Popular Post cybermonkey Posted April 29, 2022 Popular Post Posted April 29, 2022 Hello, This is my first post on the site so forgive me if I don't follow etiquette correctly. I am working on a project that is looking at the Cyber Security within schools. I have had numerous chats with a variety of school officials from School IT Staff, Governors, Head Teachers etc.. and there appears to be a reluctance to sometimes share information openly (understandable when we're talking and looking into how a Cyber attack occurred. We Hypothesis that usually time, money & resource are major factors behind why attacks happen. What I want to try and do is quantify some of those things and understand what the Direct & more importantly the Indirect costs are. I have added a table below that defines what I mean by Direct & Indirect. I have also have a browse through the forum and found what look like really useful pages (sadly some of them are hidden behind restricted walls) [TABLE=width: 0] [TR] [TD][/TD] [TD]Short Term (Days)[/TD] [TD]Medium Term (Weeks)[/TD] [TD]Long Term (Months)[/TD] [/TR] [TR] [TD]Direct Costs[/TD] [TD]* Consultant fees * Cyber ransom and extortion losses * Financial theft * Insurance excess * Staff response (overtime) * Staff response costs (contracting external staff)[/TD] [TD]* Changes in cyber security practices * Compensation/discounts * Complaints (external) * Fines * Investigation (external) * Legal * PR/marketing activities (external) * Recruitment costs * Third party liability[/TD] [TD]* Credit rating/insurance premiums * Cyber security improvements * Investment/donor/funding loss * Staff costs (long term) * Training costs * Training costs (external resources) [/TD] [/TR] [TR] [TD]Indirect Costs[/TD] [TD]* Containment * Data and software loss * Intellectual property theft * Interruption of staffs’ business as usual activities (opportunity cost) * IT equipment damage * Notification costs (authorities) * Notification costs (customer) * Physical equipment damage (not including IT equipment damage) * Interruption of service [/TD] [TD]* Complaints (internal) * Investigation (internal) * Post-breach customer protection * PR/marketing activities (internal)[/TD] [TD]* Customer attrition * Cyber security improvements (opportunity cost) * Long term productivity * Supply chain attrition * Training costs (internal resources) * Training costs (opportunity cost) [/TD] [/TR] [/TABLE] Any information, data or papers that people would be willing and able to share would be greatly appreciated. Thanks 5
GrumbleDook Posted May 3, 2022 Posted May 3, 2022 This is a really good list and a perfect way to start to help quantify things for your SLT. Some members will have already had to deal with some of this, so do people think anything is missing at all? Is anybody willing to DM and share some info (if you can't do it publicly)? 1
Popular Post DrBeaker Posted May 3, 2022 Popular Post Posted May 3, 2022 Sadly until something happens I don't think they will take IT or Cyber security seriously. Just my 2 cents. A lot of tech in schools is simply a sticking plaster on top of an older sticking plaster, bodging a solution. There's no interest and no investment in equipment despite IT being proactive and trying to make them aware and educate them. e.g. If you left your front door unlocked on your house, got burgled and told the insurance you couldn't be bothered to lock your front door - they'd void your claim. Pretty simply really. Sad to be in an industry that's supposed to be cutting-edge but they don't want to spend proper money to fix things. 5
Popular Post pete Posted May 3, 2022 Popular Post Posted May 3, 2022 The Harris Federation after-action report from the CEO is about the most forthright I've seen an SLT/Trust-level non-technical person be about an incident: Particularly useful for making leadership pay attention is when he gets to the "all the incident response firms within the UK were fully booked" and "our cyber insurance only covered 2/3 (£500K) of the cost of recovery" parts. Training costs (under long-term) should be highlighted as "you should be paying for this anyway", since doing so goes a long way toward mitigating all the other costs. 6
Primus Posted May 3, 2022 Posted May 3, 2022 Sadly until something happens I don't think they will take IT or Cyber security seriously. Just my 2 cents. A lot of tech in schools is simply a sticking plaster on top of an older sticking plaster, bodging a solution. There's no interest and no investment in equipment despite IT being proactive and trying to make them aware and educate them. e.g. If you left your front door unlocked on your house, got burgled and told the insurance you couldn't be bothered to lock your front door - they'd void your claim. Pretty simply really. Sad to be in an industry that's supposed to be cutting-edge but they don't want to spend proper money to fix things. It's not like that everywhere...
