Zoom7000 Posted July 2, 2024 Posted July 2, 2024 (edited) It's a bit short notice, but I'm meeting with the DfE's cyber security lead tomorrow morning at 9:30am to discuss the NCSC's cyber security training resources. This stems from a post I made on LinkedIn a few weeks ago mentioning that the training hadn't been updated in over 3 years. Did anyone have any suggestion for items that need to be included in any update of the resources? Or even general thoughts about the materials. Here's a copy of my post for those who might not be on LinkedIn: Hey National Cyber Security Centre! Let's talk about "Cyber security training for school staff" The RPA (Risk Protection Arrangement) requires schools to ensure that all school staff have undertaken training on Cyber Security using the content from the NCSC's website, in order to be eligible for their cyber cover offering: https://www.ncsc.gov.uk/information/cyber-security-training-schools However, this content hasn't been updated in over 3 years. The Cyber Security landscape has changed a LOT in that time. I think it's well overdue for an update to the content. Edited July 2, 2024 by Zoom7000 4
Popular Post kevin_lane Posted July 2, 2024 Popular Post Posted July 2, 2024 Lol I remember seeing this made me chuckle, Could you perhaps get them to fund all Network Managers / IT Techs to go on some sort of Cyber security certification, im thinking Security+ CISSP, EHC course or something that is combined and is certified by the NCSC and recognised achievement….and free?? “Just a thought” 5
pete Posted July 2, 2024 Posted July 2, 2024 If we're playing the "Blog posts that the NCSC should really have updated by now" game, could you point them towards this one: https://www.ncsc.gov.uk/blog-post/offline-backups-in-an-online-world from almost 5 years ago that the RPA is relying on to make decisions about what counts as an "offline" backup? Better yet, have a mechanism for reviewing and updating blog posts that other government depts (with or without NCSC's knowledge) are using to justify decisions to make sure said blog posts are still effective advice.
bitznpcz Posted July 2, 2024 Posted July 2, 2024 A general refresh of the video would be a good start if teachers and governors are to watch it every year. Lots of SBMs have been falling for phishing emails recently so more focus on that, plus vishing, smishing and quishing (QR code phishing), whaling, spearphishing and gift card scams (particularly for MATs). A few other ideas: A section on AI and deepfakes maybe. A section about what makes a good password and why you should have unique passwords for every site and service. MFA Data Loss Prevention / GDPR / Secure File Sharing Patch management (and why you should periodically reboot your computer to install updates). Supply Chain Attacks Incident response - what to do 2
TechMonkey Posted July 3, 2024 Posted July 3, 2024 Is it just about training? Can you bring up the travesty that is CyberAlarm? Ask why they are allowing the Police to take lead on it and explain what a mess it is? 3
Michael Posted July 3, 2024 Posted July 3, 2024 A few things come to mind really - Cyber Security Training doesn't require authentication, so anyone can download and populate the certificate and state they've viewed it: https://www.ncsc.gov.uk/information/cyber-security-training-schools + last reviewed in April 2021. Schools generally review all policies every 12 months. The MyNCSC portal seems to be forever in Beta (literally years now). Despite the advisories, some hosting providers are just stubborn and will still block the Web Check service. There's no framework as such (as far as I can tell) for third party hosting providers to adhere to, other than linking them to the main NCSC website. It needs to get to a point where it's compulsory, just as Safeguarding is. Related to the above, maybe a referral program to accelerate the compliance for all schools? Overall a positive experience and it's useful to gauge Mail Security procedures which are up-to-date.
Michael Posted July 3, 2024 Posted July 3, 2024 Separately, but this is probably more a DfE thing - Government should broker a deal with both Microsoft and Google to unlock some of the paid for features, which would benefit all UK schools and enforce better security standards by default. By this I primarily mean Conditional Access. 3
bitznpcz Posted July 3, 2024 Posted July 3, 2024 Separately, but this is probably more a DfE thing - Government should broker a deal with both Microsoft and Google to unlock some of the paid for features, which would benefit all UK schools and enforce better security standards by default. By this I primarily mean Conditional Access.I have broached this with a few companies - the problem is how to handle schools that are already paying for A3 and A5 licenses etc - should they be entitled to a discount? Would they stop paying if Microsoft made this free? I completely agree with you, but it's a difficult thing for the vendors to manage. There's lots of other things that would be nice to have, such as Impossible Travel alerts to detect IPs from foreign countries. 2
timbo343 Posted July 3, 2024 Posted July 3, 2024 Mention that the video doesn't have to be watched as the certificate can be accessed without watching the video - if can be found in the description of the video and can be easily modified - certificate here: https://www.youtube.com/redirect?event=video_description&redir_token=QUFFLUhqa3RFUGdMMGhGQkpVVTV0VjhNeVZJRWRNNWVZUXxBQ3Jtc0tuYkdfRHBFakkxbGo3akk2ZDhpelVIbFk3NGF6REQ2YzVXWjBkOWpRVUI4SFdqazNxS3BZaVJuSU13akdfOUh3SW1iam40Rk0xSnN0RTlRWWFkVjk1VVpGTnJCRjFDTnlRRHluY1I1NzlKXzBIN0I1bw&q=https%3A%2F%2Fwww.ncsc.gov.uk%2Fcyber-security-schools-training-certificate&v=pP2VKWSagE0 Video URL: Therefore schools are turning to systems that require staff to watch the video and then complete the certificate that contains Organisation Name, Date it was completed. Bit of a shower of .. if you ask me considering it's mandatory. 1
