Cyber Security Breaches Survey 2023

The Cyber Security Breaches Survey is a research study for UK cyber resilience, aligning with the National Cyber Strategy.

The full report is here: Cyber Security Breaches Survey 2023

There is a separate annex published for education institutions, the full report is here: Cyber Security Breaches Survey 2023 Education Institutions Annex

In Summary, the percentage of organisations that have identified breaches or attacks in the last 12 months:

World Password Day - May 4th

May 4th is World Password Day - it's good to have a day to consider how secure your passwords are and where you store that information.

Intel created World Password Day - the first Thursday of May - to address the critical need for solid passwords.  The day was first celebrated in 2013, and since then it has become an important reminder to take password security seriously.   In a world where technology is increasingly integrated into our daily lives, our passwords serve

Cyber Attack: Wiltshire School

A Wiltshire secondary school has been severely affected by a targeted attack by hackers who demanded a ransom to restore access to its IT network.  The attack affected the school's local server, its website, internet access, Wi-Fi, printers and internal phone systems.

A full report can be read here: https://www.gazetteandherald.co.uk/news/23476464.hacker-demands-ransom-taking-control-wiltshire-schools/

The school's website was still down several days later.  An updat

Keeping your IT systems safe and secure

The ICO recently published an updated article aimed at small business with tips for IT security - this advice would also be applicable for schools and colleges.  

This table shows the advice from the ICO and how areas of the Data Protection Education Knowledge Bank can help and guide you in those areas. 

ICO Recommendation DPE Knowledge Bank Links  Back up your data    Info/Cyber Security Checklist

 How secure is your se

Types of Cyber Attacks: DDoS Attacks

This article explains what a DDoS attack is and how to manage if your organisation is attacked.

A DoS attack is a denial of service attack.  It occurs when users are denied access to computer services or resources, usually by overloading the service with requests.  Your server or your website will be repeatedly bombarded with requests for information or resources.  This overwhelms the system making it unusable and unavailable.

An attack becomes a 'distributed de

Types of Cyber Attacks: Phishing

This article is linked to a series of articles about different types of Cyber Attacks. They can be viewed in the Information/Cyber Security News section of the Data Protection Education website or as part of the Information & Cyber Security Best Practice Area. Each article discusses a different type of cyber attack, steps to try to minimise the risk and guidance.

Phishing is a type of cyber attack in which an attacker tries to trick the victim into giving away sensitive

Types of Cyber Attacks: The Insider Threat

This article is linked to a series of articles about different types of Cyber Attacks. They can be viewed in the Information/Cyber Security News section of the Data Protection Education website or as part of the Information & Cyber Security Best Practice Area. Each article discusses a different type of cyber attack, steps to try to minimise the risk and guidance.

The Cybersecurity and Infrastructure Security Agency (CISA) defines insider threat as the threat that an insider will

Why your data is profitable to cyber criminals

This article covers ways in which cyber criminals profit from their cyber crimes.  Often we might think our data, if it is not financial, is not interesting or profitable to hackers, so this article discusses the different types of data that are stolen and why.

Financial data is the main data type that we all think of when considering why a hacker might steal information.  Financial data can be sold to various individuals for different purposes. It is not uncommon for t

Using WhatsApp in Schools

This article is about the use of WhatsApp as a communication tool in schools and recent vulnerabilities. It discusses school staff using WhatsApp as a communication method for school business.

We are sometimes asked by staff whether it is OK for staff to be in a WhatsApp group for important school messages. Staff often wish to use it because it is an easy way to communicate and a platform that a lot of people are familiar with.  It is also free. There are issues around this:

Types of malware and how they are linked to data protection

Malware is malicious software designed to harm computer systems and is linked to data protection in several ways.

Malware can be used to steal or compromise sensitive data stored on a computer system or network. This data could include personal information, financial data, or confidential business information. In this sense, malware poses a significant threat to data protection, as it can lead to data breaches and other security incidents.

