Showing posts with label ICT in education. Show all posts
Showing posts with label ICT in education. Show all posts

Tuesday, 10 October 2017

GDPR - top tips to get compliant

It’s that time of year again, the summer break is over and it is back into the routine for another academic year. Any bursar will tell you that September is an extremely busy time of the year with a seemingly endless list of things requiring attention. In the hubbub of the new academic year, it is easy for tasks to be put on hold, which is why I am taking an opportunity in this edition of ‘educateIT’ to gently remind headteachers and bursars of a deadline that is now two months closer – the GDPR regulation.

I’ve spoken so much with bursars about GDPR recently that I am starting to feel like a broken record, but the reality is that it is so important that it will be on the agenda right through until the 25th May 2018 deadline and beyond.

After a well-deserved 2-month break, you may be racking your brains to remember exactly what GDPR entails. The General Data Protection Regulation (GDPR) is a piece of EU legislation designed to provide a common data protection policy amongst EU member states. When it comes into effect next May, it will supersede all existing data protection regulations (in the case of the UK, that is the Data Protection Act 1998). Because current data protection legislation differs across member states and was introduced before the cloud and social media, it was clear that modern legislation was required.

No doubt that if you have heard about GDPR, you will have heard the scare stories about fines of up to €20 million for non-compliance. As an independent school, it is unlikely that you could ever face such an astronomical fine for non-compliance, these fines are reserved for the worst offenders. However, it is a safe assumption that under GDPR fines for non-compliance will move up the value chain. For more on GDPR, read my blog from March 2017 entitled “GDPR – What’s it all about and how does it affect Independent Schools?”

During my visits to Independent Schools at the tail end of last term, I was frequently asked when would be a good time to start tackling the issue of GDPR compliance. At that time, I urged schools to begin work as soon as possible – since compliance is not something that can be attained overnight. In the new academic year, with the deadline less than 9 months away, my message is that if your Independent School hasn’t begun the process of GDPR compliance, it should be as near to the top of your agenda as possible.

With that in mind, what are some key considerations an Independent School should make as it progresses towards GDPR compliance?

Firstly, it is a good idea to get acquainted with the Information Commissioners Office. This is the Data Protection Regulator in the UK. Under GDPR, an organisation that experiences a data breach of any kind is obligated to inform the ICO of the breach, exactly what was exposed and what measures are being taken to mitigate damage, within 72 hours of discovery. Failure to do so is an offence and will result in a fine. Furthermore, GDPR requires certain businesses to appoint a dedicated ‘Data Protection Officer’ who is an expert on GDPR. The details are a little cloudy on this at present, but it is quite possible that schools will fall into this category.

The next consideration involves processing of personal data and consent. GDPR gives individuals more control over the use of their personal data. At a recent visit to an Independent School, this topic came up when the bursar mentioned that they perform wealth screening on prospective parents. Whilst this is a savvy business practice, under GDPR withholding personal information for the purposes of wealth screening can only be legally performed with the explicit consent of the individuals in question. Furthermore, the school must keep a record of exactly when consent was given and must make it clear to the individual the basis for which the school requires this information. The individual may also withdraw consent at any time, at which point withholding personal information becomes illegal.

In certain instances, passive consent is allowed. For example, when a pupil enrols at a school, it is implied that the individual gives consent for personal information to be stored by the school for the purpose of providing them with an education and pastoral care.

Once you have collected that data, the question of where that data is stored arises. Whilst many Independent Schools still store all their important data in servers on-site, cloud adoption is accelerating. Popular cloud services such as OneDrive or Dropbox are provided by U.S. based companies and are powered, for the most part, by U.S. based datacentres. U.S. data protection law is not as stringent as EU legislation and reliance on U.S. based storage could lead to compliance issues.
That doesn’t mean that storing data on-site is a preferred option. In almost all cases I have dealt with in my long career in the IT industry, on-site storage options are less secure than their cloud counterparts. The only exception is for organisations that make their cyber-security a top priority, throwing vast amounts of cash at servers, monitoring software and antivirus. A cloud storage option such as ShareFile is a strong offering if security is mission critical.

A final important consideration is that of Social Media and pupil internet usage. This links back to my earlier paragraph on consent. Because most school pupils are under 16, they can never legally give consent online. An Independent School, particularly one that has boarding pupils, acts as a legal guardian for those pupils while they are on school grounds. The school is therefore legally responsible for the information they share online, and the websites and social media accounts they sign up for while on school grounds. Having a stringent acceptable use policy in place for pupils’ internet use is a good first step, but educating the pupils on the dangers of posting personal information online would go a positive step further.

As the GDPR deadline looms, I cannot stress enough the importance of taking action now. In the business sector, GDPR is getting increasing air time and most parents will be aware of the regulation by now. To show that your Independent School is on top of the changes, I recommend a letter to inform parents that your staff are aware of the changes, and that your school is making the necessary steps to reach GDPR compliance by the May 2018 deadline. Proactively reassuring parents that the personal information of themselves and their children is safe will put minds at ease.

Towards the end of the last academic year, I received a number of requests for assistance with GDPR. To Independent Schools with a genuine need and interest, I met with bursars to discuss further. I am continuing to offer this service at the beginning of this academic year. If you would like advice on GDPR compliance, please do not hesitate to get in contact with me on 0330 002 0045 or email schools@entrustit.co.uk

Tuesday, 19 September 2017

Why Independent Schools must Prepare Pupils for Jobs that Haven't been Invented


Whether we like or loathe technology, there is no doubt that every facet of our lives is being changed by digital transformation.

Technology is changing businesses - we only have to see the impact of Uber on traditional taxis, Purple Bricks on traditional estate agents or Airbnb on traditional holiday accommodation, to understand that the world around us is changing because of the use of technology.

