InfoSec / Cyber

Keeping your IT systems safe and secure

Keeping your IT systems safe and secure

The ICO recently published an updated article aimed at small business with tips for IT security - this advice would also be applicable for schools and colleges.  

This table shows the advice from the ICO and how areas of the Data Protection Education Knowledge Bank can help and guide you in those areas. 

ICO Recommendation DPE Knowledge Bank Links
 Back up your data
 

 How secure is your server?

 Use strong passwords and multi-factor authentication

 Password Best Practice Library

 A Guide to Multi Factor Authentication

 Password Security Learning Nugget

  Be aware of your surroundings

 Information & Cyber Security Best Practice Library

 How to avoid a data breach: Information and Cyber Security Training Course

 Be way of suspicious emails

 Phishing Simulation

 Types of Phishing News Articles

 NCSC Cyber Security Training for School Staff

 Install anti-virus and malware protection

 Information & Cyber Security Best Practice Library

 Protect your device when it's unattended

 Information & Cyber Security Best Practice Library

 Physical Security

 Physical Security Learning Nugget

 Make sure your Wi-Fi connection is secure  Info/Cyber Security Checklist
 Limit access to those who need it

 Info/Cyber Security Checklist

Acceptable Use

 Take care when sharing your screen

 Working At Home Learning Nugget

 Working Out of School Best Practice Library

 Don't keep data for longer than you need it

 Records Management Best Practice Library

 Dispose of old IT equipment and records securely

 Info/Cyber Security Checklist

The full ICO article is here:  11 Practical Ways to Keep Your Systems Safe And Secure

Further ICO Password guidance: Passwords in online services

What to do in the event of a Cyber Attack 

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body. 

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to: 

  • Action Fraud on 0300 123 2040, or the Action Fraud website 
  • the DfE sector cyber team at This email address is being protected from spambots. You need JavaScript enabled to view it. 

You may also need to report to: 

You must act in accordance with: 

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator. 

Preserving evidence is as important as recovering from the crime.

Forward suspicious emails to This email address is being protected from spambots. You need JavaScript enabled to view it.. Report SMS scams by forwarding the original message to 7726 (spells SPAM on the keypad).

Little Guide to ACTION FRAUD

 

 

Search