Jump to content

Recommended Posts

Posted

Hi All,

 

We have been asked to look into what we would need to be able to achieve the Cyber Essentials and Cyber Essentials + certifications.

A key aspect appears to be that BYOD devices are in scope. We were not initially concerned by this as we don't currently allow staff or students to bring devices in.

However, the definition that CE use is "devices not owned by the organisation which are used to access organisational data and services, A personally-owned device used to access company emails would be an example of BYOD".

 

This is a game changer. We currently allow staff to pop their email accounts onto their phones which appears to be in scope. 

We offer a Virtual Desktop solution to staff and students, which I understand means the devices they use to access the virtual desktop service on, are in scope.

This would also include any device staff use to access M365.

 

I appreciate that the CE accreditation is not specifically designed for Education, and that in a corporate world, users are probably given laptops in order to do their work.

I find it interesting that the scope does not include students devices, which would clearly be as much of if not potentially more of a risk to security than staff devices.

 

For those of you who have considered CE or who have achieved compliance, any advice on what you needed to do, or advice in general would be most appreciated.

 

Posted

You could look to see if Webmail counts and could change to that.  I know that Intune offers the option to manage data in certain apps and keep the device compliant i.e. it offer a mode for BYOD.  I also believe the Exchange remote wipe works as well.

  • Like 1
Posted (edited)

What is the issue with having BYOD in scope? You would have to put in place measures to limit BYOD access or improve BYOD security. Why would this be a bad thing?

So, you need to make the choice; either you do not want to entertain BYOD as you do not want to deal with the headache, so you act accordingly OR you do want to allow BYOD and you act accordingly to ensure you are secure.

 

Seems the opposite of the Cyber essentials ethos, to want to do something but get round having to introduce security for it.


EDIT: For example JISC has a blog post about this very thing that can be setup using Intune.

Edited by TechMonkey
Posted

We are happy to do what is needed to ensure everything is compliant. Just reaching out to see who has gone through this, and what they have put in place. 

Posted

We put in Ruckus Cloudpath to take care of all BYOD issues for staff and sixth formers (lower age children not allowed to bring devices to school).  That worked well.

 

The big showstopper for us going with Cyber Essentials Plus was the requirement for MFA for all children, including the primary school pupils using school tablets.  It just wasn't worth it, the support overhead would be monstrous.

 

So I advised my school seniors that we would have to pull out of CE+.

  • Like 1
Posted

If you don't control the security standards of the devices that access your school's data, then you can't protect it. The scope for Cyber Essentials makes sense - but it does pose challenges. 

It sounds like you use Microsoft products - if you haven't come across Conditional Access Policies, take a look. There are quite a few threads on here about it. 

 

If staff *need* email on their phones, then the school should provide phones. Similarly if they need laptops to do their work, the school should provide them. If staff are being offered the convenience/privilege of working from home or using their own device, setting standards and controlling what data can be accessed is entirely reasonable - and entirely non-negotiable. 

 

And while I don't sound sympathetic, I really am - it's still a battle I'm having where I work, which isn't a school. I just hope I win before we have a catastrophic attack. 

 

Cyber Essentials is an appropriate name - in my view what they ask for is a bare minimum.

  • Like 3
Posted

I know all about Conditional Access Policies. 

 

Our problem was trying to provide a foolproof MFA system for 7-11 year olds. Not easy without an awful lot of errors, lost security fobs and support issues.

Posted (edited)
15 hours ago, MartinT said:

I know all about Conditional Access Policies. 

 

Our problem was trying to provide a foolproof MFA system for 7-11 year olds. Not easy without an awful lot of errors, lost security fobs and support issues.

Sorry - it was a reply to the thread, not aimed at you and the part about conditional access was supposed to refer to BYOD specifically. I get the issues with MFA in schools. 

I do get irritated when organisations say they can't afford to give people laptops/phones etc. If users are allowed to choose to use their own device, they need to obey the roles and technical controls need to be in place. Otherwise the employer must provide the equipment for the employees to do their job. That might mean a shared PC in an office in school. If they're expected to work at home or be contactable by phone, then the employer must provide the equipment.

Edited by jmak
  • Like 1
Posted (edited)
On 31/07/2025 at 22:23, jmak said:

And while I don't sound sympathetic, I really am - it's still a battle I'm having where I work, which isn't a school. I just hope I win before we have a catastrophic attack. 

 

Cyber Essentials is an appropriate name - in my view what they ask for is a bare minimum.

 

I hope you manage to get there!  The reprocussions if not can be severe. One of my neighbours is IT in a Fortune 500 - they literally had to shut down worldwide IT for at least a month due to cyber attack. I think the total cost is now into 9 figures and still going up every day.