The way our young people socialise and interact with each other has also totally changed in recent years with the use of Snapchat, Instagram, Facebook and a plethora of other social media sites, not to mention the streaming of music and films/TV and the advent of e-readers and the subsequent digitisation of books - so different from my day where we went to a shop to buy a CD or borrowed a book from the library!

Technology has also made the world a much smaller place, with the cloud, virtual learning environments, and virtual meeting environments enabling remote working and real-time communication wherever we are. And - for better or worse - this "permanently connected" status of our smartphones and tablets has also meant for many of us that much of our work lives and our personal lives have become 24x7.

And the pace of change continues to increase. Already Artificial Intelligence (AI) is starting to change the world around us, dispensing with the need for some jobs, while creating the need for different, digitally savvy skills to create and manage the technology. This is a trend that can only be set to continue and extend in coming years. Meanwhile the Internet of Things (IoT) is continuing to evolve, with everything from our building management systems, to our CCTV systems being connected to the Internet. Perhaps soon the fridges in our school kitchens will be monitoring their own stock levels and automatically re-ordering items that are running short.

Embracing technology, and equipping pupils with the skills to thrive in the new digital economy, forms a vital part of preparing pupils for life beyond school. Already there are so many jobs that just didn't exist 10 years ago, and there is no doubt that some of our pupils today will be undertaking jobs in the future that haven't even yet been invented.

This is why it is so vital for schools to embrace technology and build it into every element of school life. Of course, embedding technology into school life does rightly raise concerns amongst the Senior Leadership Team as to how to safeguard pupils in this environment, as well as preventing all the distractions that come with things like social media. However with the right controls, processes and technologies in place, this is very much achievable, as has been shown by many independent schools, such as Stroud School, whom I featured in a recent piece on my blog

If you would like to know more about EntrustIT's ICT strategy and project services, which enable schools to embrace digital technology and embed it into school life, please do not hesitate to contact me on 0330-002-0045 or email schools@entrustIT.co.uk

Monday, 8 May 2017

Preparing for GDPR – Understanding and Securing your School’s Data


Following on from my recent blog, “GDPR – What’s it all about and how does it affect Independent Schools” I’ve had requests from several schools asking for more information, so I thought it would be useful to elaborate on some of the issues that GDPR raises for Independent Schools.

I wanted to start by further exploring the importance of understanding what personal data you hold and where that confidential data is stored. Bear in mind personal data can be as simple as a pupil, teacher or parent’s name or email address.

This may sound like an odd topic, as I'm sure many of you are thinking you know exactly where all your schools’ data is held. But do you really?

The scary reality nowadays is that your school’s precious data may already be widely scattered. Yes, some of it will certainly be residing (hopefully securely) on your in-house servers. But what about the proliferation of school, staff and pupil owned portable devices such as laptops, tablets and smartphones which now hold school data or emails? Or data that has been copied to removable media such as USB sticks? Or data that has been shared with business partners and other third-parties? Or copies of data taken for backup purposes?

Then there is the cloud. The cloud has revolutionised the way many schools store their data, but in doing so has also globalised the way data is stored, with many public cloud providers distributing data across servers worldwide in order to optimise costs.

So do you really know where all your data is held? And does it matter?

Well in terms of GDPR it certainly matters, as you need to be able to demonstrate that you are protecting your data and using it appropriately. The more widespread and less controlled your data is, the more vulnerable you leave your school to a breach of data security. So understanding what you have and where it is forms the first step towards compliance.

If, on reflection, you realise that your school’s data is already widely scattered, you may wish to bring it together in one secure, central repository in order to make it easier to control and manage. Luckily nowadays there are technologies that facilitate this; for example we have built our very own EducateIT desktop platform for schools, which is an onsite private cloud solution which allows a school to bring together all their data in one secure, central, onsite repository, where they and their authorised partners can access it securely wherever they are, without the source data ever leaving the security of the school. For other schools, where data is generally central, but perhaps also resides on some mobile devices too, we work to implement processes and technologies to prevent data leakage and manage mobile devices.

Either way, it is paramount to put the school back in control of its data, knowing both where it is and who has access to it. This in turn needs to be documented, both so that the senior leadership team team have understanding of, and control over, their valuable data and also in order to provide documentation for compliance and audit purposes. This not only puts schools back in control of their data, but minimises the risk of a security breach and takes the first step towards preparing for GDPR compliance.

Once you have this understanding, the next step is to understand how you secure your data. This broadly falls into two categories – access control (effective security for authorised users) and cyber security (protection against unauthorised access).

Today I am going to talk about the former, as having good access control systems lies at the heart of successfully protecting your school’s data, and forms an important part of preparing your school’s information systems for GDPR compliance.

GDPR places accountability on schools to have in place policies, procedures and documentation that demonstrates the personal data they hold is stored securely. Bearing in mind that schools hold a vast array of personal data, much of which is about children, whom the GDPR identifies as “vulnerable individuals” deserving of “special protection”, and it becomes clear that the legislation is likely to cover the vast majority of a school’s data.

Therefore, for each of your computer systems, it is important to understand, and have documented, who has access to that system and what level of access they have. Bear in mind that it is best practice to give each user the minimum access they require to the system. Allowing wider access to systems puts you at greater risk of a data security breach or data loss through incidents such as accidental deletion, a ransomware attack or malicious insider threats. As well as having SOPs in place to handle the ICT access control requirements of new starters, it is equally important that there are procedures in place to cover leavers (both pupils and staff) and what happens when somebody changes role within the school.