Malware can

Striking Data Breach

The headteacher of a grammar school has left her role after sending parents a list of the teachers going on strike.

The Headteacher at King Edward VI Five Ways Grammar school in Birmingham  had been headmistress for just 18 months when an email she sent to parents is alleged to have named some teachers who would be striking during the planned walkouts last month.

Windows Server 2012 & 2012 R2 Retirement

This article is a reminder that Microsoft will stop support for both Windows Server 2012 and Windows Server 2012 R2 after October 10th 2023.  Keeping software up to date on devices is best practice to help prevent cyber attacks and data breaches.

How to contact us for support, subject access requests, data breaches and FOI's

This article lists the ways that Data Protection Education can be contacted for general data protection queries, data breaches, subject access requests and freedom of information requests.

While all our customers have a dedicated consultant who can be contact directly, if there is an urgent issue we would always advise emailing This email address is being protected from spambots. You need JavaScript enabled to view it..

When you email This email address is being protected from

How a school fought back after a cyberattack

The following article talks about how a school thwarted a cyber attack, more through luck than judgement.  Our advice is for the whole organisation to be cyber aware and review how your organisation might respond when attacked.    The article gives ideas on how to begin making a cyber ready plan.

In October 2020 Kellett School was subject to a ransomware denial-of-service (DoS) attack orchestrated by a Russian criminal hacker group.  After the attack, a post m

Types of Cyber Attacks - Credential Stuffing

This article is linked to a series of articles about different types of Cyber Attacks. They can be viewed in the Information/Cyber Security News section of the Data Protection Education website or as part of the Information & Cyber Security Best Practice Area. Each article discusses a different type of cyber attack, steps to try to minimise the risk and guidance

End of Windows 8.1 Support

Given the current financial pressure on schools it is very likely there are devices in schools running out of date software.  This article looks at the most recent version of Windows that support has ended for, what that means and why upgrades are a must. 

Assigning courses to staff using to-dos

To assign courses to your staff, we should use the to-do functionality via the Course Assignment and Progress Report.

When we assign a to-do via this report, and the user completes the course, the to-do will be automatically marked as complete in the to-do list. 

The NCSC 2022 Annual Review - What does this mean for schools?

What does the NCSC 2022 Annual Review, published this week, mean for schools? It’s been a busy year for education already with school budgets hit by unplanned teacher pay rises and doubling energy bills all before the end of the first term.  It is hard to fathom or think about how the conflict between Russia and Ukraine, being fought thousands of miles away, can be another influence. 

