Showing posts with label cloud computing in Independent Schools. Show all posts
Showing posts with label cloud computing in Independent Schools. Show all posts

Tuesday, 19 September 2017

Why Independent Schools must Prepare Pupils for Jobs that Haven't been Invented


Whether we like or loathe technology, there is no doubt that every facet of our lives is being changed by digital transformation.

Technology is changing businesses - we only have to see the impact of Uber on traditional taxis, Purple Bricks on traditional estate agents or Airbnb on traditional holiday accommodation, to understand that the world around us is changing because of the use of technology.

The way our young people socialise and interact with each other has also totally changed in recent years with the use of Snapchat, Instagram, Facebook and a plethora of other social media sites, not to mention the streaming of music and films/TV and the advent of e-readers and the subsequent digitisation of books - so different from my day where we went to a shop to buy a CD or borrowed a book from the library!

Technology has also made the world a much smaller place, with the cloud, virtual learning environments, and virtual meeting environments enabling remote working and real-time communication wherever we are. And - for better or worse - this "permanently connected" status of our smartphones and tablets has also meant for many of us that much of our work lives and our personal lives have become 24x7.

And the pace of change continues to increase. Already Artificial Intelligence (AI) is starting to change the world around us, dispensing with the need for some jobs, while creating the need for different, digitally savvy skills to create and manage the technology. This is a trend that can only be set to continue and extend in coming years. Meanwhile the Internet of Things (IoT) is continuing to evolve, with everything from our building management systems, to our CCTV systems being connected to the Internet. Perhaps soon the fridges in our school kitchens will be monitoring their own stock levels and automatically re-ordering items that are running short.

Embracing technology, and equipping pupils with the skills to thrive in the new digital economy, forms a vital part of preparing pupils for life beyond school. Already there are so many jobs that just didn't exist 10 years ago, and there is no doubt that some of our pupils today will be undertaking jobs in the future that haven't even yet been invented.

This is why it is so vital for schools to embrace technology and build it into every element of school life. Of course, embedding technology into school life does rightly raise concerns amongst the Senior Leadership Team as to how to safeguard pupils in this environment, as well as preventing all the distractions that come with things like social media. However with the right controls, processes and technologies in place, this is very much achievable, as has been shown by many independent schools, such as Stroud School, whom I featured in a recent piece on my blog

If you would like to know more about EntrustIT's ICT strategy and project services, which enable schools to embrace digital technology and embed it into school life, please do not hesitate to contact me on 0330-002-0045 or email schools@entrustIT.co.uk

Monday, 10 July 2017

Preparing Your Independent School for GDPR: Cyber Security Issues


In my recent blog I talked about the importance of understanding your data and securing your information systems from internal threats in readiness for GDPR. In today's article I wanted to talk about the other side of the coin: securing your information systems from external security threats.

We only have to open a newspaper or turn on the news these days to hear about some new cyber security threat or data breach that has occurred. Protecting against such breaches forms an important part of GDPR compliance, since you need to be able to demonstrate that you are taking proper care of the personal data that your school holds.

There are a wide range of factors to consider here, which will include:

1. How is your network secured from threats like malware, ransomware and hackers?
In days gone by a firewall and some antivirus software would largely do the job, but with the constantly evolving threat landscape this is no longer the case and a much more sophisticated suite of school procedures, processes and technologies is needed to provide full protection.

2. What are your procedures for applying security updates to your systems?
New security threats are emerging daily and software vendors are releasing a constant stream of fixes and patches to try and mitigate the risks from these threats. Therefore it is critical that you apply these security fixes to both your servers and your PCs and laptops in a timely fashion. Indeed, the timeliness of updates has now become even more critical since some cyber criminals are now reverse engineering the fixes from vendors such as Microsoft, in order that they can see what vulnerabilities have been fixed, and using that information to directly target those vulnerabilities in organisations who have not applied the appropriate update to their systems.

3. How is your data backed up?
Taking full system backups which are regularly tested is essential, so that you know you could recover data in a timely fashion should your school be hit by a cyber threat such as ransomware.

4. What are your procedures around physical security of your servers and IT equipment? Having good cyber security in place is critical, but if someone can access your server room or acquire a laptop or smartphone containing school data, then the very best cyber security systems can be rendered useless.

