JazzFlute Posted January 7 Posted January 7 (edited) Can see a lot of schools affected this year as its an upward trend. Not sure what happened but I know a lot of schools find it hard or have the budget to give extra money to IT Support to help them to try and stop this becoming regular as with the new DFE regs, Cyber essentials etc. a lot of money is needed to comply to help combat attacks. As a lot of schools front end users don't see the benefit of updated switches, Internet redundancy, Cloud Back Up etc. and all that is needed behind the scenes to keep a school running and secure. I can see it will be hard for all schools to cover themselves when front line staff and teaching/learning etc. Isn't "seen" to benefit from the expenditure needed. https://www.coventrytelegraph.net/news/local-news/nuneaton-school-closed-until-at-33176735 Edited January 7 by JazzFlute spelling
gszech Posted January 7 Posted January 7 Direct updates: https://www.highamlaneschool.co.uk/news/?pid=3&nid=1&storyid=344
AlphamaleZed Posted February 2 Posted February 2 Does anyone have any updates o rumours on this? Currently reviewing our cyber security stuff and this came to mind. Interesting to see that there phone lines were out of action which looks like there using something on prem but surely the phone company would have a backup of it?
JazzFlute Posted February 2 Author Posted February 2 2 hours ago, AlphamaleZed said: Does anyone have any updates o rumours on this? Currently reviewing our cyber security stuff and this came to mind. Interesting to see that there phone lines were out of action which looks like there using something on prem but surely the phone company would have a backup of it? I think that when incidents like this occur, there should be national internal communications sent to all schools so they can act on any recommendations that come out of the investigation. Obviously, this shouldn’t be shared through the press, as doing so could expose weaknesses that other attackers might exploit. But I would expect that, at the very least, the DfE could distribute internal guidance, especially considering how much they already require schools to comply with various regulations. It also looks like not everything is fully operational yet: https://www.highamlaneschool.co.uk/_site/data/files/users/school communications/letters-2025-26/1BF76121BE5A98E097C7C1921D45EDB8.pdf
xicor Posted February 5 Posted February 5 is there any updates on this ? I tried calling them to ask about this but I couldn't get through to them. I agree that whenever things like that happen there should be some communication to help other schools avoid the same issue.
Popular Post pete Posted February 5 Popular Post Posted February 5 ^ Right, let's nip this in the bud. It is fantastically unhelpful for a school dealing with a cyber incident to also have to deal with phone calls from Internet randos who are curious about it. Had they answered, they wouldn't have told you anything beyond what's already been made available. Comms on the subject will be controlled and routed via the HT and governance. Staff will have been explicitly instructed not to discuss it with third parties, especially if they're not certain they've spotted and resolved every problem. That's normal. It's basic incident management: https://www.ncsc.gov.uk/guidance/effective-communications-in-a-cyber-incident Managing external factors Manage speculative media coverage with care, such as inaccurate reporting about the impact or suggestions that personal data has been compromised when it hasn’t. By managing communications proactively, you can control the narrative around the incident. Highlight your response efforts, the steps you are taking to prevent future incidents, and your commitment to safeguarding stakeholder interests. Avoid compromising the integrity of future investigations by regulatory bodies or law enforcement agencies. You can still provide updates that are factual and consistent with the progress of the investigation, without revealing sensitive details. You should also avoid speculation or premature conclusions about the cause or extent of the incident, or who is behind it. While some groups require more detailed information about the incident than others, you should be aware of the risk that this information could be leaked to the media. 15
DrCheese Posted February 5 Posted February 5 Ouch. Yes, don't be calling them, what on earth did you think they'd tell you? You could be a nosey parent, a journalist looking for a story, or even the attacker for all they know so you're not going to get anything other than the existing public lines. If they want to release information, they will do so in their own time & via the proper channels. 2
Davit2005 Posted February 6 Posted February 6 (edited) On 02/02/2026 at 12:34, AlphamaleZed said: Does anyone have any updates o rumours on this? Currently reviewing our cyber security stuff and this came to mind. Interesting to see that there phone lines were out of action which looks like there using something on prem but surely the phone company would have a backup of it? Not uncommon to block all access in and out during a cyber incident. Edited February 6 by Davit2005 1
xicor Posted February 6 Posted February 6 (edited) Hold your horses people, nothing wrong with trying. recpetion can just say no its no big deal what's the harm ? I've done it before with other schools and had some responses. If i had a cyber incident myself and someone called me from another school to ask for advise I would be happy to help! Edited February 6 by xicor
jmak Posted February 6 Posted February 6 I've quickly checked the horses, they're fully saddled up and heading for you. It's really bad form to interrupt when someone's in the middle of a crisis. There's lots wrong with trying - you're saying you believe talking to you is more important than getting their own school running again. 2
xicor Posted February 6 Posted February 6 (edited) 7 minutes ago, jmak said: I've quickly checked the horses, they're fully saddled up and heading for you. It's really bad form to interrupt when someone's in the middle of a crisis. There's lots wrong with trying - you're saying you believe talking to you is more important than getting their own school running again. I called their reception and asked if there was an update the conversation lasted 20 seconds, no harm done and nobody's time was wasted. and their update was some time ago so its not like I called them when they just announced an incident... Edited February 6 by xicor
FN-GM Posted February 7 Posted February 7 (edited) On 07/01/2026 at 22:51, JazzFlute said: a lot of money is needed to comply to help combat attacks. There is a lot of free stuff that can be done but isn't. For example, how many people on here have used CIS hardening on their environment? Very few, a quick search only shows 9 posts. This one is more common, but Ping Castle should be ran weekly. How many people have introduced Active Directory tiering? Edited February 7 by FN-GM 1
mavhc Posted February 8 Posted February 8 Well, we've finally found out how to get SLT to thank the IT team
Davit2005 Posted February 9 Posted February 9 Even dealing with staff constantly asking you if it is OK to log into their computer the minute you arrive on site and have not even began to investigate or aware you have a problem is infuriating enough, lol. When ever we have been involved in an incident the strict line is no outside discussion unless goes thru official channel. 3
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now