Schools & MATs

AI Due Diligence: DfE Standard announced. Generative AI safety standards in education.

New DfE AI Standards

The DfE previously issued training and guidance about the use of AI in Education - this has now changed to standards.  Standards define minimum requirements that must be met, whereas a guideline offers recommended best practice or advice. The standards outline the safety standards that generative AI products and systems should meet to be used in educational settings.

Read more …

Know your IT Support Provider graphic. IT Support Due Diligence Directory for schools and colleges.

Is your IT Support Provider Compliant?

Finding the right IT partner and support provider is a big decision.  Due diligence for IT Support isn't just about who can 'fix computers', it's about ensuring standards are followed and they work with you to meet your organisation's strategy. Data Protection Education has a DfE IT Support Tracker and Supplier Due Diligence Directory to provide support and guidance as well as tracking your progress.

Read more …

The Government Cyber Action Plan 2026 document. UK public sector cyber security strategy.

The Government Cyber Action Plan

The Government Cyber Action Plan, published in January 2026, sets out a radical shift in how the UK public sector manages cyber security and digital resilience. It moves away from fragmented, siloed defences toward a "Defend as One" model led by a new Government Cyber Unit within the Department for Science, Innovation and Technology (DSIT).

Read more …

Higham Lane School cyber attack in Nuneaton keeps 1500 students home. School's digital systems are down.

School Cyber Attack: Higham Lane School Hit by Major Cyber Attack: Campus Remains Closed

NUNEATON, January 7, 2026 — Higham Lane School in Nuneaton has been forced to remain closed this week following a "significant" cyber attack that has crippled its entire digital infrastructure. The incident, which was discovered over the weekend just as students were set to return from the Christmas break, has left approximately 1,500 pupils unable to attend classes.

Read more …

 A promotional image for new digital standards in education.  The top half shows four primary school-age children sitting at a desk, looking down and focusing on work. The child closest to the camera on the right is smiling.  The bottom half has an orange and blue graphic overlay that reads: "New standard announced! MEETING DIGITAL STANDARDS IN SCHOOLS AND COLLEGES." In the bottom left corner is a circle image showing students working on laptops. The text "IT Support" is written in a yellow box below the circle. In the bottom right corner is a logo for the "DATA PROTECTION EDUCATION" initiative.

IT Support Standards for Schools and Colleges Guidance (DfE Digital Standards)

The government has announced an additional Digital Standard to help with planning, commissioning and reviewing their IT support services.  The services can be internal, external or a hybrid.  Effective IT support is essential for maintaining technology, planning improvements and mitigating risks like outages and cyber incidents, and sits alongside the other 11 standards.

Read more …

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

October 31. On the road to improving cyber resilience

As Cyber Security Awareness Month draws to a close, it's important to recognise that cybersecurity isn't a destination; it's a continuous journey. For organisations, particularly those in the education sector, this journey often involves working towards recognised standards and certifications. In the UK, Cyber Essentials and Cyber Essentials Plus are government-backed schemes designed to help organisations protect themselves against common cyber threats. For schools, the Department for Educat

Read more …

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

October 29. Admin Controls & Accounts

Administrator accounts (often called "privileged accounts") are the most powerful and, so, the most sought-after targets for cybercriminals. These accounts hold the "keys to the kingdom," possessing extensive permissions to configure systems, access sensitive data, manage users, and make critical changes across an entire network or application. A single compromised admin account can lead to a catastrophic data breach, widespread system paralysis, or complete organisational takeover by attacke

Read more …

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

October 28. Phishing: Don't Take the Bait!

Phishing remains one of the most prevalent and effective cyberattack methods, tricking millions into compromising their data every year. These deceptive messages, often arriving via email, text message (smishing), or phone call (vishing), are designed to look legitimate. They aim to trick you into revealing sensitive information like login credentials, credit card numbers, or personal data, or to click on malicious links that install malware.  They may also be the start of a more complex

Read more …

"A graphic announcing 'October is Cyber Security Awareness Month,' with text explaining the importance of creating a cyber emergency contact list in preparation for a cyber attack. It also includes a 'Cyber tip' to assess passwords, turn on MFA, and review critical accounts, especially email. A shield icon with a checkmark and a lightbulb icon are visible."

October 27. Passwords

Your password is your first, and often most critical, line of defence. Yet, far too many people still rely on easily guessable combinations like "123456" or "password," leaving their digital lives wide open to attack. Cybercriminals use sophisticated tools to crack weak passwords in seconds, and is one of the easiest forms of attack - low risk.