 

Because schools get their per pupil income money no matter what - it's very hard to get them secure as there is no carrot "we will go bankrupt" to dangle in front of the donkey, the money will keep coming in the school will stay open, etc.

Edited by PotNoodleTech
Posted
On 31/07/2025 at 22:50, MartinT said:

I know all about Conditional Access Policies. 

 

Our problem was trying to provide a foolproof MFA system for 7-11 year olds. Not easy without an awful lot of errors, lost security fobs and support issues.

Passkeys, store them locally on their assigned school laptop

Posted
17 minutes ago, mavhc said:

Passkeys, store them locally on their assigned school laptop

Yes, that's a possibility as they have school -provided iPads.

 

Still, it's not my problem any more.

Posted

For me it roughly goes like this:

 

*Start of conversation*

"Our security posture is poor. We need to deploy 2FA to the children"

"No, that would be overly complex, expensive and would be a barrier to learning"

"Then we need to scrap BYOD and provide devices that can be secured using conditional access policies and hello for business"

 "No, that would be overly complex, expensive and would be a barrier to learning"

"Then you have to expect a catastrophic cyber attack to be successful as our defences are not up to standard"

"Oh no! You MUST improve our cybersecurity posture!"

*return to start of conversation*

 

Obviously it's more complex than that, but I expect the only thing that would break the cycle is the aforementioned catastrophic cyber attack. At which point I probably be referring them back to my warnings as I walked out the door.

  • Like 3
Posted
5 hours ago, midweek said:

For me it roughly goes like this:

 

*Start of conversation*

"Our security posture is poor. We need to deploy 2FA to the children"

"No, that would be overly complex, expensive and would be a barrier to learning"

"Then we need to scrap BYOD and provide devices that can be secured using conditional access policies and hello for business"

 "No, that would be overly complex, expensive and would be a barrier to learning"

"Then you have to expect a catastrophic cyber attack to be successful as our defences are not up to standard"

"Oh no! You MUST improve our cybersecurity posture!"

*return to start of conversation*

 

Obviously it's more complex than that, but I expect the only thing that would break the cycle is the aforementioned catastrophic cyber attack. At which point I probably be referring them back to my warnings as I walked out the door.

I've had this conversation so many times! Totally get why education org's/enterprises chose to adopt BYOD - to REMOVE barriers to learning - but I can't help but feel that from an org/enterprise perspective the balance has tipped to where BYOD now lacks both security features AND important enterprise deployment functionality. In many cases, there ends up being almost no link btw. IT and Teaching/Learning, not even managed bookmarks, even at the top end simple wins are ignored and students/users are presumed capable of organising themselves... in my experience, you need only sit with almost any student/user to realise this is a very problematic assumption

  • Like 1
Posted

I have taken a 45 school Trust through Cyber essentials successfully.

 

The NCSC have some good MFA guidance, including the point that we should only prompt for authentication or MFA when it makes a difference

 

For MFA internally we successfully argued that the device itself was the token, as long as we prompted for MFA at least once - I referenced this blog as well:

 

https://www.ncsc.gov.uk/blog-post/not-all-types-mfa-created-equal

 

For BYOD we successfully argued that MAM without enrollment met the criteria - we protect the data but do not allow the device to be registered with our systems.

  • Like 3
Posted
On 31/07/2025 at 08:52, Razzy said:

 

I appreciate that the CE accreditation is not specifically designed for Education, and that in a corporate world, users are probably given laptops in order to do their work.

Hello from the corporate world.

We do provide laptops for our staff but that’s more to do with our hot-desking in the office & work wherever you like policy.

 

With regards to email on phones, we provide corporate phones globally for anyone who needs one and these are obviously managed devices.
 

If you don’t qualify for a company phone, or you don’t want to carry two phones, then you can use your personal device if you wish but we require you to install our “light touch” Intune ‘byod’ policy.

  • Like 1
  • Thanks 1
Posted
12 hours ago, Mr.Ben said:

I have taken a 45 school Trust through Cyber essentials successfully.

 

The NCSC have some good MFA guidance, including the point that we should only prompt for authentication or MFA when it makes a difference

 

For MFA internally we successfully argued that the device itself was the token, as long as we prompted for MFA at least once - I referenced this blog as well:

 

https://www.ncsc.gov.uk/blog-post/not-all-types-mfa-created-equal

 

For BYOD we successfully argued that MAM without enrollment met the criteria - we protect the data but do not allow the device to be registered with our systems.

Very impressive!!

  • Like 1
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...