  1. France Issues Adtech Giant $65 million Fine
  2. Are we Going too Far with Biometric Technology in Schools?
  3. October is #Cybersecurity Month
  4. You Can Still Use Facebook in Europe... For Now: News Roundup
  5. Google Urges Developers to Patch their Apps: Weekly Cyber Update
  6. What the Online Safety Bill Means for Social Media
  7. The Changes Made to the Online Safety Bill
  8. An Introduction to the Online Safety Bill
  9. Google’s Services Deemed Unsafe for Schools
  10. Scammers Pretending to be Family Members: Cyber Update
  11. What Can Happen When a Primary School Aged Child Breaks the Law
  12. Disney Signs New Automated Advertising Deal: News Roundup
  13. Subject Access Requests and Children's Data
  14. The Key to Long Term Sustainable Cyber Security
  15. The End of Public Sector ICO Fines?
  16. Latest Privacy Concerns Surrounding Tiktok
  17. Changes to Cookie Pop Ups
  18. Apps Using Loophole to Track Childrens’ Phones
  19. Lockdowns opened Child Data Privacy Concerns
  20. News Roundup: Mark Zuckerberg Sued for Failing to Protect User Data
  21. Best Interests of the Child Self Assessment
  22. Cyber Threat to Health and Education Sectors
  23. UK Schools Introducing Biometrics Without Due Care
  24. Meet the Robot that Scans Your Entire House
  25. How the Record of Processing Can Help You
  26. WhatsApp Hit by Fake Voice Message Scam
  27. How Schools are Dealing with Cyber Security Breaches
  28. 2022 Security Breach Report Published
  29. Information Security Basics: What are VPN's?
  30. March Cyber Update
  31. What does a Data Protection Officer Do?
  32. Are you ready for a Data Breach?
  33. Information Security Basics: What are Cookies?
  34. Weekly Cyber Update February 8th
  35. Privacy in the Metaverse
  36. Weekly Cyber Update: Fraud, Ransomware and Cyber Essentials
  37. Data Privacy Day
  38. Blog: Best Practice on the Retention of Child Protection Information
  39. Weekly Cyber Update
  40. Carrying out Supplier Due Diligence
  41. The Draft Online Safety Bill
  42. Email and retention periods
  43. The Education sector now at highest risk of cyber attacks
  44. How to Assess your Data Security
  45. EU’s Data Protection Advisor latest to call ban on tracking ads
  46. Lloyd v Google: A Landmark Case
  47. Schools Blocked from Using Facial Recognition Systems
  48. Facebook Deletes User Data
  49. The Government's 'Data: a New Direction'
  50. Sharing this year’s Nativity play online
  51. How Facebook Knows Where You Are Without Knowing Where You Are
  52. The Importance of Schools Staying Protected Against Ransomware
  53. Amazon Ring and Facebook fines
  54. NCSC Weekly Threat Report October 15th
  55. The ICO's New Data Sharing Code
  56. How to Handle a Data Breach
  57. Apple's New Privacy Focused Software
  58. A quick introduction to the Phishing Simulation tool
  59. The Flow of Data Post Brexit
  60. The Children's Code
  61. Recording vaccination of staff
  62. B&H FoI: Racist/religious incidents/bullying
  63. B&H FOI Request: ‘Racial Literacy Training 101’
  64. Cyber Attacks
  65. Brexit update - Adequacy
  66. Protocol for Setting Up and Delivery of Online Teaching and Learning
  67. COVID-19 National Testing Programme: Schools & Colleges handbook
  68. Brexit update
  69. Class Dojo International Data Sharing
  70. Model Publication Scheme: Amendments, Improvements and Updates
  71. Child friendly privacy notices
  72. Transparency
  73. Brexit...what we know so far.
  74. Parents and students covertly recording conversations
  75. Do you need help getting focused?
  76. SAR? ER? FOI?
  77. Encryption backdoors by-design
  78. WisePay Data Breach
  79. Data Protection Education Ltd and GDPRiS Partnership
  80. Secure file transfer of files using Royal Mail
  81. Cyber security alert issued following rising attacks on UK academia
  82. Is it safe for children and teachers to be back to normal in schools?
  83. Quick guide to key contact information: LA and other information
  84. Quick guide to key contact information: Official DfE guidance
  85. Key elements of a successful DPIA
  86. FOI Publication Schemes
  87. Morrisons and Vicarious Liability
  88. SHARE: Avoid disinformation online
  89. Best Practice for Managing Photos and Video
  90. GDPR and Coronavirus
  91. Cybersecurity warning: Coronavirus fraud attacks
  92. How one school is coping with the day to day reality of COVID-I9
  93. Criminals seek to exploit Coronavirus fears
  94. New Drip Feeds: Recognise and Respond to Subject Access Request
  95. When to contact the Data Protection Officer?
  96. National child measurement programme 2019
  97. You thought BA was a large fine?
  98. Make sure DPE is your registered DPO with the ICO
  99. GDPR: One year on
  100. Compliance Manager released
  101. Google hit with €50,000,000 fine
  102. Headteacher fined for breach of data protection legislation
  103. January 2019 Knowledge Bank Update
  104. Passwords – simplifying the approach
  105. Emails – good practice and minimising the risk of a data breach

Search

Keep in the Know!

Get our latest news directly to your inbox

Privacy notice