DrBeaker Posted May 3, 2022 Posted May 3, 2022 It's not like that everywhere... Would you say that's down to legitimate interest e.g. in risk mitigation/reduction, actual knowledgeable SLT/Management etc? Some schools are light years ahead of others.
Primus Posted May 3, 2022 Posted May 3, 2022 Would you say that's down to legitimate interest e.g. in risk mitigation/reduction, actual knowledgeable SLT/Management etc? Some schools are light years ahead of others. In my current case I'm fortunate to have leaders that will listen to experts - at least most of the time. But some of it's how you engage with them. Educating them, little and often. Sending them snippets of articles, referencing ransomware in conversations about hardware refresh: "This is why replacing these PCs before 2025 is so important so that we can move to Windows 11 so we still get security updates - if we get stuck on Windows 10 we'll get no further security updates making ransomware more likely." Gentle reminders about data protection requiring us to take "all reasonable steps" - when they propose something that isn't reasonable flagging it. Involving outside trusted opinions to back up what you're saying. Getting certifications and qualifications yourself to give yourself some weight behind your points (this is more difficult but there are some qualifications that sound good and are easy to get - eg. Microsoft Innovative Educator, Google Certified Educator/Trainer [a bit less easy but still not that tough] etc.)
cybermonkey Posted May 4, 2022 Author Posted May 4, 2022 This is a really good list and a perfect way to start to help quantify things for your SLT. Some members will have already had to deal with some of this, so do people think anything is missing at all? Is anybody willing to DM and share some info (if you can't do it publicly)? Thanks for that. There is a lot of information out there. Lots of surveys have been done by the DfE, IPSOS Mori and other bodies.. yet still the lack of quantifiable data is extraordinary. I appreciate it's one of those things that is just dealt with when something happens. However people must have an understanding of what was spent, headteachers surely? Just to add any data that is shared will be completely anonymous or accredited correctly which ever the sharer of the information wants.
MartinT Posted May 4, 2022 Posted May 4, 2022 I have found that you can get the attention of the SLT/SMT if you state your case succinctly (and your list is an excellent help) and present them with case studies of damage to other schools as well as good videos like the NCSC one for school staff. It's also worth giving governors a heads-up because some of them will work in industry and be aware of what's going on in the cyber world. They will not want your school to be attacked and will be prepared to listen. The cost of improving security is not always money; you can get a great deal done with just time and effort.
foofighterjim Posted May 4, 2022 Posted May 4, 2022 The cost of improving security is not always money; you can get a great deal done with just time and effort. And training. 2
JoeRogue Posted May 4, 2022 Posted May 4, 2022 We've been concentrating on this for nearly a year now and luckily the Bursar is quite proactive. Pushed 2FA on our Google accounts, double/triple checked firewall settings etc. Biggest thing that someone has already mentioned is training and just making people aware. As with most things in schools, it needs SLT/SMT to lead by example and that isn't always the case.
Brax Posted May 4, 2022 Posted May 4, 2022 IT teams do their best to secure everything as they know the risks. But with most things in education it's down to training and funding and getting everyone on board. I'd assume the biggest risk to most schools is Social Engineering and Phishing emails along with out of date equipment. The wannacry NHS attack springs to mind.
slim1986 Posted May 4, 2022 Posted May 4, 2022 Sadly until something happens I don't think they will take IT or Cyber security seriously. Just my 2 cents. A lot of tech in schools is simply a sticking plaster on top of an older sticking plaster, bodging a solution. There's no interest and no investment in equipment despite IT being proactive and trying to make them aware and educate them. e.g. If you left your front door unlocked on your house, got burgled and told the insurance you couldn't be bothered to lock your front door - they'd void your claim. Pretty simply really. Sad to be in an industry that's supposed to be cutting-edge but they don't want to spend proper money to fix things. Great analogy. Unfortunately I can't see things improving any time soon when the cost of services etc. are rising as quickly as they are.
