Limbrick Consultancy LLP


Sign In

or
Don't have an account? 

A Simple Guide to Cyber Security

Cyber security
It is difficult to know where to start with addressing cyber security issues
An image of a padlock sitting on a laptop keyboard to signify cyber security
Share:
X

We all know what a crowbar looks like, we know which windows in our school are most likely to get a brick put through them and we know the strengths and weaknesses of CCTV. Physically securing our schools is not new territory and the technology used by those trying to get in has not really changed in quite some time.

Cyber security is not quite so easy. To begin with the number of people with potential access is not limited to those within walking / driving distance – but potentially anyone with internet access (so around 4.66 billion people).

Then you have the speed at which technology changes – the design and technique of using a crow bar have largely unchanged since William Shakespeare wrote Romeo and Juliet (Act 5 Scene 2: “Get me an iron crow”). I cannot imagine any of the software and devices we are using today will be around at the end of the decade, let alone into the next century.

But the real challenge is the complete lack of ability to see an attack coming or to understand which digital door maybe kicked in. It may even be that you are attacked and never find out.

Of all the discussion within the online community of the ANME – this is the biggest challenge and frustration. We know the attacks are happening because we see the headlines, but we never get to find out where the vulnerabilities were.

The knee jerk reaction from School and MAT leaders is to ask for a security audit, often out of frustration of now knowing what else to do. A security audit is possibly a good idea, but it is only every a snapshot and not a strategy for ensuring ongoing protection.

Much like the introduction of GDPR, it is about putting ongoing processes in place and potentially a systemic change of culture.

So this is my checklist of things that SBM’s and Technical Teams need to work together to put in place – all of which should eb part of an ongoing review:

Patch / Release Management
Hardware and software manufacturers release updates for their products all the time. The vast majority of these are security updates. Make sure you have a robust process for installing the latest releases on anything connected to your system including all laptops, desktops, switches, routers, projectors, CCTV, door entry etc. Patch management is generally a small update – often released several times a year. Release management is a more significant upgrade done every few years and may have a license or cost implication.

You would always replace an old and rusty padlock, so update your old and rusty software too.

Configuration Management
Make sure that your devices and software are not still using the factory settings and that any changes made to the configuration are documented and reviewed.

You would not leave a combination padlock set on “0000” – don’t so the same thing with your systems.

Service Continuity Management
With the number of attacks that have happened in schools over the last year it is no longer safe to assume you will never be a victim and make sure you are prepared for when an attack happens.

I have done a number of exercises with MATs and individual schools to walk them through an attack so they can understand what their response needs to be at each level.

This can include how to cope without computer and telephone systems, what the decision making process will be, who the key contacts will be, how to handle press enquires etc.

The impact of a cyber-attack is directly related to your ability to respond to it – so do not underestimate the importance of preparation.

Training
Despite all the technology, the biggest threat to your organisation is the people within it. The biggest weakness is the weakest password or the member of staff who is not aware of the need to be vigilant about which links to click in an email and how to check whether you should put your password into any given website.

Training and awareness is, and will always be. the easiest and cheapest way to keep your systems safe.

Share:
X

Other Blog Posts
Planting Orchards, Not Just Picking Apples: What Apple Farmers Can Teach Us About IT Strategy
by Neil Limbrick
4 hours ago 13 views
IT Strategy
EdFITS
School Leadership
Safeguarding
Long-Term Planning
Sustainable IT
Digital Maturity
Technology Planning
Curriculum Support
Device Refresh
Access Control: From Railway Block Tokens to Cybersecurity Sessions
by Neil Limbrick
7 days ago 125 views
cybersecurity
access control
session management
IT best practice
digital security
railway history
historic lessons
heritage railways
risk management
technology leadership
Don't Get Caught by the Auto-Renewal Trap: Why Every School Needs a Contracts Register
by Neil Limbrick
13 days ago 152 views
contract management
digital governance
DfE standards
school leadership
how to
templates
risk management
school business management
EdFITS
planning
What Shopkeepers and 99p Pricing Can Teach Us About Zero Trust Security
by Neil Limbrick
14 days ago 318 views
Cyber Security
Zero Trust
Digital Confidence
School IT
Network Security
Why Do We Keep Fixing the Same IT Issues? - The Case for Problem Management in Schools
by Neil Limbrick
19 days ago 180 views
Problem Management
EdFITS
Continuous Improvement
IT Efficiency
What Does Operational Excellence Look Like in School IT?
by Neil Limbrick
27 days ago 167 views
IT Strategy
Operational Excellence
School IT
Self Audit
Cyber Essentials: The Policy Checklist Every School Needs
by Neil Limbrick
34 days ago 174 views
Cyber Security
Checklist
Cyber Essentials
When the Wi-Fi Goes Down... Then What?
by Neil Limbrick
40 days ago 131 views
Service Continuity
EdFITS
Blog
Digital Oversight for Governors: What to Ask and Why It Matters
by Neil Limbrick
47 days ago 293 views
Governance
IT Strategy
Getting to grips with leadership and governance of IT
by Neil Limbrick
51 days ago 214 views
Leadership
Governance
How to evaluate your IT provision
by Neil Limbrick
148 days ago 165 views
Strategy
The questions you should be asking when implementing an IT strategy
by Neil Limbrick
178 days ago 159 views
Strategy
Governance
Breaking down your IT Strategy
by Neil Limbrick
1 year ago 204 views
The SBM guide to IT strategy
by Neil Limbrick
2 years ago 156 views
Strategy
Leadership
Governance
Separate the wheat from the chaff
by Neil Limbrick
4 years ago 128 views
Strategy
Improving your ICT game: The benefit of CPD programmes
by Neil Limbrick
8 years ago 177 views
CPD
School Closures - The Simple Guide to Clear Communication
by Neil Limbrick
10 years ago 158 views
Communication
Strategy
A Simple Guide to Cyber Security on Limbrick Consultancy LLP