Jump to content

Recommended Posts

Posted

With KCSIE 2026 mandating that schools should  conduct a review of their Filtering and Monitoring systems effectiveness at least once every academic year does anyone have a an idea on how this should be done? Is using https://testfiltering.com/ enough to show the system is up to scratch?

Posted

I'd be inclined to have a couple of testfiltering results from around the school (pref by people who arent IT) recorded each month, and then a yearly "consider your policies, and what needs improving" - a minuted meeting with relevant stakeholders would go a long way to documenting that.

  • Thanks 1
Posted
1 hour ago, fiza said:

With KCSIE 2026 mandating that schools should  conduct a review of their Filtering and Monitoring systems effectiveness at least once every academic year does anyone have a an idea on how this should be done? Is using https://testfiltering.com/ enough to show the system is up to scratch?

 

Personally, I don't think that showing that some specific url subdomains are blocked does anything but lull a false sense of security. That is all the test tool does.  

 

At least one school ISP blocks the urls anyway, so you will always pass regardless of whether you filtering is actually up to scratch or not anyway.

 

EG if testfiltering.pornhub.com is blocked, The tool will tell you you have porn filtering in place regardless of whether you actually do, or not.

 

https://testfiltering.com/faq/  See "Information for filter providers"

 

The best you can hope for by running the tool is to show whether your filtering is likely switched on or not. 

 

I note it has been upgraded a little since I last looked at it.

Posted

Testfiltering is pretty useful, moreso when it is run from devices and accounts which don't belong to IT.

You would be surprised how many safeguarding issues exist because filtering is missing or misconfigured.

 

Additionally testfiltering now demonstrates wether you've got https decryption (or something equivalent). Again. there are more schools than you'd like to think running filters with no visibility into (eg) google search terms.

 

Having evidence of some regular and frequent testing will certainly demonstrate a broader commitment to considering your filtering rather than set-and-forget.

  • Like 1
  • Thanks 1
Posted

I was asked to do this the other year with our DSL and just did some random tests with expectations but you would have thought now that the DSL gets Smoothwall alerts, Impero alerts and Smoothwall Monitor alerts, they would have all the tests with what the outcomes are without the need for IT Support to get involved 

Posted (edited)

I won't get too involved as it makes me sorta angry, yearly checks feel like a tick box for gov to say 'well we did ask' and schools to absolve themselves. 

 

Checks should be done often. The Internet isn't sitting still. People make mistakes, human error causes open holes.

 

My boiler is serviced yearly, my car MOT is yearly, my teeth are checked 6 monthly... Kids safety is more important than all of those, but check their safety net once a year, good job /s

 

Honestly if I was in schools rather than ISP side, machine in every vlan and capable of being on every individual policy, constantly checking known endpoints, alert for any anomalies, weekly audit of filtering changes, termly firewall checks. Costs a little setup but you have the answers whenever you are questioned. With DSLs supposed to be taking control of whats allowed, but maybe tech level not so high, the risk of changes going squiffy is high. 

 

I know some schools check often, I know some haven't made a single change in 3 years and just expect it to keep working. Im genuinely scared at some points.

 

I'll now retire to my hole and rest!

(Obviously its my personal view, not the company view...)

 

Edited by PaddyNewman
  • Like 1
Posted
3 hours ago, tom_newton said:

Testfiltering is pretty useful, moreso when it is run from devices and accounts which don't belong to IT.

You would be surprised how many safeguarding issues exist because filtering is missing or misconfigured.

 

Additionally testfiltering now demonstrates wether you've got https decryption (or something equivalent). Again. there are more schools than you'd like to think running filters with no visibility into (eg) google search terms.

 

Having evidence of some regular and frequent testing will certainly demonstrate a broader commitment to considering your filtering rather than set-and-forget.

 

I confess I'm actually "shocked", if after all this time, there are schools are not running decryption (or something equivalent), and frankly, knowing (unfortunately), what is hosted on some domains probably considered essential that cannot be identified without decryption, I'm chilled to the core.

 

Although knowing what is being searched for including deliberate typos, random space, slang and other techniques is a safeguarding issue, the priority is surely regularly taking a deep dive into "what was and can be found", but shouldn’t be, and nearly as important, "what's blocked and shouldn't be". 

