Cyber crime is on the increase and schools can be particularly vulnerable. Read how you can help protect against this threat.
We are all aware of the threat of cybercrime, yet cyber incidents are on the increase, with specialist cyber insurer CFC seeing 7 or 8 notifications each day, with over 50% of these relating to the theft of funds or ransomware.*
Whilst the majority of schools are not profit driven and may therefore have a lower exposure in that regard, damage to systems can be costly, not to mention the risks to private and confidential information being accessed. Schools can be particularly vulnerable as they have a limited IT budget and often have old legacy systems in place.
Ensure your staff receive regular training in relation to the threats of cybercrime and understand the risks involved. Regularly implement password resets and use complex passwords that are harder to crack.
Ensure that staff understand the reporting process should they become aware of a data breach/loss of laptop etc.
If you can adopt a system that automatically implements a two-factor authentication this will give you additional protection should a password be breached. If not, ensure that all sensitive documents are password protected and follow the protocols outlined above.
Regular back-ups of data on your school's IT systems is essential to protect your school in the event of a cyber-attack. Ensure that the back-ups are stored on a separate server to your main data store.
Having professional cyber crime support and insurance on hand for your school can provide you with an immediate response to guide you through an issue, supporting you through the lifecycle of the incident/claim and get you up and running as quickly as possible.
Traditional security methods fail to stop such attacks because of the clever way in which the emails are constructed, enticing users to click links in the belief that they will be unable to access applications in the future if they do not.
To reduce the risk of phishing attacks all members of staff should be trained to identify suspicious emails arriving in their inbox. Email security is essential.
Ransomware involves data being encrypted followed by demands for large cash payments to release or un-encrypt the data. Some attacks might not be as sophisticated as encryption and may be as simple as the deletion of critical files.
Staying one step ahead is extremely important.
Many will see these steps as a hindrance to their daily routine, but the potential risk to the school is far greater than the few minutes it takes to change a password or double check a suspicious email.
Staying one step ahead is extremely important to help prevent cyber attacks on your school's systems proving to be successful and causing damage.
Many will see these steps as a hindrance to their daily routine, but the potential risk to the school is far greater than the few minutes it takes to change a password or double check a suspicious email.
Schools can insure against potential losses due to cyber-attacks, but some 'cyber add-ons' to policies give very limited cyber cover and are inadequate compared to a properly structured cyber insurance policy.
We can provide cyber insurance for your school which can include:
In addition, our policies can provide risk management services including breach monitoring (searches the dark web for information specific to your school); building an incident response plan; and risk awareness training.
Consider paying for a full penetration test of your network, both inside and out. Penetration testing will look for weaknesses in your network, weaknesses in staff training and understanding of potential threats through phishing, weaknesses in poor update policies and patch roll outs.
At a minimum, conduct a cyber essentials assessment. If your IT department is reluctant to allow such a test, then you may already have security issues that need to be resolved.
Having the ability to restore business data quickly and easily to maintain business continuity and reduced downtime is critical. Regularly test data recovery and bare metal restores. How long do you realistically expect it to be to get your school back up and running?
The risk of cyber-attacks is greater than ever with the perpetrators using ever increasing levels of sophistication to trick users and gain access to services:
If you have concerns about your IT systems and lack of transparency then consider an independent IT audit to look at staffing, skills gaps, processes, backup strategy, resourcing, budgets and service delivery for both administration and teaching. Problems at this level can lead to bigger issues with the underlying IT infrastructure.
For help and advice regarding cybercrime, including purchasing our cyber insurance, please get a quote online or contact us on01438 739 626.
Jo Taylor is an respected insurance industry leader with over 15 years’ experience working with both education and the public sector. She is responsible for supporting her clients on all things insurance and risk related, and is also a mental health first aider qualified through Mental Health First Aid England.
* Source: CFC 2019 claims notifications
Date: May 27, 2020
Category: Care and Medical