DrBeaker Posted May 4, 2022 Posted May 4, 2022 Great analogy. Unfortunately I can't see things improving any time soon when the cost of services etc. are rising as quickly as they are.Yep...just look at the 'hidden costs' schools have with reconfiguring the crappy spec DfE laptops as an example of rising costs. 1
pete Posted May 4, 2022 Posted May 4, 2022 (edited) Would you say that's down to legitimate interest e.g. in risk mitigation/reduction, actual knowledgeable SLT/Management etc? It's a combination of the IT team teaching them to care, with occasionally deployment of pointy (May 2018 GDPR deadline), sticks (external security audit) when ($staff_member did something daft, it wasted days of people's time) necessary (RPA Cyber cover requirements from ~Sep 2022) to move (YouTube link above) them along in the right direction. Plus when you improve their safety, make sure they know about it (include on the "cool things I did" section of your appraisal) and collect before/after metrics to demonstrate benefit. Over time they should (assumes reasonable people) realise that you: Come to them with a solution to any problems you flag up Are involving them because you need their support or sign-off and wouldn't be bothering them if you could fix it under your own authority Don't create lots of work for yourself if it isn't necessary In terms of pointy sticks available to you now.... If your school uses the RPA for insurance (many do, it's pretty cheap), the requirements for the newly-introduced Cyber Cover is: Staff have to undergo NCSC Training - https://www.ncsc.gov.uk/information/cyber-security-training-schools (we've just finished everyone last week) You need offline backups Register with police CyberAlarm (don't install the software though) Have a Cyber response plan in place The opportunity cost for not doing the above is losing £250K of cover, should you have an incident. Send them the YouTube link above up-thread as well. I'd also ask for a copy of the IT section of the school/trusts risk register and red pen all over it where it's missing risks and mitigations. Include things you've already mitigated too - you need to blow your own trumpet. -- Disclaimer: Leadership here respond well (if occasionally grumpily) to constructive criticism provided it's valid. They're also not egomaniacs. My line manager is the trust CEO. YMMV. Edited May 4, 2022 by pete typo 3
PotNoodleTech Posted May 6, 2022 Posted May 6, 2022 Interesting thread. I think sadly, most are only going to realise the cost after it's happened. 1
pete Posted May 6, 2022 Posted May 6, 2022 Interesting thread. I think sadly, most are only going to realise the cost after it's happened. Reasonable (don't cry wolf) extrapolation from smaller-scale incidents can help. Especially if you merely got lucky it was a small-scale incident. 1
free780 Posted May 6, 2022 Posted May 6, 2022 I experienced locky affect 1 user on a RDS host a few years back. It sped up getting AppLocker enforced and a rigorous checking of defender settings that needed enabling.
OSSMAPhil Posted May 16, 2022 Posted May 16, 2022 Hi, in terms of the RPA, what are other schools looking into or already done. I have not been passed any information about the RPA and what we need to do to be covered, the Business Manager has just asked to get quotes for a Pen test, but companies are also offering cheaper vulnerability assessments.
pete Posted May 16, 2022 Posted May 16, 2022 Hi, in terms of the RPA, what are other schools looking into or already done. I have not been passed any information about the RPA and what we need to do to be covered, the Business Manager has just asked to get quotes for a Pen test, but companies are also offering cheaper vulnerability assessments. Your business manager will have a one-page summary (copy attached) RPA Cyber Cover Summary (1).pdf sent from rpa.dfe@education dot gov dot uk circa 14:00 on 15th February. There is no requirement for a penetration test as part of it, but a general vulnerability assessment or pen test as a budget lever is never a bad thing. Shop around though and ask pre-sales questions like "If you're looking for evidence of password policies (for example), does the employee running the assessment/tool know to look in GPOs *and* Password Setting Objects?". 1
Shixn Posted October 2, 2023 Posted October 2, 2023 Great Information, I have seen whole borough/district use the same wifi password... Makes me wonder if they are actually trying to protect their data or if they just want to invite attackers:suicide:
filteringtech Posted October 2, 2023 Posted October 2, 2023 You will also need some commitment/contract review from ISPs and filtering providers where they supply the filtering and firewall. They "should" be on the asset side of the equation, but they seem to be more appropriate placed on the risk side. A firewall with no logging for example is practically useless. They also need to get up to speed with Cloud Architecture, specifically the difference between the cloud provider's platform architecture and the mass of user content hosted in the platform's cloud. I am truly AMAZED at the number of ISPs and filtering providers who when recently asked, just whitelist everything Microsoft for example "because its Microsoft" regardless that some is just phishing, malware and other regular crapware uploaded to Microsoft Cloud by any bad actor. The same is true for user content on Google, Amazon et al. You might not even know this "if the whitelist settings are hidden from you". Don't even think of getting me started on why they whitelist infected ad networks. Yes I know we have virus guards and the like, but a proper multi-layered approach needs each layer to be configured appropriately.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now