School cyberattacks – more schools have had sensitive staff and pupil data leaked – and what you can do to prevent them

We are concerned and disappointed to see another series of school hacking attacks reported by the BBC last week, resulting in confidential documents being posted online. 

This recent surge of cyberattacks on schools is a despicable attack on organisations already under immense pressure. Schools have had confidential and sensitive information, including children’s SEN information, child passport scans, staff pay scales and contract details, leaked online by malicious actors. 

It is essential for schools to take the necessary steps to protect their sensitive data and mitigate the risk of a successful attack but we understand how difficult this can be. Based on our experience in the sector, we outline four steps below to help get them on the right track as quickly and cost-effectively as possible.

Confidential sensitive staff and pupil data leaked

In this latest series of attacks, schools have experienced the loss of confidential and sensitive information including children’s SEN information, child passport scans, staff pay scales and contract details. 

Once the documents had been acquired, the cyber criminals attempted to blackmail the schools into making a payment to avoid their data being leaked online. 

The BBC reports that documents from 14 schools have been released online by a hacking group known as Vice Society, which it says “has been behind a high-profile string of attacks on schools across the UK and the USA in recent months.”

Securious has previously written about a ransomware attack on the Harris Federation, which it was ultimately able to withstand, but only with considerable cost and disruption.

What steps can schools take to protect their sensitive data?

At Securious, we understand the critical importance for schools to protect their data and we have developed tried and tested four-step approach to help them do just that:

1. External review (cyber security audit)

This is a third-party assessment of your cyber resilience that will help schools meet the requirements of the Academies Financial Handbook (AFH) and show stakeholders that they are aware of the importance of cyber security and are proactively addressing any weaknesses in their infrastructure

2. Penetration testing

This is a controlled attempt by qualified professionals to safely exploit your applications and network to determine whether they’re vulnerable to attack. The environment can then be better protected by mitigating any critical threats.

3. Cyber Essentials & Cyber Essentials Plus 

These certifications are great first steps towards making systems more secure. They are supported by the National Cyber Security Centre, recommended by the ICO and accredited through IASME.  The scheme is UK Government-backed and suitable for schools of all sizes.

4. Staff cyber security awareness training

People can be both the biggest risk factor and the greatest line of cyber defence. If they are trained in the latest threats and know how to respond, they can minimise the chance of attacks being successful. Training can be entirely online and take the form of simulated attacks with tailored feedback to individuals depending on the actions they take. 

What to do if you need help

At Securious, we believe every organisation in education should have access to the best cyber security advice and are offering a discount to all organisations in the sector. 

We want to help more schools, colleges, MATs, and universities across the UK strengthen their defences and minimise the loss of confidential information.

To learn more about the four steps above or for a free chat or consultation with one of our experienced education sector consultants, please call on 01392 247 110, email info@securious.co.uk or fill in the contact form below.

For more information and resources see our education help page