5. How do you manage secure disposal of old PC and server equipment?
Equipment that is end-of-life and being replaced will often contain confidential data or emails, and therefore it is important that it is properly wiped, to guarantee that data cannot be restored.

6. How are your staff educated to ensure they are aware of the latest cyber security threats?
It is all too easy to click on seemingly legitimate attachments or web links which may actually contain malicious code, and with new threats constantly emerging, the vigilance of your staff in being able to spot such scams will form part of your defence strategy.

7. How and when are your procedures around cyber security reviewed and updated?
Given the constantly changing threat landscape, it is critical that procedures and controls around cyber security are regularly reviewed and updated

For more information about protecting your school from cyber threats or preparing for GDPR, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk.

Monday, 26 June 2017

Protecting your School's Network Manager from Stress and Burnout



In my recent blog, Why Every Independent School needs a Super-Hero, I talked about the wide ranging variety of roles that we expect our network managers to fulfil, from support provider and trainer, right through to network architect, project manager, cyber security expert and much more besides. 

At this time of year, when for many of us our thoughts are beginning to turn to a welcome break from work, let's spare a thought for our network managers who are often planning for one of their busiest periods in the school year – the summer holidays.  

Whilst we are enjoying the sunshine, many of them will be immersed in technically complex projects to upgrade the school’s network infrastructure. Now don't get me wrong, for many network managers, this is an exciting period of the year when they get to experience new technology and increase their technical skill set.  However, it is important that all of us get a break from time to time, and as employers we all have a duty of care towards our staff to ensure that that is the case.

So, if not during the summer holidays, then when will your network manager get a break this year?  This can be a tricky challenge, since once the summer holiday projects are complete, and school is back in full swing, we need our network managers to be in school more than ever, to provide support, hand holding and training, especially during that back-to-school phase, when invariably passwords will have been forgotten, there will be large numbers of new pupils, some new staff and  some snagging issues from the holiday upgrade projects.  As a result, I see many network managers who become overloaded, and in some cases this can even lead to serious health issues.

One answer can be to partner with an experienced schools ICT provider, who can provide a flexible holiday cover support contract for your network manager, giving network managers the time and uninterrupted rest they need to recharge their batteries, whilst giving schools the reassurance that their ICT systems are still safely supported.  Such contracts can also provide a useful backstop for the network manager at other times, by providing them with extra resources and skills to call upon during what could otherwise be stressful situations, such as getting to the bottom of a particularly thorny problem, or providing day-to-day support when they are tied up on project work.

So while you are relaxing by the pool this summer, do spare a thought for our hardworking network managers.  
If you would like more information about EntrustIT’s support services for schools, including holiday cover for Network Managers, please do not hesitate to contact me on 0330 002 0045, email schools@entrustIT.co.uk or visit our website http://www.entrustit.co.uk/our-specialisms/education/


Monday, 12 June 2017

How would your Independent School cope with 22 Hours of ICT Downtime?


In the wake of British Airways catastrophic IT Failure which left so many passengers stranded at airports at the start of half term, I thought it would be timely today to talk about disaster recovery.

As anyone who has ever experienced network downtime will know, it is amazing how crippling an ICT system failure is to a school, and how far reaching the consequences can be. Not only does an outage create classroom and administrative operational chaos, it can also have serious consequences for the school’s reputation, particularly where there is loss of critical data such as pupils’ coursework, or a breach of security around confidential pupil data.

Whilst many schools I talk to tend to associate ICT downtime with large events such as fires or floods, the reality is that the majority of ICT downtime has much more mundane causes which can include hardware failures, loss of power, cyber security breaches (such as ransomware attacks) and software failures. And in many cases the downtime is considerable, with the EMC Global Data Protection Index 2016 study showing that the average length of unplanned downtime was 22 hours. Indeed the situation seems to be worsening this year, with ICT downtime caused by ransomware attacks in particular often running into a week or more.

And while many of us can work around a short system outage, when such outages are extending into days or even weeks there can be a serious impact on the school’s operations and reputation. As such, it is critical that the senior leadership team have a thorough understanding of their risk management processes and contingency procedures around network resilience, backups and disaster recovery.