  • Like 1
Posted
2 hours ago, timbo343 said:

I was asked to do this the other year with our DSL and just did some random tests with expectations but you would have thought now that the DSL gets Smoothwall alerts, Impero alerts and Smoothwall Monitor alerts, they would have all the tests with what the outcomes are without the need for IT Support to get involved 

 

Whilst I completely agree, my DSL doesn't have the technical wherewithall to do this, moreso when they are teaching, in meetings with agencies etc

Posted

So how is everyone testing their filtering/monitoring is compliant with KCSIE 2026? Other than using testfiltering.com I cant see us typing in a selection of inappropriate sites to see if they get blocked or not.  If this is the way to do it then how do you select which websites to use?

Posted

We use testfiltering.com and http://test.mysmoothwall.net/ in addition to loading known blocked websites as agreed with the DSL on a termly basis - from a range of accounts on a range of devices. For example, we heavily use 888.com or other known blocked websites - we also then cross check on the live logs as well to provide evidence certain categories are being blocked correctly for websites we wouldn't want to load.

 

For monitoring, we use the smoothwall test phrase to generate a Level 5 alert, again on a range of devices and different user accounts and save the evidence from the monitor portal.

Posted

Theres a degree to which "testing the filter is active and roughly appropriately configured" and "testing that monitor is configured and active" are different jobs to "test the technology and prove it catches stuff" - the latter is more a job for UKSIC to make sure the accredited solutions are up to snuff. Being compliant is a combination of picking the right tools, installing them in the right wat, and wrapping that in a layer of policy and process that works for your school.

Posted

There's an LGfL checklist which we based our checking regime on - https://viewonline.lgfl.net/hubfs/SafeguardED/Online Safety Audit And Filtering Checks Template/Filtering Checks Template-LGfL-September-2025.docx

 

We do a list of tests, against six different varieties of access we offer, once a term. It does feel like a bit of a box ticking exercise, but it does also occasionally bring up config errors that we were unaware of and loopholes that need closing.

 

 

This generates a spreadsheet for each academic year, in case anyone ever asks.

 

Of course, the real answer is, we are always vigilant and constantly reviewing our filtering and monitoring systems, right guys? RIGHT!?! ;)

 

  • Like 2
Posted

We also discuss issues and events related to filtering and monitoring that occurred during the year since the last review as part of this year's review.

 

We found some proper fails this year. Ignoring other details, one was a member of staff letting some pupils user their staff account as the pupils were blocked from a couple of sites they wanted to play on.  This sort of thing doesn't just fall out of standard reports/alerts, though was discovered through analysing log data so that somebody could visit the room. 

 

We find Manga and Anime continue to be challenging to filter without over-blocking.

  • Like 1
Posted

Typically I'll get a request from the DSL to sit with him in the HT office with two devices, one with staff access and another with student access. Then we can try and break the filter.

 

Gotta say it never stops being awkward when you manage to get through the filter via some obscure search engine and getting a face full of porn, with the DSL beside me and HT behind me.

  • Like 1
Posted

testfiltering is the Bechdel Test of filtering, an impossibly minimal standard that somehow many don't even reach.

 

Pay $20 a month for an AI subscription and leave it trying to find bad sites automatically every day, give it all of a domain/pupil/staff/guest VM/login so it can test multiple places

  • Like 1
Posted

Some good info here, quite like the checklist from LGFL, cheers @DavR, a very good starting point.

We should all be doing the basic checks anyway - I would expect DSL's to have been doing this for some time but knowing what goes on in schools, it doesn't surprise me to hear that it doesn't happen.

Ours is fairly "ad-hoc" but we do have weekly checks just based on testfiltering.com as well as manual checks to ensure authentication is correct and the right policies are applied, but this is followed up by a termly meeting with our DSL to review it all. The DSL is ultimately responsible of course and should have oversight of everything that is blocked, unblocked and all changes so this is a good forum to go through these on a common sense approach. (i.e. if a site needs unblocking immediately which is incorrectly categorised, we'll do it, otherwise those requests need to go to the DSL rather than IT). Again, all of that is logged and discussed. Not only does that seem to make sense from a safeguarding perspective, it would also help in the future should we decide to move to a different filtering system and then have a good baseline to work from.

  • Like 1
  • 2 weeks later...
Posted

Afternoon all, I'm currently working with a developer on a new product designed for education called Filter Sentinel. It stress-tests your school's filtering against the risk mandated by KCSIE 2026 safely simulating real-world vectors and goes above the tool mentioned above by running against recommended education baselines rather than just illegal content.

I did a short presentation at the ANME a little while ago, but it's about ready for a closed beta launch, so if you fancy being included please complete the form:

Filter Sentinel - Closed Beta Application – Fill in form

It asks a few questions about your security stack, etc, as it's important that IT teams also understand how this can affect filtering results and is important to ensure various levels of protection are working as expected.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...