Read more …

  1. October 26. Physical Security of Digital Assets
  2. October 25. Server Security: Protecting Your Digital Core
  3. October 24. Backups: Your Recovery Safety Net
  4. October 23. Filtering and Monitoring
  5. October 22. Hardware: Printers
  6. October 21. Hardware: Asset Management
  7. October 20. Hardware: Safe disposal
  8. October 19. Anti-virus/anti-malware
  9. October 18. Regular Updates: Patching Against Threats
  10. October 17. Access Control: Managing User Privileges
  11. October 16. Access Control: Securing Your Digital Gateways (Wi-Fi & Networks)
  12. October 15. Access Control: Securing Your Home Office (Working From Home)
  13. October 14. Access Control : (Multi-factor authentication)
  14. We've teamed up on a podcast with the Small Business Cyber Security Guy
  15. October 13. Cyber Security Awareness
  16. October 12. Training: Empowering your human firewall
  17. October 11. Policies and Procedures: Cyber Blueprint
  18. October 10. Understanding Your Cyber Posture
  19. Time's Ticking: Windows 10 support ends in October 2025!
  20. October 9. A Guide for Education Providers
  21. October 8. How Can Your Organisation Prevent Ransomware Attacks?
  22. October 7: Under Attack: The Reality of Ransomware
  23. October 6: Cyber Action Plan and A Roadmap to Resilience
  24. October 5: Cyber Responsibilities - We're All in This Together
  25. October 4: When a Cyber Attack Hits
  26. October 3: Data Security, the Core of Protection
  27. October 2: Privacy Protection & Safeguarding Personal Data
  28. October 1: Welcome to Cyber Security Awareness Month!
  29. Nursery Cyber attack
  30. Fraud awareness from the DfE
  31. The Classroom's Dark Side: Cyber crime from the Classroom
  32. Data Breach: School sends out names and contact details in a spreadsheet.
  33. KCSIE 2025: Data Protection, AI, and Cyber Security
  34. The Online SCR Data Breach: What You Need to Know
  35. Back to School Basics for Data Protection and Cyber Security Compliance
  36. The Latest Cyber Threat: The "Murky Panda"
  37. Building a Secure School: Using the ICO Accountability Framework to Meet DfE Digital Standards
  38. Why Physical and Data Security Must Go Hand-In-Hand
  39. Digital Safeguarding: DfE announces statutory DfE Digital Standards
  40. The Data Protection Lead/Champion Role
  41. Changes to the Academy Trust Handbook 2025
  42. School closes for two days after cyber incident
  43. Social Media Day 2025
  44. How Ofsted looks at AI during inspection and regulation
  45. Data Breaches 2025 Report Highlights
  46. Not everyone needs access: The Key to Protecting Sensitive Data
  47. School cyber attack: Outwood Academy, Middlesbrough
  48. Alert: Schools receiving Microsoft File Sharing Phishing Emails
  49. School cyber attack: Framlingham College, Suffolk
  50. West Lothian Schools in Cyber Attack
  51. A Wake-Up Call for Cyber Vigilance - Danger in the Threat Landscape for Everyone
  52. New Governor Resources
  53. Are teachers using AI? 83% say its a time-saver
  54. DfE Digital Standards - narrowing the digital divide
  55. Arbor AI - On By Default
  56. DfE Guidance: Choosing a new MIS
  57. Short Guide to AI Video
  58. Safer Internet Day, Cyber Security & Data Protection
  59. The Cyber Resilience Championship
  60. The Multiple Dimensions of Supplier Due Diligence
  61. School shares sensitive pupil information as part of an FOI response
  62. Blacon High School Cyber Attack
  63. WhatsApp and FOI's: ICO Warnings
  64. New AI Guidance from the DfE
  65. What the proposed Government legislative proposal around cyber crime means
  66. DfE update to record keeping and management
  67. Update to data sharing for school immunisation programmes
  68. SLT Digital Lead Profile
  69. The role of governors in cyber security and data protection
  70. Navigating Privacy at the End of Term , Special Occasions and End of Year
  71. South East Technological University has experienced a cyber incident
  72. Safeguarding Identity in Microsoft 365: Protecting the UK Education Sector Against Cyber Threats
  73. Cyber Attack on a Special School
  74. Stealing children's data
  75. Ofqual highlights the value of cyber security training in schools
  76. Fylde Coast Academy Trust Cyber Attack This Week
  77. Calling all IT leads in schools and mult academy trusts!
  78. Ransomware cyber attack on a school in Bromley
  79. School hit by Cyber Attack
  80. DfE Digital Standards for Schools and Colleges Tracker
  81. Schools and Trusts Best Practice Area
  82. ESFA Cyber Essentials Requirement for Colleges from 2024/2025
  83. ICO Reprimands a School
  84. Out of date technology
  85. Data Retention and the Pupil File
  86. Have you assigned your SLT Digital Lead yet?
