School staff offered training to help shore up cyber defences

21 Apr 2021 01:52 PM

New cyber security training resource for the schools sector to improve cyber resilience.

SCHOOLS will be able to improve their defence against online attacks through new training created for teachers and staff by the UK’s leading cyber experts.

The National Cyber Security Centre (NCSC) – a part of GCHQ – has today (Wednesday) released free cyber security training for school staff, which sets out real-life incident case studies and four practical steps staff can take to protect themselves online.

The resource is the latest package of support the NCSC has offered the schools sector to improve cyber resilience, and follows an updated alert issued last month to help education establishments in the wake of a rise in ransomware attacks.

The training, available from the NCSC website, shines a light on the main threats schools face and outlines the severe impact cyber incidents can have, with one case study showing how a school lost a substantial sum in school fees after reception staff fell victim to a phishing scam.

Sarah Lyons, NCSC Deputy Director for Economy and Society Engagement, said:

“It’s absolutely vital for schools and their staff to understand their cyber risks and how to better protect themselves online.

“That’s why we’ve created an accessible, free training package offering practical steps on cyber security to help busy professionals boost their defences.

“By familiarising themselves with this resource, staff can help reduce the chances of children’s vital education being disrupted by cyber criminals.”

Schools Minister Nick Gibb said:

“It is vital that schools have robust cyber security in place, and these new resources and training will help staff to increase protection from attacks.

“This training will boost support for schools, giving teachers the tools and skills they need to identify possible risks. I would strongly encourage all schools to adopt the resources and all staff to complete the training to make sure data is protected.”

The training package is designed to be accessible by any staff member, regardless of role or technical knowledge, and is available as a scripted presentation.

The four steps for school staff are being encouraged to follow are:

  1. Defend against phishing attempts: Reduce the information available about you, check for anything that looks suspicious, don’t be embarrassed to ask for help.
  2. Use strong passwords: Choose three random words for your passwords, have a separate password for your work account, switch on two-factor authentication where possible, keep passwords secure by saving them to your browser.
  3. Secure your devices: Don’t ignore updates, only download software and apps from official app stores, put a screen lock on devices (password, PIN, etc), if necessary only use school-issued USB sticks.
  4. If in doubt, call it out: Report anything suspicious as soon as possible and do not be afraid to flag up IT security policies that make your job difficult.

Once the training has been completed staff members can download a certificate which indicates they have taken part.

The case studies based on real cyber incidents include:

The launch of the training builds on a raft of support given to schools since research commissioned by the NCSC in 2019 found 92% of UK schools would welcome more cyber security awareness training for staff.

Additional tailored guidance and advice can be found in a dedicated area on the NCSC website. Resources include questions for schools’ governing bodies to ask school leaders to help improve understanding of cyber risks, as well as cyber security practical tip cards for schools.