Jump to content

Recommended Posts

Posted
This is a really good list and a perfect way to start to help quantify things for your SLT. Some members will have already had to deal with some of this, so do people think anything is missing at all? Is anybody willing to DM and share some info (if you can't do it publicly)?
  • Thanks 1
Posted
Sadly until something happens I don't think they will take IT or Cyber security seriously. Just my 2 cents.

 

A lot of tech in schools is simply a sticking plaster on top of an older sticking plaster, bodging a solution.

 

There's no interest and no investment in equipment despite IT being proactive and trying to make them aware and educate them.

 

e.g. If you left your front door unlocked on your house, got burgled and told the insurance you couldn't be bothered to lock your front door - they'd void your claim. Pretty simply really.

 

Sad to be in an industry that's supposed to be cutting-edge but they don't want to spend proper money to fix things.

 

It's not like that everywhere...

Posted
It's not like that everywhere...

 

Would you say that's down to legitimate interest e.g. in risk mitigation/reduction, actual knowledgeable SLT/Management etc?

 

Some schools are light years ahead of others.

Posted
Would you say that's down to legitimate interest e.g. in risk mitigation/reduction, actual knowledgeable SLT/Management etc?

 

Some schools are light years ahead of others.

 

In my current case I'm fortunate to have leaders that will listen to experts - at least most of the time. But some of it's how you engage with them. Educating them, little and often. Sending them snippets of articles, referencing ransomware in conversations about hardware refresh:

"This is why replacing these PCs before 2025 is so important so that we can move to Windows 11 so we still get security updates - if we get stuck on Windows 10 we'll get no further security updates making ransomware more likely."

 

Gentle reminders about data protection requiring us to take "all reasonable steps" - when they propose something that isn't reasonable flagging it. Involving outside trusted opinions to back up what you're saying. Getting certifications and qualifications yourself to give yourself some weight behind your points (this is more difficult but there are some qualifications that sound good and are easy to get - eg. Microsoft Innovative Educator, Google Certified Educator/Trainer [a bit less easy but still not that tough] etc.)

Posted
This is a really good list and a perfect way to start to help quantify things for your SLT. Some members will have already had to deal with some of this, so do people think anything is missing at all? Is anybody willing to DM and share some info (if you can't do it publicly)?

 

Thanks for that. There is a lot of information out there. Lots of surveys have been done by the DfE, IPSOS Mori and other bodies.. yet still the lack of quantifiable data is extraordinary. I appreciate it's one of those things that is just dealt with when something happens. However people must have an understanding of what was spent, headteachers surely?

 

Just to add any data that is shared will be completely anonymous or accredited correctly which ever the sharer of the information wants.

Posted

I have found that you can get the attention of the SLT/SMT if you state your case succinctly (and your list is an excellent help) and present them with case studies of damage to other schools as well as good videos like the NCSC one for school staff. It's also worth giving governors a heads-up because some of them will work in industry and be aware of what's going on in the cyber world. They will not want your school to be attacked and will be prepared to listen.

 

The cost of improving security is not always money; you can get a great deal done with just time and effort.

Posted

We've been concentrating on this for nearly a year now and luckily the Bursar is quite proactive. Pushed 2FA on our Google accounts, double/triple checked firewall settings etc.

 

Biggest thing that someone has already mentioned is training and just making people aware. As with most things in schools, it needs SLT/SMT to lead by example and that isn't always the case.

Posted
IT teams do their best to secure everything as they know the risks. But with most things in education it's down to training and funding and getting everyone on board. I'd assume the biggest risk to most schools is Social Engineering and Phishing emails along with out of date equipment. The wannacry NHS attack springs to mind.
Posted
Sadly until something happens I don't think they will take IT or Cyber security seriously. Just my 2 cents.

 

A lot of tech in schools is simply a sticking plaster on top of an older sticking plaster, bodging a solution.

 

There's no interest and no investment in equipment despite IT being proactive and trying to make them aware and educate them.

 

e.g. If you left your front door unlocked on your house, got burgled and told the insurance you couldn't be bothered to lock your front door - they'd void your claim. Pretty simply really.

 

Sad to be in an industry that's supposed to be cutting-edge but they don't want to spend proper money to fix things.

 

 

Great analogy. Unfortunately I can't see things improving any time soon when the cost of services etc. are rising as quickly as they are.

