How schools, colleges, academies and MATs can improve their cyber security without breaking the bank

Whether you’re a school, college, academy or MAT, you’re responsible for protecting a lot of sensitive data. From information about vulnerable young people to your staff’s financial details. So it’s vital that you’ve taken appropriate steps to ensure that your systems are secure, and that this data can’t be accessed by cyber criminals.

Aside from your ethical (and legal) duties to protect the sensitive data in your care, a cyber attack could also have catastrophic consequences on your operations. Disruption to core systems and networks could stop your staff accessing electronic registers, your students from accessing coursework, and even compromise access to physical locations and tools – like electronic doors and whiteboards.

This would all make your day-to-day operations a real challenge at best, compromising safeguarding and making it almost impossible for teachers to do their jobs and students to learn. It won’t do your reputation any good either, and is likely to cost an eye-watering amount to fix.

But it is not a hopeless situation. There are some important steps you can take to minimise the risk without spending huge amounts of time or money on them.

So what steps should you be taking to protect your school from cyber attacks?

1) Find out how resilient you are

Before you spend a penny on cyber security solutions or technology, you need an assessment of your current cyber posture. You wouldn’t go and buy new parts for your car before you knew what was broken, and the same goes for cyber security.

Speak to an independent provider who can assess your current situation, and tell you what you need to do to make things better. You can do this in a couple of ways:

Cyber security audit / external review

This is a comprehensive, independent assessment of your current cyber security with a prioritised action plan for tackling issues. Get real, valuable, non-technical insights into your potential risks, threats and vulnerabilities, along with details of business or operational impact on the customer.

You’ll receive a detailed report with your strengths, weaknesses and any urgent issues that require attention, along with a prioritised road-map that suggests how you should address existing risks, threats and vulnerabilities.

Many cyber security providers offer this service. Securious’ cyber security audit starts at just £995.

Penetration testing

A penetration test is an attempt to safely exploit your IT systems to determine whether they’re vulnerable to attack. This means you can protect your systems and network by identifying and mitigating critical threats, which reduces the likelihood of a breach.

Imagine your systems and networks are a building. A penetration tester comes along and checks all your windows and doors. Then they report back to you, letting you know which are open, which are shut, and which are locked, so you can then ensure they are all appropriately secured, and you’re not left wide open to opportunists.

Penetration testing tends to be a service tailored to your individual needs and circumstances, so get in touch with a provider that looks right for you and ask them for a quote.

2) Make things better

Remediation

This means implementing the changes suggested in your audit or penetration test report. Chances are,it’s likely to be a series of improvements that need to be made by your IT team or external provider – and they’ll often be relatively simple, low-cost fixes.

Focus on sorting the critical threats and vulnerabilities first, working your way through the roadmap provided in your audit or penetration test.

Staff awareness training

A real quick win for improving your cyber security is educating your team. The number of cyber attacks that are caused by someone within your organisation doing something they shouldn’t – often out of lack of knowledge rather than malice or negligence – is staggering. Whether it’s clicking a dodgy link, downloading nasty malware or accidentally sending a payment to a cyber criminal rather than its intended recipient.

There’s no way of combating this risk using technology alone. That means it’s vital you educate your team around their own individual responsibilities in keeping your organisation safe. There are many ways you can do this. Whether it’s giving them regular updates about current threats or organising days (or weeks) of training to help improve their knowledge and behaviour, there’s a solution out there to suit everyone.

We’ve partnered with KnowBe4, a world leading provider of cyber security awareness training, to offer a comprehensive package managed by Securious. Your staff will receive simulated phishing emails in a totally safe way, and if they click a link they shouldn’t, they receive immediate feedback and training. You can see how many get it wrong, and track how quickly their ability to spot phishing emails and bad links improves.

It costs from under £3 per person per month and the great thing is, you are giving your staff a skill that will help protect them in their personal life too.

3) Get accredited

Cyber Essentials

Cyber Essentials is a great first step towards making your systems more secure – and having a badge to prove it. The certification is supported by the National Cyber Security Centre, recommended by the ICO and accredited through IASME. The scheme is UK Government-backed and suitable for organisations of all sizes, and we offer an Assisted Cyber Essentials package to get you accredited for just £595.

Cyber Essentials consists of a simple online self-assessment that allows you to demonstrate you are taking the appropriate measures to protect your systems, data and networks. The assessment targets your organisation’s internet-facing infrastructure, workstations and servers, in order to ensure your current software meets the necessary security standards.

You will need to answer the questions provided (we can provide support where needed), which will highlight any gaps in your current systems (which should be sorted before submission). Your responses will be reviewed to ensure that you meet the requirements, and we will come back to you if we believe further clarification is required. The latest guidelines specifically exclude student devices from the scope of the assessment.

Once the questionnaire has been successfully reviewed, your Cyber Essentials certificate & badge will be issued.

Cyber Essentials Plus

Cyber Essentials Plus is a step up from Cyber Essentials. It covers the same controls, only a third party (like us) verifies that the responses on the self-questionnaire are correct. This means it has considerably more credibility with key stakeholders, providing assurance that you take cyber security seriously.

It costs from £1,620 (+ vat), and you’ll go through the same process as Cyber Essentials, filling in the questionnaire and fixing issues prior to submission.

Once gaps are closed and the questionnaire is completed, we will carry out an on-site technical verification to ensure you have met the requirements of the scheme. We perform an external vulnerability scan to ensure and demonstrate that the final requirements have been met, before preparing a report of our findings for you and arranging for the Cyber Essentials Plus certificate and badge to be issued.

Schools and cyber security – final thoughts

We’ve covered a lot in this article, but don’t think that means you have to do all of the above to improve your cyber security. It’s not an all or nothing thing – any improvements are good, helping you move forward on your journey to being cyber secure. You need to keep working on it – perfection isn’t the point: progress is the key and regular small steps are better than big occasional interventions that are quickly forgotten.

If you want to talk to a member of our team about improving your school, college, academy or MAT’s cyber security, get in touch using the contact form below.

Otherwise, check out the dedicated page on our website for schools, colleges, academies and MATs by clicking here.