  87. What's a Cyber Incident and what should we do?
  88. Getting Started with AI (Artificial Intelligence)
  89. Cyber attack on a school during half term
  90. The rise of cyber attacks in schools are causing pupils to miss classes
  91. Cyber attack on a Trust; the aftermath
  92. School Focus: The Vale Federation | Aylesbury
  93. DfE Dealing with Subject Access Requests (SARs) Guidance
  94. Update to the Guidance on Information Sharing from the DfE
  95. Product Focus on Checklists : Initial Trust Plan
  96. Product Focus on Checklists : End of Term Checklist
  97. Product Focus on Checklists : Social Media
  98. Product Focus on Checklists : Lettings
  99. Milk Island: The secret location that allows children to view restricted content on Google Maps
  100. Free Cyber help, advice and training with the Cyber Resilience Centres
  101. The Perils of Paper: The Printing Vulnerability
  102. Product Focus on Checklists : Governors and Data
  103. Product Focus on Checklists : Site Moves
  104. Cyber attack on a University
  105. Product Focus on Checklists : Bring your own device
  106. Product Focus on Checklists : Working out of school/offsite
  107. Cyber Attack on a School
  108. Major cyber-criminal gang Lockbit brought down by UK Law Enforcement
  109. Product Focus on Checklists : Photos and video
  110. Safer Internet Day 2024
  111. Kent Councils Data Breach
  112. Free cyber training for staff
  113. DfE Digital Standards Update
  114. ClassCharts Possible Data Breach
  115. School Focus: St Bernadette's Catholic Primary School | Brighton
  116. Guardians of Privacy: 16. Social Media Checklist
  117. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  118. Guardians of Privacy: 14. Social Media and Cyber Bullying
  119. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  120. Guardians of Privacy: 12. Social Media and Going Viral
  121. Guardians of Privacy: 11. Staff Social Media Accounts
  122. Guardians of Privacy: 10. Social Media and Cookies
  123. Guardians of Privacy: 9. Social Media and Morality
  124. New Resources for Schools from the ICO
  125. Guardians of Privacy: 8. Social Media Policies
  126. Guardians of Privacy: 7. Social Media Data Retention
  127. Guardians of Privacy: 6. Posting Safely
  128. Guardians of Privacy: 5. Social Media and Consent
  129. Guardians of Privacy: 4. Social Media Access Control
  130. Guardians of Privacy: 3. Social Media Channels
  131. Guardians of Privacy: 2. Law and Regulations
  132. Phishing attacks targeting schools - alert from City of London Police
  133. The ICO reprimands a Multi Academy Trust
  134. Guidance for the use of school email and applying email retention in schools
  135. Data Protection Tips for Early Years Settings
  136. Trust Initial Plan Checklist Update
  137. Update on Advisory for Rhysida Ransomware
  138. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  139. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  140. Lettings Best Practice and Guidance
  141. The UK Online Safety Bill becomes an Act (Law)
  142. Considerations when migrating to a new MIS
  143. The importance of software updates (PaperCut vulnerability and Rhysida ransomware)
  144. Public bodies and sensitive data
  145. ICO: 10 Step guide to sharing information to safeguard children
  146. Email and Security: ICO recent guidance
  147. Social Media Policy
  148. Data Protection and Cyber Security (Inset Day) Training Ideas
  149. Changes to Microsoft Free Licensing for Schools
  150. What to do in the event of a Cyber Attack
  151. How KCSIE is linked to Cyber Strategy
  152. VICE SOCIETY - Ransomware attacks on schools
  153. Using Tags if you are a group of organisations in the DPE Knowledge Bank
  154. Cyber Insurance in the Public Sector
  155. Cyber Attack: Leytonstone School
  156. The ICO Reprimands a school
  157. Cyber Attack: Dorchester School
  158. Knowledge Bank Role Types: Admin, Staff and Trustee
  159. Cyber Attack: Wiltshire School
  160. Types of Cyber Attacks: The Insider Threat
  161. Why your data is profitable to cyber criminals
  162. Striking Data Breach
  163. January Cyber update - How Can Schools Help Prevent Cyber Attacks?
  164. FOI: Vaccination Justifications
  165. The Education sector now at highest risk of cyber attacks
  166. Schools Blocked from Using Facial Recognition Systems
  167. The Children's Code
  168. Cyber Attacks
  169. Protocol for Setting Up and Delivery of Online Teaching and Learning
  170. Class Dojo International Data Sharing
  171. Secure file transfer of files using Royal Mail
  172. Emergency contacts and consent
  173. Best Practice for Managing Photos and Video
  174. Headteacher fined for breach of data protection legislation

Search