Posted
Great analogy. Unfortunately I can't see things improving any time soon when the cost of services etc. are rising as quickly as they are.
Yep...just look at the 'hidden costs' schools have with reconfiguring the crappy spec DfE laptops as an example of rising costs.
  • Thanks 1
Posted (edited)
Would you say that's down to legitimate interest e.g. in risk mitigation/reduction, actual knowledgeable SLT/Management etc?

 

It's a combination of the IT team teaching them to care, with occasionally deployment of pointy (May 2018 GDPR deadline), sticks (external security audit) when ($staff_member did something daft, it wasted days of people's time) necessary (RPA Cyber cover requirements from ~Sep 2022) to move (YouTube link above) them along in the right direction. Plus when you improve their safety, make sure they know about it (include on the "cool things I did" section of your appraisal) and collect before/after metrics to demonstrate benefit.

 

Over time they should (assumes reasonable people) realise that you:

 

  • Come to them with a solution to any problems you flag up
  • Are involving them because you need their support or sign-off and wouldn't be bothering them if you could fix it under your own authority
  • Don't create lots of work for yourself if it isn't necessary

 

In terms of pointy sticks available to you now....

 

If your school uses the RPA for insurance (many do, it's pretty cheap), the requirements for the newly-introduced Cyber Cover is:

 

The opportunity cost for not doing the above is losing £250K of cover, should you have an incident. Send them the YouTube link above up-thread as well.

 

I'd also ask for a copy of the IT section of the school/trusts risk register and red pen all over it where it's missing risks and mitigations. Include things you've already mitigated too - you need to blow your own trumpet.

 

--

 

Disclaimer:

 

Leadership here respond well (if occasionally grumpily) to constructive criticism provided it's valid. They're also not egomaniacs. My line manager is the trust CEO. YMMV.

Edited by pete
typo
  • Thanks 3
Posted
Interesting thread. I think sadly, most are only going to realise the cost after it's happened.

 

Reasonable (don't cry wolf) extrapolation from smaller-scale incidents can help. Especially if you merely got lucky it was a small-scale incident.

  • Thanks 1
Posted

I experienced locky affect 1 user on a RDS host a few years back.

 

It sped up getting AppLocker enforced and a rigorous checking of defender settings that needed enabling.

  • 2 weeks later...
Posted

Hi, in terms of the RPA, what are other schools looking into or already done.

I have not been passed any information about the RPA and what we need to do to be covered, the Business Manager has just asked to get quotes for a Pen test, but companies are also offering cheaper vulnerability assessments.

Posted
Hi, in terms of the RPA, what are other schools looking into or already done.

I have not been passed any information about the RPA and what we need to do to be covered, the Business Manager has just asked to get quotes for a Pen test, but companies are also offering cheaper vulnerability assessments.

 

Your business manager will have a one-page summary (copy attached) RPA Cyber Cover Summary (1).pdf sent from rpa.dfe@education dot gov dot uk circa 14:00 on 15th February.

 

There is no requirement for a penetration test as part of it, but a general vulnerability assessment or pen test as a budget lever is never a bad thing.

 

Shop around though and ask pre-sales questions like "If you're looking for evidence of password policies (for example), does the employee running the assessment/tool know to look in GPOs *and* Password Setting Objects?".

  • Thanks 1
  • 1 year later...
Posted

Great Information,

I have seen whole borough/district use the same wifi password...

Makes me wonder if they are actually trying to protect their data or if they just want to invite attackers:suicide:

Posted

You will also need some commitment/contract review from ISPs and filtering providers where they supply the filtering and firewall. They "should" be on the asset side of the equation, but they seem to be more appropriate placed on the risk side.

 

A firewall with no logging for example is practically useless.

 

They also need to get up to speed with Cloud Architecture, specifically the difference between the cloud provider's platform architecture and the mass of user content hosted in the platform's cloud. I am truly AMAZED at the number of ISPs and filtering providers who when recently asked, just whitelist everything Microsoft for example "because its Microsoft" regardless that some is just phishing, malware and other regular crapware uploaded to Microsoft Cloud by any bad actor. The same is true for user content on Google, Amazon et al. You might not even know this "if the whitelist settings are hidden from you".

 

Don't even think of getting me started on why they whitelist infected ad networks.

 

Yes I know we have virus guards and the like, but a proper multi-layered approach needs each layer to be configured appropriately.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...