So is it enough to have a disaster recovery plan? Sadly I fear not. I’m sure BA had a disaster recovery plan, but how well did it work when it was used in anger? For many schools, I find the disaster recovery plan that was put together some years ago and has sat in the fireproof safe ever since, without testing or updating. My experience is that this document needs to be constantly evolving, as our use of technology in education has moved on apace, and what was an acceptable recovery plan a couple of years ago may now be totally inadequate. In addition, our systems are constantly changing, with software updates and security fixes being installed on a regular basis, all of which can impact on the technical success of a recovery.

In order to ensure ongoing relevance, I always recommend that schools continually re-assess and test their plans around resilience, backup and disaster recovery, against the operational needs of their school and their changing use of technology. Some points to consider would include:-
  • How long could you afford for each of your various ICT systems to be down for? 
  • How much data and email, if any, could you afford to lose?  
  • When did you last try a test restore of your data or email? Did it work?
  • Have you tried a test of your full disaster recovery plan lately? Did it work? How long did it take? How much data was lost? Did the results demonstrate that recovery times and data loss met your school’s current operational requirements as defined above? 
  • Do your backup and disaster recovery plans meet your forthcoming GDPR compliance obligations? 
  • Where are your backups held? Would an incident like a fire or a ransomware attack wipe out your backups as well as your live systems? 
  • In the event of a major disaster, what hardware would you restore your backups on to? 
  • How would your school operate in the period whilst the systems were down? 
  • How would you communicate details of an outage with parents, staff, pupils and the public to minimise the reputational damage to your school?
 If you are unclear of the answers to any of these questions, it may be time to review your processes and procedures around disaster recovery planning to ensure your school is not exposed to undue risk in this area. If you have any questions or would like information on ways EntrustIT can help, please do not hesitate to contact me on 0330-002-0045 or email schools@entrustit.co.uk

Monday, 22 May 2017

Monetising Your School’s ICT Facilities


Independent schools spend a significant amount of money on ICT facilities both to enhance the learning environment and to ensure the smooth running of the school’s administrative function. Whilst most schools will look to incorporate messages about their ICT facilities into their marketing literature to attract new pupils, there is also the opportunity to leverage ICT to generate income from other sources too.

Technology plays an important part in most people’s lives nowadays, and when booking social, educational or leisure activities, having access to good technology, such as fast Wi-Fi and Internet connectivity, forms an important part of people’s decision making process in choosing a venue for such events. This is something which Independent Schools can capitalise on, since they have these facilities anyway, which are often lying dormant, or as a minimum under-utilised, during the school holiday periods.

ICT suite(s) are an obvious facility that can be let out in the school holidays to summer schools, clubs or local groups. However lettings do not need to be restricted to the ICT suite alone nowadays, since most independent schools now enjoy school-wide Wi-Fi and support for BYOD (Bring Your Own Device) which presents the opportunity to let out any classroom, allowing guests to bring their own equipment and effectively set up an ICT suite "on the fly".

Many Independent Schools have also invested in a music technology suite, which is a desirable facility which can be let to groups, clubs and budding local musicians during periods when the school is not using it.

Wi-Fi is also now considered a "must have" for events such as weddings, parties, summer schools or business conferences. Whilst they are not always aware of it, many schools’ Wi-Fi systems offer the facility to generate restricted-duration tickets for guest Wi-Fi access, as well as the ability to charge for Wi-Fi access in the way that many hotels do, typically offering a basic level of connectivity for free and then charging a fee for higher speed/capacity.

Most schools have also bitten the bullet and paid the charges needed to get high speed leased line Internet connectivity into their premises. However many smaller businesses or clubs in the area cannot necessarily afford these type of costs. This offers another opportunity to Independent Schools to provide a slice of their internet connectivity to a local small business/golf club/sports club etc as an income generator for the school.

So one way and another there is much that schools can do to leverage their ICT and create an additional income stream from it.

Naturally if you're planning to provide access to your school ICT facilities to outsiders, then some suitable security provisions need to be put in place. This is relatively straightforward though, since firewall policies can be set up and Wi-Fi configured such that guests are kept completely separate from the school's network traffic and systems.

If you would like more information on this topic, please do not hesitate to contact me on 0330-002-0045 or email schools@entrustit.co.uk.