Password policies are always a bone of contention and an area where a fine balance needs to be struck. Policies that are too lax lead to easily guessable passwords which may not demonstrate due care of data under GDPR. On the other hand, policies which demand highly complex, long passwords which change frequently, may lead to dozens of forgotten passwords and/or the temptation to record passwords on sticky notes, which also certainly doesn’t demonstrate due care of data!

Nowadays, it is also likely that third parties such as freelancers, suppliers and of course parents will have access to some of your ICT systems or data. In this case this needs to be secured in just the same way, so you are clear who has access to what parts of the system, why this is needed and how it is controlled. There also need to be procedures in place to review, amend and remove access for third parties, as relationships evolve and change.

Mobile and remote working present a whole additional set of challenges to ICT security, with the potential for copies of data or emails to be residing on all kinds of devices, both school owned and personally owned, which do not necessarily conform to school security standards. So developing policies around mobile working and ensuring there is not leakage of data or unauthorised access to data form a critical part of compliance. Policies and technologies also need to be implemented to protect against data breaches from mobile devices that are lost or stolen.

Finally, bear in mind that it is not just your main school-wide IT systems that fall under the GDPR. Any indexed system that contains personal data is subject to the legislation, so do make sure you are also including in your access control procedures all those little databases or spreadsheets that have been developed by an individual or department and which contain personal data.

I hope this has given you a useful insight into some of the key areas to consider around readying your school for GDPR compliance. If you need help preparing for GDPR, or indeed with any element of your ICT system, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk

Monday, 3 April 2017

Why Every Independent School needs a list of Specific Unknown Problems!


It's that time of year again, when schools are starting to plan their network upgrade projects for the summer holidays. And if only we could list every unknown problem that might occur, it would make all our lives so much easier!

Of course with technology being technology, it never seems to work quite like that. We only have to think about any high-profile public sector ICT project to know that these things are rarely brought in successfully on time and within budget, with a fanfare from the delighted user base!

And to expect our schools’ Network Managers to deliver what are now often highly complex ICT projects on their own over the school holidays can be an unrealistic expectation. We have to bear in mind that delivering ICT infrastructure projects requires a whole raft of specialist skills ranging from systems design (a specialist skill in its own right), to systems installation, people management, project management, risk management and organisational skills.

Then put this against the backdrop of a schools' operational environment: often hundreds of software applications, not always inventoried, and indeed sometimes not on the Network Manager's radar at all. Downtime windows confined to school holidays. The need to structure the project plan around certain days or rooms where the system needs to be operational, such as on exam result days or periods where certain facilities are let for summer schools. A plethora of rooms, buildings and keys. Laptops, some of which will invariably have been taken off site. The need to liaise with third parties such as software suppliers over a period when many people are away. Key users who aren't available for testing or training as they are on holiday. And the vagaries of technology, where something doesn't quite do what it says on the tin!

Then there’s the increasingly critical need to build in cyber security and data protection from the ground floor up in any new or upgraded systems, again a specialist skillset in its own right.

Added to this, we need to remember that these types of projects are not something our Network Managers do every day, and just like anything any of us are doing for the first time, it is unlikely to go as smoothly as if we had done it many times before. So perhaps it is little wonder that schools sometimes experience disruption at the start of term in September, when ICT projects have over run!

The key to success in these projects lies in the planning. Whilst none of us have a crystal ball to be able to anticipate every problem that may occur, having a breadth of experience in carrying out these type of projects means that many of the "unknown problems" that might present a challenge to in-house ICT staff, will actually be "known issues" to someone with wider experience, and can be planned for accordingly.

And let’s not lose sight of the fact that, with a helping hand to support them to succeed, these exciting projects not only enhance the schools’ learning environment, but also offer a fantastic development opportunity for schools’ Network Managers.

If your school needs an experienced organisation to work with your in-house ICT team to plan and deliver your forthcoming network development projects, please do not hesitate to contact me on 0330-002-0046 or email schools@entrustit.co.uk to discuss your requirements.

Monday, 20 March 2017

GDPR – What’s it all about and how does it affect Independent Schools?


The new EU General Data Protection Regulation (GDPR) comes in to effect in May 2018 and represents the most radical change in data protection legislation in the last 20 years. Whilst many schools, and indeed businesses, that I work with were hoping this would go away, especially in light of Brexit, it has now been confirmed that the UK will be implementing the legislation and as such, is “the elephant in the room” that schools can no longer afford to ignore. So today I thought it would be useful to share some information on what GDPR is all about and what key actions Independent Schools need to be taking to ensure compliance.

  By way of background, GDPR has been developed to reflect the changing use of data in the digital world in which we now live. With the digital economy being primarily built upon the collection and exchange of data, including large amounts of personal data, which is often sensitive, there is a need to protect EU citizens’ privacy rights. GDPR is designed to enable citizens to benefit from modern digital services, whilst providing sound, well formulated and properly enforced data protection safeguards to help mitigate risks and inspire public confidence in how their information is handled by businesses, third parties, the state and public service providers.

Whilst these aspirations are to be lauded, there is much concern amongst schools and businesses alike as to the reality of understanding and implementing the legislation within their organisation. And whilst the implementation date of 25th May 2018 may still seem a long way off, the reality of the situation is that the changes this legislation requires many organisations to make are so far reaching that they need to start work now in order to be compliant in time.

The new legislation also gives the regulator real "teeth" in terms of enforcement. For example if you do not comply with some of the fundamental provisions in the legislation, such as obtaining necessary consent, you can be fined up to 4% of your total worldwide annual turnover or €20 million, whichever is greater. Equally, penalties of up to €10 million or 2% of your total annual turnover apply for not putting in place adequate security.

In addition, breaches have to be notified to the data protection authority and in some cases the people affected, without delay. This leaves the school concerned highly exposed to reputational damage and potential pay-outs to affected parties.

