Jump to content

Recommended Posts

Posted (edited)

It's a bit short notice, but I'm meeting with the DfE's cyber security lead tomorrow morning at 9:30am to discuss the NCSC's cyber security training resources.

 

This stems from a post I made on LinkedIn a few weeks ago mentioning that the training hadn't been updated in over 3 years.

 

Did anyone have any suggestion for items that need to be included in any update of the resources? Or even general thoughts about the materials.

 

Here's a copy of my post for those who might not be on LinkedIn:

 

Hey National Cyber Security Centre! Let's talk about "Cyber security training for school staff"

 

The RPA (Risk Protection Arrangement) requires schools to ensure that all school staff have undertaken training on Cyber Security using the content from the NCSC's website, in order to be eligible for their cyber cover offering: https://www.ncsc.gov.uk/information/cyber-security-training-schools

 

However, this content hasn't been updated in over 3 years. The Cyber Security landscape has changed a LOT in that time. I think it's well overdue for an update to the content.

Edited by Zoom7000
  • Thanks 4
Posted

If we're playing the "Blog posts that the NCSC should really have updated by now" game, could you point them towards this one:

 

https://www.ncsc.gov.uk/blog-post/offline-backups-in-an-online-world

 

from almost 5 years ago that the RPA is relying on to make decisions about what counts as an "offline" backup?

 

Better yet, have a mechanism for reviewing and updating blog posts that other government depts (with or without NCSC's knowledge) are using to justify decisions to make sure said blog posts are still effective advice.

Posted

A general refresh of the video would be a good start if teachers and governors are to watch it every year.

 

Lots of SBMs have been falling for phishing emails recently so more focus on that, plus vishing, smishing and quishing (QR code phishing), whaling, spearphishing and gift card scams (particularly for MATs).

 

A few other ideas:

 

A section on AI and deepfakes maybe.

 

A section about what makes a good password and why you should have unique passwords for every site and service.

 

MFA

 

Data Loss Prevention / GDPR / Secure File Sharing

 

Patch management (and why you should periodically reboot your computer to install updates).

 

Supply Chain Attacks

 

Incident response - what to do

  • Thanks 2
Posted
Is it just about training? Can you bring up the travesty that is CyberAlarm? Ask why they are allowing the Police to take lead on it and explain what a mess it is?
  • Thanks 3
Posted

A few things come to mind really -

 

Cyber Security Training doesn't require authentication, so anyone can download and populate the certificate and state they've viewed it: https://www.ncsc.gov.uk/information/cyber-security-training-schools + last reviewed in April 2021. Schools generally review all policies every 12 months.

 

The MyNCSC portal seems to be forever in Beta (literally years now).

 

Despite the advisories, some hosting providers are just stubborn and will still block the Web Check service. There's no framework as such (as far as I can tell) for third party hosting providers to adhere to, other than linking them to the main NCSC website. It needs to get to a point where it's compulsory, just as Safeguarding is.

 

Related to the above, maybe a referral program to accelerate the compliance for all schools?

 

Overall a positive experience and it's useful to gauge Mail Security procedures which are up-to-date.

Posted

Separately, but this is probably more a DfE thing -

 

Government should broker a deal with both Microsoft and Google to unlock some of the paid for features, which would benefit all UK schools and enforce better security standards by default. By this I primarily mean Conditional Access.

  • Thanks 3
Posted
Separately, but this is probably more a DfE thing -

 

Government should broker a deal with both Microsoft and Google to unlock some of the paid for features, which would benefit all UK schools and enforce better security standards by default. By this I primarily mean Conditional Access.

I have broached this with a few companies - the problem is how to handle schools that are already paying for A3 and A5 licenses etc - should they be entitled to a discount? Would they stop paying if Microsoft made this free?

 

I completely agree with you, but it's a difficult thing for the vendors to manage.

 

There's lots of other things that would be nice to have, such as Impossible Travel alerts to detect IPs from foreign countries.

  • Thanks 2
Posted

Mention that the video doesn't have to be watched as the certificate can be accessed without watching the video - if can be found in the description of the video and can be easily modified - certificate here: https://www.youtube.com/redirect?event=video_description&redir_token=QUFFLUhqa3RFUGdMMGhGQkpVVTV0VjhNeVZJRWRNNWVZUXxBQ3Jtc0tuYkdfRHBFakkxbGo3akk2ZDhpelVIbFk3NGF6REQ2YzVXWjBkOWpRVUI4SFdqazNxS3BZaVJuSU13akdfOUh3SW1iam40Rk0xSnN0RTlRWWFkVjk1VVpGTnJCRjFDTnlRRHluY1I1NzlKXzBIN0I1bw&q=https%3A%2F%2Fwww.ncsc.gov.uk%2Fcyber-security-schools-training-certificate&v=pP2VKWSagE0

 

Video URL:

 

Therefore schools are turning to systems that require staff to watch the video and then complete the certificate that contains Organisation Name, Date it was completed.