Monday, 8 May 2017

Preparing for GDPR – Understanding and Securing your School’s Data


Following on from my recent blog, “GDPR – What’s it all about and how does it affect Independent Schools” I’ve had requests from several schools asking for more information, so I thought it would be useful to elaborate on some of the issues that GDPR raises for Independent Schools.

I wanted to start by further exploring the importance of understanding what personal data you hold and where that confidential data is stored. Bear in mind personal data can be as simple as a pupil, teacher or parent’s name or email address.

This may sound like an odd topic, as I'm sure many of you are thinking you know exactly where all your schools’ data is held. But do you really?

The scary reality nowadays is that your school’s precious data may already be widely scattered. Yes, some of it will certainly be residing (hopefully securely) on your in-house servers. But what about the proliferation of school, staff and pupil owned portable devices such as laptops, tablets and smartphones which now hold school data or emails? Or data that has been copied to removable media such as USB sticks? Or data that has been shared with business partners and other third-parties? Or copies of data taken for backup purposes?

Then there is the cloud. The cloud has revolutionised the way many schools store their data, but in doing so has also globalised the way data is stored, with many public cloud providers distributing data across servers worldwide in order to optimise costs.

So do you really know where all your data is held? And does it matter?

Well in terms of GDPR it certainly matters, as you need to be able to demonstrate that you are protecting your data and using it appropriately. The more widespread and less controlled your data is, the more vulnerable you leave your school to a breach of data security. So understanding what you have and where it is forms the first step towards compliance.

If, on reflection, you realise that your school’s data is already widely scattered, you may wish to bring it together in one secure, central repository in order to make it easier to control and manage. Luckily nowadays there are technologies that facilitate this; for example we have built our very own EducateIT desktop platform for schools, which is an onsite private cloud solution which allows a school to bring together all their data in one secure, central, onsite repository, where they and their authorised partners can access it securely wherever they are, without the source data ever leaving the security of the school. For other schools, where data is generally central, but perhaps also resides on some mobile devices too, we work to implement processes and technologies to prevent data leakage and manage mobile devices.

Either way, it is paramount to put the school back in control of its data, knowing both where it is and who has access to it. This in turn needs to be documented, both so that the senior leadership team team have understanding of, and control over, their valuable data and also in order to provide documentation for compliance and audit purposes. This not only puts schools back in control of their data, but minimises the risk of a security breach and takes the first step towards preparing for GDPR compliance.

Once you have this understanding, the next step is to understand how you secure your data. This broadly falls into two categories – access control (effective security for authorised users) and cyber security (protection against unauthorised access).

Today I am going to talk about the former, as having good access control systems lies at the heart of successfully protecting your school’s data, and forms an important part of preparing your school’s information systems for GDPR compliance.

GDPR places accountability on schools to have in place policies, procedures and documentation that demonstrates the personal data they hold is stored securely. Bearing in mind that schools hold a vast array of personal data, much of which is about children, whom the GDPR identifies as “vulnerable individuals” deserving of “special protection”, and it becomes clear that the legislation is likely to cover the vast majority of a school’s data.

Therefore, for each of your computer systems, it is important to understand, and have documented, who has access to that system and what level of access they have. Bear in mind that it is best practice to give each user the minimum access they require to the system. Allowing wider access to systems puts you at greater risk of a data security breach or data loss through incidents such as accidental deletion, a ransomware attack or malicious insider threats. As well as having SOPs in place to handle the ICT access control requirements of new starters, it is equally important that there are procedures in place to cover leavers (both pupils and staff) and what happens when somebody changes role within the school.

Password policies are always a bone of contention and an area where a fine balance needs to be struck. Policies that are too lax lead to easily guessable passwords which may not demonstrate due care of data under GDPR. On the other hand, policies which demand highly complex, long passwords which change frequently, may lead to dozens of forgotten passwords and/or the temptation to record passwords on sticky notes, which also certainly doesn’t demonstrate due care of data!

Nowadays, it is also likely that third parties such as freelancers, suppliers and of course parents will have access to some of your ICT systems or data. In this case this needs to be secured in just the same way, so you are clear who has access to what parts of the system, why this is needed and how it is controlled. There also need to be procedures in place to review, amend and remove access for third parties, as relationships evolve and change.