The situation for schools is further complicated by the fact that the GDPR identifies children as “vulnerable individuals” deserving of “special protection”. As such, schools also need to be aware that the new rules introduce some child-specific provisions, most notably in the context of legal notices and the legal grounds for processing children’s data.

One important element of GDPR compliance is protecting your data from external security threats. Schools are becoming an increasingly popular target to cyber criminals unfortunately, as there is a perception that they are a soft target, not always equipped to spot signs of increasingly sophisticated cyber fraud. Threats like ransomware for example, which I highlighted in my recent blog, are sadly now becoming more and more common in schools. And apart from the financial and operational impact these type of threats have on the school, which can be extremely damaging as they lock pupils and staff out of the system, such malware can also be used to export information. This presents a major risk under GDPR, given the compromised data involves the details of schoolchildren, which could have serious implications if it fell into the wrong hands.

In addition to outside security threats, there are a plethora of other threats to schools’ confidential data, ranging from something as simple as a staff member’s laptop or phone containing school email or data being lost or stolen, through to unauthorized copies of data being made or inadequate starter and leaver procedures for systems access.

There is no doubt that GDPR will have a wide ranging impact on schools, affecting functions as diverse as marketing, fund raising, admissions, HR and ICT, and as such is something that will need much Senior Leadership Team time and planning in order to mitigate the risks and ensure compliance by the deadline.

So what do Independent Schools need to be doing in order to mitigate the risks?

Well this is a big question and one I will be exploring in more detail in coming blogs, but to give you a flavour, the type of things you should be considering include:

  1. Identify what personal data you are holding. Bear in mind personal data can be as simple as a pupil, teacher or parent’s name or email address. This is vital because you need to be able to demonstrate that you are protecting this data and using it appropriately. So understanding what you have and where it is forms the first step towards compliance.
  2. Identify threats to this data. This could include things like cybercrime mentioned above, but also accidental loss by staff, deliberate theft by staff or pupils, lost devices and unauthorised access to data. This is vital if schools are to avoid the fines of up to €10 million that can be levied for unauthorised access to, or disclosure of, personal information.
  3. Invest in and implement the right technologies to deal with insider and external threats to data. This will involve a wide raft of technologies to provide protection from a range of different threats. It is vital to realise that a firewall and a piece of anti-virus software are not enough.
  4. Put together a new or updated data protection policy and train staff on it. This is important as everyone in your school needs to understand their obligations under GDPR and how to make themselves fully compliant.
  5. Put in place processes for ongoing education for all members of staff around cyber security and data protection. Because the cyber security landscape is constantly changing, it is very important that all staff are constantly kept up-to-date with best practice around security and data protection.
  6. Create a breach notification plan. This is important because if the worst should happen, and you do experience a data breach under GDPR, you need to have a clear plan to deal with it and communicate it as smoothly and accurately as possible, and with the least possible damage to your school.
In future blogs I will be exploring these issues in more depth, but if in the meantime you need help with GDPR compliance, please do not hesitate to contact me on 0330-002-0046 or email schools@entrustit.co.uk

Monday, 9 January 2017

Getting Best Value from ICT Budgets in Independent Schools


With ever increasing demands for new and improved technology in independent schools, it is easy for ICT to become a bottomless money pit. Naturally, every school wants to use technology to enhance the learning environment, equip pupils for the digital world that they will be living and working in, as well as ensure that the school is keeping up with its competitors and using technology in a way that will serve to attract further pupils to the school.

The bursar however, has the unenviable job of trying to balance all these laudable ambitions against a limited budget!

This is where I often get called in to help bursars review current ICT budgets and look at strategic ways next academic year's ICT budget can be most effectively utilised. Because we work with numerous schools, and have a good handle on the technology marketplace, we are able to give bursars a steer on whether they are paying about the right amount for ICT services and staffing both commercially and in relation to other schools. We also look at whether there may be ways they can "flip" their budget to achieve their technological aspirations in a different way.

Every school is different, but with ICT forming a significant part of the school’s overall budget, it is well worth taking a little time to review how best to deliver maximum possible value from a limited pot of resources. Whilst time and space don't allow me to cover every scenario here, I thought it would be useful to jot down a few of the common areas that I find are worth reviewing:-

1. ICT Invoice review. This is often a very revealing exercise, as many schools receive a plethora of invoices from different providers each term or year, relating to services, maintenance contracts, software subscriptions and the like. The descriptions on such invoices are often vague or use technical jargon, which make it hard to know what they relate to, whether they are still actually relevant and whether they are offering good value for money. We have spent time with many schools unravelling their invoices to understand just these factors and frequently this exercise alone has yielded many thousands of pounds in ongoing cost savings.

2. Software review. Most independent schools have an array of software applications that have grown over time. Reviewing (or indeed making!) a list of all applications and asking questions such as "Who uses it?", "What for?", "Do we still need it?" and "Is there a cheaper way to licence it?" normally reveals another nice chunk of money that can be used for more exciting ICT projects.

3. Internet connectivity. With technological advances, prices for Internet connectivity are constantly falling, but many schools are not aware of this and so are oblivious of the opportunities to re-negotiate their contract, or perhaps add a back-up Internet line for the same cost they are currently paying for their main line alone.

4. ICT staffing costs. In some cases, independent schools find a better skills mix and a cost saving can be achieved by part or fully outsourcing their ICT function, or by changing provider.

5. The Cloud. Strategic use of the right public and private cloud solutions can potentially save schools a fortune in hardware and support costs, whilst also offering remote working capability and the ability to securely access the school system from pupil and staff owned devices.