PotNoodleTech Posted July 3, 2024 Posted July 3, 2024 Haha you mouthed off on social media now you got the telling off to come I actually agree that upgraded google and office365 licences for all school would probably make the most difference as then each network manager would have the tools to 100% tighten up the cybersecurity whilst still making it as easy to use as it can be. Training - training for IT managers/techs is really important and most schools won't fund it - i got turned down for a course as it was too expensive all about cyber securing office365 etc and they then denied the 400 quid a year for upgraded office licenses for conditional access etc - if anything ever happens I got the I told you so card printed out ready to go. reason I got it printed out is that the network will be down when I need it.... Training for staff - needs to be made mandatory alongside safeguarding training or you're flogging a dead horse if it's voluntary. Apparently 80% of all cybersecurity incidents are through phishing so that needs to be targeted as the highest priority really. Upgraded licences help here, training for IT staff helps here. mandatory training for staff helps here. 4
Michael Posted July 3, 2024 Posted July 3, 2024 I have broached this with a few companies - the problem is how to handle schools that are already paying for A3 and A5 licenses etc - should they be entitled to a discount? Would they stop paying if Microsoft made this free? I completely agree with you, but it's a difficult thing for the vendors to manage. There's lots of other things that would be nice to have, such as Impossible Travel alerts to detect IPs from foreign countries. I guess it's like anything - a change of policy and a change of procedure going forward. It doesn't necessarily need to include the whole of A3 or A5, but certainly some more crucial aspects to boost security. This would be far more beneficial rather than it being advisory or hypothetical for smaller establishments (which there are still many)! 1
bitznpcz Posted July 3, 2024 Posted July 3, 2024 I guess it's like anything - a change of policy and a change of procedure going forward. It doesn't necessarily need to include the whole of A3 or A5, but certainly some more crucial aspects to boost security. This would be far more beneficial rather than it being advisory or hypothetical for smaller establishments (which there are still many)!I totally agree, but don't think it will happen. I'd love to have Microsoft Defender for O365 P2 included in the A1 licenses as that would prevent a lot of phishing emails and you could argue that Microsoft could do more to protect their uses, but they're in business to make money at the end of the day.
robintech Posted July 3, 2024 Posted July 3, 2024 MFA mainly , at the moment MFA is "where possible" in a section about complex passwords, I think it should be MFA enforced everywhere and let people keep a password that doesn't expire and allow simpler passwords.
fiza Posted July 3, 2024 Posted July 3, 2024 Ask them if they could collaborate with someone like the National College to create a video course that asks questions, doesn’t let you skip parts and prints a certificate at the end. 1
DavonPotter Posted July 8, 2024 Posted July 8, 2024 That sounds like a crucial meeting! It's great to see you advocating for updated cybersecurity training resources. Given how rapidly the landscape changes, updating the content definitely seems vital. Maybe including more real-life case studies or practical scenarios could make the training more engaging and relevant to current threats. Best of luck with your discussion!
howartp Posted July 8, 2024 Posted July 8, 2024 Ask them if they could collaborate with someone like the National College to create a video course that asks questions, doesn’t let you skip parts and prints a certificate at the end. This! I came to say, “can they host the video somewhere and require us to complete it?” If National College can do it, staff all have logins already for it so win-win!
jmak Posted July 8, 2024 Posted July 8, 2024 That sounds like a crucial meeting! It's great to see you advocating for updated cybersecurity training resources. Given how rapidly the landscape changes, updating the content definitely seems vital. Maybe including more real-life case studies or practical scenarios could make the training more engaging and relevant to current threats. Best of luck with your discussion! Sick response man. Everything moves so fast I'm dizzy. Totally dope to have you onboard. I'm glad you mentioned luck. I'll be sure to take my four leafed clover with me!
mikes Posted July 10, 2024 Posted July 10, 2024 I think it's a bit of a sad joke that MS and Google will offer free licenses to schools yet won't offer the licenses good enough to actually safeguard children's data properly. Shows they aren't really actually doing it out of the kindness of their heart after all. They are of course after money and we should never forget that. Anyway my head is swirling with cybersecurity policies after reading page after page of corporate-speak after filling in the Welsh 360 forms showing how well we are complying with online safety, a lot of it basically repeating the same thing over and over but slightly differently. Like others said I wish they could have some more real life examples and actual help than corporate policy speak saying "thou must" but not actually telling you how to accomplish such things.
Zoom7000 Posted July 15, 2024 Author Posted July 15, 2024 @Zoom7000 - How did the meeting go? It was a good meeting, but how productive it was, I'm not too sure. The representative was nice and welcoming, but I guess the meeting happened at the worst possible time, being the day before the general election and the inevitable change of the government. There's also some insane levels of bureaucracy which is probably not surprising. We've agreed to stay in touch and meet again at a later date once things have settled down at the DfE.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now