 

Bit of a shower of .. if you ask me considering it's mandatory.

  • Thanks 1
Posted

Haha you mouthed off on social media now you got the telling off to come ;)

 

I actually agree that upgraded google and office365 licences for all school would probably make the most difference as then each network manager would have the tools to 100% tighten up the cybersecurity whilst still making it as easy to use as it can be.

 

Training - training for IT managers/techs is really important and most schools won't fund it - i got turned down for a course as it was too expensive all about cyber securing office365 etc and they then denied the 400 quid a year for upgraded office licenses for conditional access etc - if anything ever happens I got the I told you so card printed out ready to go. reason I got it printed out is that the network will be down when I need it....

 

Training for staff - needs to be made mandatory alongside safeguarding training or you're flogging a dead horse if it's voluntary.

 

Apparently 80% of all cybersecurity incidents are through phishing so that needs to be targeted as the highest priority really. Upgraded licences help here, training for IT staff helps here. mandatory training for staff helps here.

  • Thanks 4
Posted
I have broached this with a few companies - the problem is how to handle schools that are already paying for A3 and A5 licenses etc - should they be entitled to a discount? Would they stop paying if Microsoft made this free?

 

I completely agree with you, but it's a difficult thing for the vendors to manage.

 

There's lots of other things that would be nice to have, such as Impossible Travel alerts to detect IPs from foreign countries.

 

I guess it's like anything - a change of policy and a change of procedure going forward. It doesn't necessarily need to include the whole of A3 or A5, but certainly some more crucial aspects to boost security. This would be far more beneficial rather than it being advisory or hypothetical for smaller establishments (which there are still many)!

  • Thanks 1
Posted
I guess it's like anything - a change of policy and a change of procedure going forward. It doesn't necessarily need to include the whole of A3 or A5, but certainly some more crucial aspects to boost security. This would be far more beneficial rather than it being advisory or hypothetical for smaller establishments (which there are still many)!
I totally agree, but don't think it will happen.

 

I'd love to have Microsoft Defender for O365 P2 included in the A1 licenses as that would prevent a lot of phishing emails and you could argue that Microsoft could do more to protect their uses, but they're in business to make money at the end of the day.

Posted
MFA mainly , at the moment MFA is "where possible" in a section about complex passwords, I think it should be MFA enforced everywhere and let people keep a password that doesn't expire and allow simpler passwords.
Posted
Ask them if they could collaborate with someone like the National College to create a video course that asks questions, doesn’t let you skip parts and prints a certificate at the end.
  • Thanks 1
Posted
That sounds like a crucial meeting! It's great to see you advocating for updated cybersecurity training resources. Given how rapidly the landscape changes, updating the content definitely seems vital. Maybe including more real-life case studies or practical scenarios could make the training more engaging and relevant to current threats. Best of luck with your discussion!
Posted
Ask them if they could collaborate with someone like the National College to create a video course that asks questions, doesn’t let you skip parts and prints a certificate at the end.

 

This!

 

I came to say, “can they host the video somewhere and require us to complete it?”

 

If National College can do it, staff all have logins already for it so win-win!

Posted
That sounds like a crucial meeting! It's great to see you advocating for updated cybersecurity training resources. Given how rapidly the landscape changes, updating the content definitely seems vital. Maybe including more real-life case studies or practical scenarios could make the training more engaging and relevant to current threats. Best of luck with your discussion!

 

Sick response man. Everything moves so fast I'm dizzy. Totally dope to have you onboard.

 

I'm glad you mentioned luck. I'll be sure to take my four leafed clover with me!

Posted

I think it's a bit of a sad joke that MS and Google will offer free licenses to schools yet won't offer the licenses good enough to actually safeguard children's data properly. Shows they aren't really actually doing it out of the kindness of their heart after all. They are of course after money and we should never forget that.

Anyway my head is swirling with cybersecurity policies after reading page after page of corporate-speak after filling in the Welsh 360 forms showing how well we are complying with online safety, a lot of it basically repeating the same thing over and over but slightly differently. Like others said I wish they could have some more real life examples and actual help than corporate policy speak saying "thou must" but not actually telling you how to accomplish such things.

Posted
@Zoom7000 - How did the meeting go?

 

It was a good meeting, but how productive it was, I'm not too sure. The representative was nice and welcoming, but I guess the meeting happened at the worst possible time, being the day before the general election and the inevitable change of the government. There's also some insane levels of bureaucracy which is probably not surprising.

 

We've agreed to stay in touch and meet again at a later date once things have settled down at the DfE.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...