Mobile and remote working present a whole additional set of challenges to ICT security, with the potential for copies of data or emails to be residing on all kinds of devices, both school owned and personally owned, which do not necessarily conform to school security standards. So developing policies around mobile working and ensuring there is not leakage of data or unauthorised access to data form a critical part of compliance. Policies and technologies also need to be implemented to protect against data breaches from mobile devices that are lost or stolen.

Finally, bear in mind that it is not just your main school-wide IT systems that fall under the GDPR. Any indexed system that contains personal data is subject to the legislation, so do make sure you are also including in your access control procedures all those little databases or spreadsheets that have been developed by an individual or department and which contain personal data.

I hope this has given you a useful insight into some of the key areas to consider around readying your school for GDPR compliance. If you need help preparing for GDPR, or indeed with any element of your ICT system, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk

Monday, 28 November 2016

“Closed Cloud” in Independent Schools


In my last article, I talked about cloud computing in independent schools, the differences between public cloud and private cloud, and some of the concerns independent schools had about data protection in relation to public cloud solutions.

Due to these concerns, I am seeing increasing numbers of schools looking to adopt private cloud or indeed "closed cloud" solutions where all data remains in school. So today I thought it would be useful to elaborate on "closed cloud": how it works, what benefits it offers independent schools and how it compares with other types of cloud technology.

Closed cloud uses the same technologies that public and private cloud providers use, but the vital difference is that rather than being hosted at a cloud provider's data centre somewhere in the world, the whole system is physically located in school.

As with private cloud, this necessitates dedicated hardware and thus is more expensive than public cloud. However it has the benefit over both public and private cloud of providing complete assurance around data protection, since all data remains in school at all times. There is also much less reliance on a third party, as although a provider will typically be running and maintaining the system on the school’s behalf, they are not actually hosting the data and therefore should there be a falling out, or indeed a firm ceases trading, there is no vulnerability to the school in terms of their data.

In terms of functionality, a closed cloud solution offered similar benefits to private cloud, including:

  • The ability to securely access all the school’s systems from any location, whether that be from different classrooms within the school, from home or elsewhere, with a uniform desktop being presented wherever you sign-on.
  • The ability to use any device, (desktop, laptop or tablet) to access the system. This can facilitate safe and effective use of "bring your own device" (BYOD), since the device is effectively just providing a "window" into the cloud system – there is no data held on it. It also means should a PC fail, it is simply a question of plugging in a replacement, with no software or data to worry about installing.
  • The ability to quickly and easily install security updates and new software releases, since in this scenario they only need to be deployed to the "master" desktop image(s) on the closed cloud server, rather than needing deployment to every computer on the network.
  • The ability to secure the desktop environment and avoid the introduction of unauthorised software, viruses, spyware and other malware.

So how do the economics of closed cloud stack up?

By the nature of it, closed cloud will necessarily be more expensive than public or private cloud, but interestingly it is still significantly cheaper than a traditional in-house school network.

Why is that? Well there are significantly reduced PC hardware costs since in this arrangement the specification of the end user device is not important as all processing is happening at the server side. This increases the lifespan of PC devices, or allows for low-cost alternatives such as thin clients or BYOD. Additionally there is a significant and ongoing ICT cost saving in the support, management and maintenance of the network.

I have put together cost comparisons for several schools on a traditional in-house IT infrastructure versus a closed cloud solution, and it has been really interesting to understand how the existing ICT budget can be redeployed to provide a solution with far more functionality, that also yields a significant and ongoing ICT cost saving. Not normally two things that go hand-in-hand when it comes to ICT!

I don't want to bore everyone here with lots of facts and figures, but if any bursar or headteacher would like to see some cost comparisons, drop me an email and I will gladly send you over some indicative figures.

I hope this article and my previous one have given you a flavour of what public, private and closed cloud solutions can offer for independent schools. If you have questions, or want to explore cloud solutions for independent schools in greater depth, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk

Monday, 14 November 2016

Cloud Computing in Independent Schools



It's true, the network does seem to get the blame for many things!

But if technology providers are to be believed, all our woes will soon be over, thanks to the advent of the “Cloud”.

This is a subject I get asked about a lot when I visit schools, so I wanted to put pen to paper to try and clarify what it's all about, as I know there is a great deal of confusion.