6. "Closed" cloud. For those schools not yet comfortable with the idea of their data residing off-site, closed cloud solutions can offer similar benefits to private cloud solutions, as well as significant cost savings over a traditional network, whilst still keeping all data in school.

7. Leveraging your ICT systems commercially. From utilising digital technology to market your school more effectively, through to renting out your shiny new music technology suite over the holidays, remember you can use your technology to boost your bank balance too, not just deplete it!

If you would like more information on any of the topics raised or if you'd like to book a budget review, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk.

Monday, 12 December 2016

Why every Independent School needs a Super-Hero!



This cartoon recently caught my eye, and made me chuckle. I do think that nowadays we expect so much from our ICT staff that they do indeed need to have superpowers to fulfil all our expectations!

Let's consider how things have changed over recent years: a decade ago, there was a small, simple network serving the administrative side of the school, and perhaps a couple of ICT classrooms equipped with specially configured computers for delivering ICT lessons.

Nowadays, the network extends to every area of the school. Pupils and staff alike are connecting all kinds of different devices to the network through Wi-Fi, and ICT services have become the bedrock of delivering most, if not every, lesson.

Whilst network managers and IT technicians are sometimes much maligned (especially, in my experience, when the network goes down!), their role has in fact changed beyond recognition in recent years.

No longer is it sufficient to have a network that runs OK most of the time. Nowadays it needs to be an "industrial strength" network that is at the top of its game every minute of the school day.  We expect our network managers to have the network design skills to put together such a system (despite typically never having done this before!), not to mention the strategic vision to "back the right horse" by investing in the right technologies that will future-proof the school network and provide the best learning environment for children. 

Naturally, we also expect them to be technical geniuses, able to fix any problem from the most mundane password reset through to a complete reconfiguration of the network.  Then during school holidays, we also expect them to don their superhero capes and become “project managers extraordinaire”, in order to smoothly, without disruption and within budget, implement technically complex upgrade projects!

Come the start of term, it's back into the phone box for our ICT folks, to metamorphose themselves into the role of hand holder, support giver, mentor and trainer.

Of course, in today's digital world, we also expect our ICT team to be cyber security experts, abreast of a constant stream of new threats and coming up with ways to mitigate the risk and safeguard our pupils, staff and data.

So next time you write a job advertisement for a Network Manager, don't forget to include "Super Powers" in the essential skills section!

Failing that, you could perhaps consider engaging an experienced Independent Schools ICT provider to work in partnership with your Network Manager, so that he or she doesn’t need to have quite so many superpowers!

Monday, 28 November 2016

“Closed Cloud” in Independent Schools


In my last article, I talked about cloud computing in independent schools, the differences between public cloud and private cloud, and some of the concerns independent schools had about data protection in relation to public cloud solutions.

Due to these concerns, I am seeing increasing numbers of schools looking to adopt private cloud or indeed "closed cloud" solutions where all data remains in school. So today I thought it would be useful to elaborate on "closed cloud": how it works, what benefits it offers independent schools and how it compares with other types of cloud technology.

Closed cloud uses the same technologies that public and private cloud providers use, but the vital difference is that rather than being hosted at a cloud provider's data centre somewhere in the world, the whole system is physically located in school.

As with private cloud, this necessitates dedicated hardware and thus is more expensive than public cloud. However it has the benefit over both public and private cloud of providing complete assurance around data protection, since all data remains in school at all times. There is also much less reliance on a third party, as although a provider will typically be running and maintaining the system on the school’s behalf, they are not actually hosting the data and therefore should there be a falling out, or indeed a firm ceases trading, there is no vulnerability to the school in terms of their data.

In terms of functionality, a closed cloud solution offered similar benefits to private cloud, including:

  • The ability to securely access all the school’s systems from any location, whether that be from different classrooms within the school, from home or elsewhere, with a uniform desktop being presented wherever you sign-on.
  • The ability to use any device, (desktop, laptop or tablet) to access the system. This can facilitate safe and effective use of "bring your own device" (BYOD), since the device is effectively just providing a "window" into the cloud system – there is no data held on it. It also means should a PC fail, it is simply a question of plugging in a replacement, with no software or data to worry about installing.
  • The ability to quickly and easily install security updates and new software releases, since in this scenario they only need to be deployed to the "master" desktop image(s) on the closed cloud server, rather than needing deployment to every computer on the network.
  • The ability to secure the desktop environment and avoid the introduction of unauthorised software, viruses, spyware and other malware.

So how do the economics of closed cloud stack up?

By the nature of it, closed cloud will necessarily be more expensive than public or private cloud, but interestingly it is still significantly cheaper than a traditional in-house school network.

Why is that? Well there are significantly reduced PC hardware costs since in this arrangement the specification of the end user device is not important as all processing is happening at the server side. This increases the lifespan of PC devices, or allows for low-cost alternatives such as thin clients or BYOD. Additionally there is a significant and ongoing ICT cost saving in the support, management and maintenance of the network.

I have put together cost comparisons for several schools on a traditional in-house IT infrastructure versus a closed cloud solution, and it has been really interesting to understand how the existing ICT budget can be redeployed to provide a solution with far more functionality, that also yields a significant and ongoing ICT cost saving. Not normally two things that go hand-in-hand when it comes to ICT!

I don't want to bore everyone here with lots of facts and figures, but if any bursar or headteacher would like to see some cost comparisons, drop me an email and I will gladly send you over some indicative figures.

I hope this article and my previous one have given you a flavour of what public, private and closed cloud solutions can offer for independent schools. If you have questions, or want to explore cloud solutions for independent schools in greater depth, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk

Monday, 14 November 2016

Cloud Computing in Independent Schools



It's true, the network does seem to get the blame for many things!

