update
  116. Update on Advisory for Rhysida Ransomware
  117. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  118. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  119. Lettings Best Practice and Guidance
  120. The UK Online Safety Bill becomes an Act (Law)
  121. Considerations when migrating to a new MIS
  122. The importance of software updates (PaperCut vulnerability and Rhysida ransomware)
  123. Public bodies and sensitive data
  124. ICO: 10 Step guide to sharing information to safeguard children
  125. Email and Security: ICO recent guidance
  126. Social Media Policy
  127. Data Protection and Cyber Security (Inset Day) Training Ideas
  128. Changes to Microsoft Free Licensing for Schools
  129. What to do in the event of a Cyber Attack
  130. How KCSIE is linked to Cyber Strategy
  131. VICE SOCIETY - Ransomware attacks on schools
  132. Using Tags if you are a group of organisations in the DPE Knowledge Bank
  133. Cyber Insurance in the Public Sector
  134. Cyber Attack: Leytonstone School
  135. The ICO Reprimands a school
  136. Cyber Attack: Dorchester School
  137. Knowledge Bank Role Types: Admin, Staff and Trustee
  138. Cyber Attack: Wiltshire School
  139. Types of Cyber Attacks: The Insider Threat
  140. Why your data is profitable to cyber criminals
  141. Striking Data Breach
  142. January Cyber update - How Can Schools Help Prevent Cyber Attacks?
  143. FOI: Vaccination Justifications
  144. The Education sector now at highest risk of cyber attacks
  145. Schools Blocked from Using Facial Recognition Systems
  146. The Children's Code
  147. Cyber Attacks
  148. Protocol for Setting Up and Delivery of Online Teaching and Learning
  149. Class Dojo International Data Sharing
  150. Secure file transfer of files using Royal Mail
  151. Emergency contacts and consent
  152. Best Practice for Managing Photos and Video
  153. Headteacher fined for breach of data protection legislation

Search