Cloud computing is a huge subject, but at its simplest it delivers software & data to any internet connected device; from datacentres owned by a service provider. Data will be synchronised across all devices that a user may use to connect and changes are immediately applied giving a “fully mobile” experience. Assuming you have the right level of internet connectivity, the experience will be almost indistinguishable from a traditional system – and of course it matters not if you lose or break the device because there’s nothing really stored on it that cannot be accessed from somewhere else.

Before I get bombarded by emails from the true experts among you, I realise this is a gross simplification. However I think it summarises nicely the key aspects of a cloud environment for an independent school.

The benefits of this kind of arrangement include:

• Systems can generally be accessed from anywhere, using any device. This facilitates remote working, easy sharing of data and Bring Your Own Device (BYOD).

• The hardware, software and security of the cloud system is maintained and managed by the service provider, removing a huge burden of work, worry and cost from the school.

• Remote storage of the data makes disaster recovery and resilience much simpler to achieve. Backup almost ceases to matter – although you have to be careful of the geography of your cloud partner (on which, more later).

• Such systems tend to be licensed on a "per user, per month" basis, thereby removing large CapEx spends on replacement server equipment and making costly disk and SAN upgrades a thing of the past.

There are however a number of different types of cloud and it is very important that schools understand the differences between them and the benefits and risks associated with each before making any decision to migrate to the cloud.

Public Cloud

With public cloud, the provider stores data in a network of computers, which potentially may be located anywhere in the world, with server use and storage pooled among clients. This model reaps huge economies of scale for the providers, and as such they are able to offer comparatively low monthly subscription costs. Well-known examples of public cloud would include Microsoft Office 365 and Google Apps for Education (GAFE).

Private Cloud

With the private cloud model, the same benefits are delivered as with public cloud, but on a "private" basis, with separate resources being dedicated to each client at the cloud provider’s data centre. This provides greater security and control over data, including assurances over exactly where the data is held. Being a more individual service, private cloud can also offer a much more tailored experience for schools, encompassing not just data storage and the common Microsoft applications, but a full desktop of all their education software. However, as this model does not allow providers to leverage the economies of scale in the same way as public cloud, it is necessarily more expensive.

Due Diligence and Data Protection

It is important to realise with any cloud implementation that, although you are transferring control of your data to a third party, you still remain legally responsible for protecting that data. As such it is vital to carry out due diligence to ensure you are happy with the level of security, availability and legal compliance the provider offers. This should include looking at their Service Level Agreements around availability, compliance with security standards such as ISO27001, and examining their T’s &C’s to ensure you are clear where your data is going to be held (including not just “live” data but also copies for backup and disaster recovery).

On this latter point, the data protection act requires that personal data may not be transferred out of the EEA unless the territory to which it is sent ensures an adequate level of protection. Given the US dominance of public cloud provision, it is transfers to and from the US that are most likely to affect a UK customer.

Last October the EU-US Safe Harbour agreement that enabled data transfers between the EU and the US to comply with Data Protection laws was overturned. Its successor (the EU-US Privacy Shield) only came into effect in July and is already being contested in courts in Ireland and France. To keep European business flowing the large public providers (Microsoft Azure, Google, Amazon) have attempted to embed EU data protection laws in their contracts for EU citizens. However, if we learned one thing from Snowden, it is that the US Government considers all data processed by a US business to be “fair game” – wherever the ultimate user may be from. So even if the cloud provider is well intentioned toward protecting its EU client base; there is no guarantee that the US courts or government will agree.

What does this all mean for an independent school?

Caution should remain in place when using public cloud services. There are some excellent applications available for education and you should take full advantage, however, try and resist public cloud based messaging solutions (email etc) unless they guarantee EU only data processing & be careful about what data you share using public cloud tools. At the end of the day, school data will always remain the responsibility of the school, and therefore it is for the school to assess safeguarding risks.

Cloud technologies can be a fantastic tool to embed ICT into school life, however, many schools remain sufficiently concerned over data geography to adopt private cloud solutions, or indeed “closed cloud” solutions where all data remains in school. The latter is a topic in its own right which I shall be exploring in a future article.

In the meantime, should any Bursar like my advice on data storage solutions that will leave their school fully compliant in this regard, or indeed any other ICT related issue, please do not hesitate to contact me on 0330 002 0045 or email schools@entrustit.co.uk