But if technology providers are to be believed, all our woes will soon be over, thanks to the advent of the “Cloud”.

This is a subject I get asked about a lot when I visit schools, so I wanted to put pen to paper to try and clarify what it's all about, as I know there is a great deal of confusion.

Cloud computing is a huge subject, but at its simplest it delivers software & data to any internet connected device; from datacentres owned by a service provider. Data will be synchronised across all devices that a user may use to connect and changes are immediately applied giving a “fully mobile” experience. Assuming you have the right level of internet connectivity, the experience will be almost indistinguishable from a traditional system – and of course it matters not if you lose or break the device because there’s nothing really stored on it that cannot be accessed from somewhere else.

Before I get bombarded by emails from the true experts among you, I realise this is a gross simplification. However I think it summarises nicely the key aspects of a cloud environment for an independent school.

The benefits of this kind of arrangement include:

• Systems can generally be accessed from anywhere, using any device. This facilitates remote working, easy sharing of data and Bring Your Own Device (BYOD).

• The hardware, software and security of the cloud system is maintained and managed by the service provider, removing a huge burden of work, worry and cost from the school.

• Remote storage of the data makes disaster recovery and resilience much simpler to achieve. Backup almost ceases to matter – although you have to be careful of the geography of your cloud partner (on which, more later).

• Such systems tend to be licensed on a "per user, per month" basis, thereby removing large CapEx spends on replacement server equipment and making costly disk and SAN upgrades a thing of the past.

There are however a number of different types of cloud and it is very important that schools understand the differences between them and the benefits and risks associated with each before making any decision to migrate to the cloud.

Public Cloud

With public cloud, the provider stores data in a network of computers, which potentially may be located anywhere in the world, with server use and storage pooled among clients. This model reaps huge economies of scale for the providers, and as such they are able to offer comparatively low monthly subscription costs. Well-known examples of public cloud would include Microsoft Office 365 and Google Apps for Education (GAFE).

Private Cloud

With the private cloud model, the same benefits are delivered as with public cloud, but on a "private" basis, with separate resources being dedicated to each client at the cloud provider’s data centre. This provides greater security and control over data, including assurances over exactly where the data is held. Being a more individual service, private cloud can also offer a much more tailored experience for schools, encompassing not just data storage and the common Microsoft applications, but a full desktop of all their education software. However, as this model does not allow providers to leverage the economies of scale in the same way as public cloud, it is necessarily more expensive.

Due Diligence and Data Protection

It is important to realise with any cloud implementation that, although you are transferring control of your data to a third party, you still remain legally responsible for protecting that data. As such it is vital to carry out due diligence to ensure you are happy with the level of security, availability and legal compliance the provider offers. This should include looking at their Service Level Agreements around availability, compliance with security standards such as ISO27001, and examining their T’s &C’s to ensure you are clear where your data is going to be held (including not just “live” data but also copies for backup and disaster recovery).

On this latter point, the data protection act requires that personal data may not be transferred out of the EEA unless the territory to which it is sent ensures an adequate level of protection. Given the US dominance of public cloud provision, it is transfers to and from the US that are most likely to affect a UK customer.

Last October the EU-US Safe Harbour agreement that enabled data transfers between the EU and the US to comply with Data Protection laws was overturned. Its successor (the EU-US Privacy Shield) only came into effect in July and is already being contested in courts in Ireland and France. To keep European business flowing the large public providers (Microsoft Azure, Google, Amazon) have attempted to embed EU data protection laws in their contracts for EU citizens. However, if we learned one thing from Snowden, it is that the US Government considers all data processed by a US business to be “fair game” – wherever the ultimate user may be from. So even if the cloud provider is well intentioned toward protecting its EU client base; there is no guarantee that the US courts or government will agree.

What does this all mean for an independent school?

Caution should remain in place when using public cloud services. There are some excellent applications available for education and you should take full advantage, however, try and resist public cloud based messaging solutions (email etc) unless they guarantee EU only data processing & be careful about what data you share using public cloud tools. At the end of the day, school data will always remain the responsibility of the school, and therefore it is for the school to assess safeguarding risks.

Cloud technologies can be a fantastic tool to embed ICT into school life, however, many schools remain sufficiently concerned over data geography to adopt private cloud solutions, or indeed “closed cloud” solutions where all data remains in school. The latter is a topic in its own right which I shall be exploring in a future article.

In the meantime, should any Bursar like my advice on data storage solutions that will leave their school fully compliant in this regard, or indeed any other ICT related issue, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk

Monday, 31 October 2016

Embedding Technology into Prep School Life



It never ceases to amaze me how much the use of technology in Independent Schools has changed over just a few years.

Only recently, ICT was confined to a suite of school-owned computers in one or two classrooms, specific to the teaching of ICT. Nowadays though, ICT is embedded in everything that we do, and provides part of the learning framework for every lesson, not just ICT.

I was recently visiting Fiona Price, head of ICT at Stroud Prep School in Romsey. Fiona is also the ICT subject advisor for IAPS, and it's great to see how Stroud have embraced and embedded the use of technology throughout the whole of school life.

Every pupil at Stroud from year 5 upwards has an allocated iPad, as do the teachers and teaching assistants, with all other students having access to a banked iPad - so about 400 in all.

To facilitate the use of technology in any part of the school, there is a centrally managed wireless solution that provides coverage across all the various buildings. These types of Wi-Fi systems have moved on light years since the early days of wireless technology, where coverage was sketchy, only a limited number of devices could be connected at any one time in any given area and security was something that had to be set individually on each wireless access point.

Stroud's Internet connectivity is provided by a 50Mbps leased line; again such circuits were cost prohibitive to many schools not so long ago, but have tumbled in price as the market has opened up, allowing many more Independent Schools to obtain high quality, fast Internet connectivity at a reasonable price.

