Welcome to my blog, ICT in Independent schools, which is designed to keep bursars and headteachers up-to-date with technology in education. As someone who is passionate about the effective use of ICT in schools, I wanted to use this forum to share best practice and discuss common challenges around using ICT to provide a powerful learning environment whilst also having in place the right security and processes to safeguard pupils.
Showing posts with label ICT support for Independent Schools. Show all posts
Showing posts with label ICT support for Independent Schools. Show all posts
Monday, 3 April 2017
Why Every Independent School needs a list of Specific Unknown Problems!
It's that time of year again, when schools are starting to plan their network upgrade projects for the summer holidays. And if only we could list every unknown problem that might occur, it would make all our lives so much easier!
Of course with technology being technology, it never seems to work quite like that. We only have to think about any high-profile public sector ICT project to know that these things are rarely brought in successfully on time and within budget, with a fanfare from the delighted user base!
And to expect our schools’ Network Managers to deliver what are now often highly complex ICT projects on their own over the school holidays can be an unrealistic expectation. We have to bear in mind that delivering ICT infrastructure projects requires a whole raft of specialist skills ranging from systems design (a specialist skill in its own right), to systems installation, people management, project management, risk management and organisational skills.
Then put this against the backdrop of a schools' operational environment: often hundreds of software applications, not always inventoried, and indeed sometimes not on the Network Manager's radar at all. Downtime windows confined to school holidays. The need to structure the project plan around certain days or rooms where the system needs to be operational, such as on exam result days or periods where certain facilities are let for summer schools. A plethora of rooms, buildings and keys. Laptops, some of which will invariably have been taken off site. The need to liaise with third parties such as software suppliers over a period when many people are away. Key users who aren't available for testing or training as they are on holiday. And the vagaries of technology, where something doesn't quite do what it says on the tin!
Then there’s the increasingly critical need to build in cyber security and data protection from the ground floor up in any new or upgraded systems, again a specialist skillset in its own right.
Added to this, we need to remember that these types of projects are not something our Network Managers do every day, and just like anything any of us are doing for the first time, it is unlikely to go as smoothly as if we had done it many times before. So perhaps it is little wonder that schools sometimes experience disruption at the start of term in September, when ICT projects have over run!
The key to success in these projects lies in the planning. Whilst none of us have a crystal ball to be able to anticipate every problem that may occur, having a breadth of experience in carrying out these type of projects means that many of the "unknown problems" that might present a challenge to in-house ICT staff, will actually be "known issues" to someone with wider experience, and can be planned for accordingly.
And let’s not lose sight of the fact that, with a helping hand to support them to succeed, these exciting projects not only enhance the schools’ learning environment, but also offer a fantastic development opportunity for schools’ Network Managers.
If your school needs an experienced organisation to work with your in-house ICT team to plan and deliver your forthcoming network development projects, please do not hesitate to contact me on 0330-002-0046 or email schools@entrustit.co.uk to discuss your requirements.
Monday, 20 March 2017
GDPR – What’s it all about and how does it affect Independent Schools?
The new EU General Data Protection Regulation (GDPR) comes in to effect in May 2018 and represents the most radical change in data protection legislation in the last 20 years. Whilst many schools, and indeed businesses, that I work with were hoping this would go away, especially in light of Brexit, it has now been confirmed that the UK will be implementing the legislation and as such, is “the elephant in the room” that schools can no longer afford to ignore. So today I thought it would be useful to share some information on what GDPR is all about and what key actions Independent Schools need to be taking to ensure compliance.
By way of background, GDPR has been developed to reflect the changing use of data in the digital world in which we now live. With the digital economy being primarily built upon the collection and exchange of data, including large amounts of personal data, which is often sensitive, there is a need to protect EU citizens’ privacy rights. GDPR is designed to enable citizens to benefit from modern digital services, whilst providing sound, well formulated and properly enforced data protection safeguards to help mitigate risks and inspire public confidence in how their information is handled by businesses, third parties, the state and public service providers.
Whilst these aspirations are to be lauded, there is much concern amongst schools and businesses alike as to the reality of understanding and implementing the legislation within their organisation. And whilst the implementation date of 25th May 2018 may still seem a long way off, the reality of the situation is that the changes this legislation requires many organisations to make are so far reaching that they need to start work now in order to be compliant in time.
The new legislation also gives the regulator real "teeth" in terms of enforcement. For example if you do not comply with some of the fundamental provisions in the legislation, such as obtaining necessary consent, you can be fined up to 4% of your total worldwide annual turnover or €20 million, whichever is greater. Equally, penalties of up to €10 million or 2% of your total annual turnover apply for not putting in place adequate security.
In addition, breaches have to be notified to the data protection authority and in some cases the people affected, without delay. This leaves the school concerned highly exposed to reputational damage and potential pay-outs to affected parties.
The situation for schools is further complicated by the fact that the GDPR identifies children as “vulnerable individuals” deserving of “special protection”. As such, schools also need to be aware that the new rules introduce some child-specific provisions, most notably in the context of legal notices and the legal grounds for processing children’s data.
One important element of GDPR compliance is protecting your data from external security threats. Schools are becoming an increasingly popular target to cyber criminals unfortunately, as there is a perception that they are a soft target, not always equipped to spot signs of increasingly sophisticated cyber fraud. Threats like ransomware for example, which I highlighted in my recent blog, are sadly now becoming more and more common in schools. And apart from the financial and operational impact these type of threats have on the school, which can be extremely damaging as they lock pupils and staff out of the system, such malware can also be used to export information. This presents a major risk under GDPR, given the compromised data involves the details of schoolchildren, which could have serious implications if it fell into the wrong hands.
In addition to outside security threats, there are a plethora of other threats to schools’ confidential data, ranging from something as simple as a staff member’s laptop or phone containing school email or data being lost or stolen, through to unauthorized copies of data being made or inadequate starter and leaver procedures for systems access.
There is no doubt that GDPR will have a wide ranging impact on schools, affecting functions as diverse as marketing, fund raising, admissions, HR and ICT, and as such is something that will need much Senior Leadership Team time and planning in order to mitigate the risks and ensure compliance by the deadline.
So what do Independent Schools need to be doing in order to mitigate the risks?
Well this is a big question and one I will be exploring in more detail in coming blogs, but to give you a flavour, the type of things you should be considering include:
- Identify what personal data you are holding. Bear in mind personal data can be as simple as a pupil, teacher or parent’s name or email address. This is vital because you need to be able to demonstrate that you are protecting this data and using it appropriately. So understanding what you have and where it is forms the first step towards compliance.
- Identify threats to this data. This could include things like cybercrime mentioned above, but also accidental loss by staff, deliberate theft by staff or pupils, lost devices and unauthorised access to data. This is vital if schools are to avoid the fines of up to €10 million that can be levied for unauthorised access to, or disclosure of, personal information.
- Invest in and implement the right technologies to deal with insider and external threats to data. This will involve a wide raft of technologies to provide protection from a range of different threats. It is vital to realise that a firewall and a piece of anti-virus software are not enough.
- Put together a new or updated data protection policy and train staff on it. This is important as everyone in your school needs to understand their obligations under GDPR and how to make themselves fully compliant.
- Put in place processes for ongoing education for all members of staff around cyber security and data protection. Because the cyber security landscape is constantly changing, it is very important that all staff are constantly kept up-to-date with best practice around security and data protection.
- Create a breach notification plan. This is important because if the worst should happen, and you do experience a data breach under GDPR, you need to have a clear plan to deal with it and communicate it as smoothly and accurately as possible, and with the least possible damage to your school.
Subscribe to:
Posts (Atom)