The Internet line at Stroud also provides a secure Virtual Private Network (VPN) connection to Stroud's parent school, King Edward VI School in Southampton, allowing for the sharing of resources between the 2 schools.

By providing pupils with tablets which are routed via the school network, and not allowing smartphones or other tablets in school, Stroud have done much to prevent pupils circumnavigating the school's web access controls.

Stroud's use of ICT demonstrates how a well-designed system can do much to help pupils use technology as an effective learning tool, without the safeguarding risks or distractions that can come with less controlled access.

Should any bursar like my advice on embedding technology in their school, or the associated issues around managed Wi-Fi, internet connectivity and systems security, please feel free to contact me on 0330 002 0045 or email schools@entrustit.co.uk

Monday, 10 October 2016

When it comes to your Network, Expect the Unexpected!


With Independent Schools becoming increasingly reliant on technology for delivering lessons and running the administrative side of the school, network reliability and resilience is one of the hot topics that I often get asked about by the schools we work with.

While many Independent Schools enjoy stunning countryside locations, there can be some pitfalls in terms of technology! Over the years, most schools have bitten the bullet with the "excess construction charges" that BT and similar organisations levy to connect these locations to the Internet. But many schools still suffer from Internet reliability issues. I noticed in the press just this week that Myddelton School which has just opened in North Wales enjoyed a challenging first few days when their Internet circuit was severed, and I know many other schools have been in the same boat over the years, when something as simple as a bad storm took down overhead cables, resulting in a lengthy Internet outage.

And when it's not the great British weather causing havoc, it can be the local wildlife creating chaos, as one school I spoke to recently had found to their detriment. They first became aware of a problem when one building could no longer connect to the network. After much troubleshooting, it was discovered that a local rodent had nibbled through the fibre-optic cable that ran between two buildings!

And of course power problems have been a common cause of downtime for many schools over the years.

Coming from a business background, where there has been a reliance on 'always on' ICT for some years now, I am well versed in ways to overcome these challenges, so I thought it would be useful to share a few pointers:-

  1. Uninterruptible Power Supply (UPS) equipment is important, not only to protect your servers but also other connectivity equipment such as Internet routers, firewall, network switches and Wi-Fi access points. Just having a UPS isn't enough though, it is important that they are sized correctly to provide an adequate run-time in the event of a power outage and that they are tested periodically and batteries replaced when indicated.
  2. Some resilience can be built into Internet connectivity by having a backup line – where practicable routed differently from the main line – which will provide a failover in the event of the main line experiencing an outage. Again, just having a backup line is not enough though, as there are some technical intricacies involved in swapping from one line to another, therefore the firewall or router needs to appropriately pre-configured to enable a seamless switchover to take place. We are currently implementing solutions for many of our customers around this technology, and the good thing is that with ever-falling Internet connectivity prices, in some cases we've been able to provide them with a new main line and a backup line for a similar cost to their current main line only.
  3. Inter-building connectivity can be made more robust by undergrounding cables where possible and providing diversely routed connections between buildings so that there is more than one route by which network traffic can travel between building A and building B.
  4. In terms of server hardware, it tends to be the components that contain moving parts - things like power supplies and disk drives - that are most prone to a failure, so it's important that equipment has redundant power supplies and redundant arrays of disk drives. Or of course you could consider migrating to the cloud to negate the need for in-house servers at all – but that’s a big topic for another day!
  5. Server monitoring software can also provide a valuable insight into the health of the network, allowing problems to be addressed proactively before they cause disruptive downtime. I would caution though, that it is vital this type of software is configured correctly, as there is a tendency for it either to over-alert and cry wolf too often, in which case real problems can be overlooked, or to under-alert resulting in vital problems being missed.
In future articles I will be discussing more ways of ensuring your ICT is “always on”, but if in the meantime you need any help or advice around making your network more resilient, then please do not hesitate to contact me on 0330-002-0045 or email schools@entrustit.co.uk

Monday, 26 September 2016

Knowledge is Power for Bursars in Independent Schools


With technology now intrinsically embedded in pretty much every element of school life, both inside and outside the classroom, the ability to make empowered decisions about the strategic use of ICT within the school has never been more important.

The Bursar frequently has the unenviable job of ensuring that the school ICT system simultaneously delivers:

• The best possible learning experience to pupils
• Provides for the smooth running of the administrative side of the school
• Safeguards the pupils
• Complies with all relevant legislation
• Serves to attract new pupils to the school

And he or she also needs to achieve all of this within the confines of a limited budget!

This is where Sir Francis Bacon's famous adage "Knowledge is Power" really comes into its own.

Because without good information the Bursar and the rest of the school's Senior Leadership Team can be left in a precarious position, as they don't have the knowledge needed to make informed decisions over the strategic use or direction of technology within the school. Whether you love or loathe technology, the reality is that ICT is now interwoven into the framework of the school and its successful strategic use is critical to the ongoing success of the school.

With technology, and associated security threats, ever-changing, this is an area where no school can afford to stand still.

So it may be worth considering the questions below, to make sure you have the information you need to make empowered decisions over the strategic use of technology in your school:-

• Do you know what technology you have got and what value it adds to your school?

• Do you understand how your ICT systems, in conjunction with your procedures, policies and pupil/staff education plan, safeguard children?

• Has the resilience and disaster recovery provision of your systems kept pace with the changing use of ICT in Independent schools?

• How cost-effective is your ICT system? Are you overspending or under spending compared with other independent schools? Could your ICT budget be deployed more effectively?

• Is the SLT kept abreast of the ever-changing cyber security threat landscape, and have you implemented the necessary technologies, policies and staff training to mitigate the risks? Is this reviewed and updated on a regular basis in light of technological advances and new threats?

• Do you know which technologies other local independent schools have deployed or are considering implementing and how that will impact on your competitiveness in attracting new pupils?

• Do you have a clear understanding of how future proof your ICT systems are? If they have a limited lifespan (and let's face it, most things in ICT do!), have you considered when you will replace them, and what with?

  • Are you clear about the benefits and risks of Cloud Computing in independent schools?

• Do you understand what technology and procedures you have in place to prevent data leakage and/or loss?

• Are you aware of the ways you can leverage your ICT systems to generate further income for the school or fulfil its charitable status obligations?

In the digital world in which we now live, making the right ICT choices is integral to success.

And that all starts with having the right information.

Monday, 12 September 2016

Web Access in Independent Schools - Protect or Educate?



One of the common themes I get asked about when I visit Independent Schools, is that of web access.

It's one of those areas where many schools find it difficult to get the fine balance right between safeguarding and usability.

In most cases - and for all the right reasons - the internet has been locked down very tightly, to ensure pupils can't access inappropriate websites. Often though, the policies set also preclude the staff from being able to access online resources which are needed, or would be useful, to carry out their job.

In other cases the system has grown organically over the years, and now has such a complicated set of algorithms behind it, that it is difficult to unravel or make changes, and indeed may seem to give inconsistent results over what can be accessed and by whom on any given day.

Neither of these situations is beneficial for any school, and when I am approached by schools who find themselves in these scenarios I normally suggest that we sit down and redefine the web access policy from scratch. Let's bear in mind that times have changed from the early days of Internet connectivity, and whatever controls we implement on the school's firewall to restrict access via Wi-Fi or school computers, pupils can, if they wish, circumvent, using 4G on their smart phone. Many schools feel this changes the onus from one of blocking everything possible, to one of educating youngsters in the safe and effective use of the Internet nowadays. Now please don't think I am proposing unrestricted Internet access for all, as that is absolutely not the case. Certain types of websites will always need to be blocked. I am just saying that schools’ responsibilities around safeguarding are complex, involving not just age appropriate access policies, but also around equipping pupils for later life by educating them in safe and effective use of the Internet, whilst also providing staff with monitoring and reporting facilities so they have visibility of what sites pupil are visiting.

Luckily, modern web filtering products have moved on apace and many now offer powerful reporting capabilities, along with the ability to set up multi-layered security policies, so that specific subsets of people such as staff or different year groups can have differing levels of access. Whilst most schools prefer to get in a specialist IT company to ensure the systems and policies are initially setup correctly, the beauty is that these systems are then largely self-managing, with automatic security updates being applied and a relatively straightforward management and reporting interface.

Monday, 29 August 2016

The Relentless March of Technology

 
I must be getting old, but the other day I found myself wondering, just when did every classroom become an ICT suite?

ICT used to be boxed away so neatly. There was that room with all the cables and the stuff with the flashing lights on it where the Network Manager lives, and there were a few ICT suites carefully equipped with highly configured and secured PCs.

But suddenly every Tom, Dick and Harry (or at least pupil, staff member and visitor) is turning up with their own laptops, tablets and phones and seems to be creating an on-the-fly ICT suite in every room. Throughout the land, Network Managers are ashen-faced and on occasion, dare I say it, a little huffy, at the thought of a random array of unapproved and uncontrolled personal devices being connected to "their" network. And as always, the Bursar is left to pick up the pieces.

At one school I visit, there is a lively debate going on between the Head of English and the Head of ICT as to whether the new school library should contain books or just electronic readers. Libraries without books? What is the world coming to?

Then there's the Cloud. Should we even have an in-house ICT system at all? Or could we do away with all this costly equipment and the people to manage it, and the hassle of trying to fix it when it goes wrong and constantly battling to keep it up to date! The Cloud sounds like the panacea to all our ICT woes. But wait, I hear you say, we can't even get a reliable high speed connection to the Internet from the stunning rural location of our Independent School.… So how's that ever going to work?!

There is no doubt that the arrival of the digital era has created enormous challenges for Independent Schools, with cyber security and safeguarding children being two of the key issues. But with the Internet now considered a “basic human right” in the digital world in which we live, the need for pupils to learn how to use it safely and effectively is paramount. And with an ever increasing reliance on technology in the classroom, making school systems bullet proof has also become a necessity, because there is nothing worse for a teacher than to stand in front of a room of eager (or not!) pupils, finding he is unable to deliver his lesson as planned because the internet has gone down. Of course a good teacher will always get by, but that's not the point, he should be able to rely on his technology to deliver the lesson in the most appealing and engaging way for his pupils. And of course there's the unenviable task of trying to find budget to fund new ICT initiatives and the appropriate safeguards that are needed to go with them.

But it's not all doom and gloom. Many Independent Schools are finding their way through the challenges and embracing the technology. They've found ways to flip their ICT budgets and use the current pot of money in a very different way to create a powerful learning platform that serves to teach children more effectively and equip them for life in the digital era. A system that is safe and secure, reliable and fast. A system that not only serves the educational needs of the school, but helps to balance the books commercially too, ensuring that their school's technology is keeping pace with, if not surpassing, that of other local schools, and is serving to attract new pupils to the school. And there are other ways these schools are leveraging their new technology commercially, perhaps to attract more events to the school, or bring in more summer school bookings. In some cases they are leveraging their new technology to help them fulfil their charitable status obligations too, by using some of that technology for the good of the local community for example. What great PR for the school too!

So actually, perhaps the relentless march of technology is not so bad after all. In fact, on reflection, I think I can safely say, bring it on!