Cyber Security

Cyber Security Policy

The Independent Grammar School: Durham

1. Purpose

The Independent Grammar School: Durham (IGS: Durham) is committed to protecting its digital systems, safeguarding sensitive information, and ensuring the secure delivery of teaching, learning, and examinations. This policy sets out the standards and behaviours required to maintain a secure cyber environment, meet applicable requirements under the Data Protection Act 2018, UK GDPR and current JCQ and awarding-body regulations, and support the school’s safeguarding responsibilities under Keeping Children Safe in Education. It takes account of the DfE’s current digital and technology standards and relevant NCSC guidance.

  1. Scope

This policy applies to:

  • All staff, students, directors, volunteers, contractors, and third-party providers

  • All school-owned devices, networks, cloud services, and digital platforms

  • Personal devices used for school purposes

  • All digital data, including student records, safeguarding information, exam materials, and operational data

  1. Roles and Responsibilities

Principal

The Principal has overall responsibility for the implementation of this policy.

Board

The Board provides strategic oversight of cyber-security risks and receives assurance from the Principal that appropriate controls, training and response arrangements are in place. A designated Board member oversees cyber security and filtering and monitoring.

Designated Safeguarding Lead

The DSL leads on the safeguarding implications of cyber security and online safety, including filtering and monitoring. The DSL works with the Principal and IT support to review relevant reports and ensure that identified safeguarding concerns are acted upon promptly.

IT Support

The school’s designated external IT support is responsible for maintaining technical security controls, applying security updates, managing access permissions and backups, and supporting incident investigation and recovery.

All Staff

  • Follow this policy and all related procedures

  • Protect passwords, devices, and sensitive data

  • Report suspicious activity immediately

Students

  • Use school systems responsibly

  • Follow digital safety rules and exam-related cyber-security requirements

  • Report concerns to a member of staff

  1. Cyber Security Principles

Access Control

  • Strong passwords must be used on all accounts

  • Multi-factor authentication (MFA) is required where available

  • Access to sensitive data is granted on a “least privilege” basis

  • Staff must lock screens when leaving devices unattended

  • Access permissions must be reviewed regularly and removed promptly when no longer required

Device Security

  • All school devices must use approved antivirus and endpoint protection

  • Personal devices used for school work must meet minimum security standards

  • Unauthorised software installations are prohibited

  • USB storage devices are restricted and encrypted where permitted

Operating systems and applications must remain supported and receive security updates promptly, with urgent vulnerabilities prioritised

Network Security

The school network is monitored for unusual activity

Firewalls and filtering systems must remain active at all times

Remote access is permitted only through secure, approved methods

Appropriate filtering and monitoring must cover staff and pupil use of school systems. Safeguarding alerts must be referred promptly to the DSL

Data Protection

  • Sensitive data must be stored in secure, approved systems

  • Emailing personal or confidential data must use encryption or secure transfer

  • Data must not be stored on unencrypted personal devices

  • Staff must follow the school’s Data Protection Policy

Backup and Recovery

Important school data must be backed up securely, with a protected copy separated from the live system. Restoration arrangements must be tested regularly

  1. Cyber Security in Examinations

Secure Storage of Digital Exam Materials

  • Digital exam papers, audio files, and computer-based assessments must be stored in encrypted, access-restricted locations

  • Only authorised exam officers and designated staff may access digital exam content

  • Downloading exam materials onto personal devices is strictly prohibited

Computer Based Examinations

Exam workstations must be isolated from the internet unless explicitly permitted by the awarding body

Devices must be checked for malware, unauthorised software, and connectivity risks before each exam session

Students must use school-provided accounts configured for exam conditions

Auto-save and secure backup systems must be enabled to prevent data loss

Preventing Malpractice

Students must not access messaging apps, cloud storage, or unauthorised software during exams

Staff must ensure no digital devices (phones, smartwatches, earbuds) are brought into exam rooms

Any attempt to access restricted materials or communicate digitally during exams will be treated as malpractice

Handling Exam Scripts and Files

Digital scripts must be uploaded using secure awarding-body portals

Staff must not store exam scripts on personal devices or email accounts

Digital exam files must be retained for the period required by current JCQ and awarding-body instructions and then deleted securely

Cyber Security During Exam Emergencies

In the event of:

  • Network failure

  • Device malfunction

  • Cyber-attack

  • Power outage

The Exams Officer will implement the Exam Contingency Plan, ensuring:

  • Immediate safeguarding of student work

  • Secure transfer or recovery of files

  • Communication with awarding bodies

  1. Staff Training and Awareness

All staff must complete annual cyber-security training covering:

  • Phishing and social engineering

  • Password hygiene

  • Safe data handling

  • Secure exam administration

Incident reporting procedures

The school will maintain a cyber awareness plan covering staff training, age-appropriate pupil education and acceptable use of technology. At least one designated Board member will complete annual cyber-security training. Training and awareness activities will be recorded.

  1. Incident Reporting and Response

Reporting

All suspected cyber incidents must be reported immediately to the Principal and designated IT support. The DSL must also be informed immediately where an incident has safeguarding implications. Incidents include:

  • Phishing attempts

  • Unauthorised access

  • Lost or stolen devices

  • Malware infections

  • Exam-related digital breaches

Response

The school will:

  • Contain the incident

  • Preserve evidence

  • Notify affected individuals where required

  • Report to external agencies (e.g., ICO, Police) when appropriate

  • Review and strengthen controls

Assess and record any personal data breach, notifying the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, affected individuals must be informed without undue delay

  1. Third Party Services and Cloud Platforms

Only approved platforms may be used for storing or processing school data

Contracts must include data-processing and breach-notification clauses

  1. Monitoring and Review

The school monitors network activity, system logs, and security alerts

This policy is reviewed annually or following a significant incident

Findings from audits or incidents will inform future improvements

A documented cyber risk assessment will be completed annually, reviewed each term, and reconsidered following significant changes or incidents. Actions, responsible persons and timescales will be recorded and significant risks reported to the School Board

Filtering and monitoring provision will be reviewed and documented at least once every academic year by the Principal, DSL, designated Board member and IT support, including checks of effectiveness and consideration of emerging risks

Cyber incident response and recovery arrangements will form part of the school’s business continuity planning and will be tested regularly

  1. Related Policies

  • Data Protection Policy

  • Online Safety Policy

  • Exam Contingency Plan

  • Safeguarding Policy

  • Mobile Phone Policy

May 2026, revised Sep 2026, next revision Sep 2027.


Cyber Security Policy

The Independent Grammar School: Durham

1. Purpose

The Independent Grammar School: Durham (IGS: Durham) is committed to protecting its digital systems, safeguarding sensitive information, and ensuring the secure delivery of teaching, learning, and examinations. This policy sets out the standards and behaviours required to maintain a secure cyber environment, meet applicable requirements under the Data Protection Act 2018, UK GDPR and current JCQ and awarding-body regulations, and support the school’s safeguarding responsibilities under Keeping Children Safe in Education. It takes account of the DfE’s current digital and technology standards and relevant NCSC guidance.

  1. Scope

This policy applies to:

  • All staff, students, directors, volunteers, contractors, and third-party providers

  • All school-owned devices, networks, cloud services, and digital platforms

  • Personal devices used for school purposes

  • All digital data, including student records, safeguarding information, exam materials, and operational data

  1. Roles and Responsibilities

Principal

The Principal has overall responsibility for the implementation of this policy.

Board

The Board provides strategic oversight of cyber-security risks and receives assurance from the Principal that appropriate controls, training and response arrangements are in place. A designated Board member oversees cyber security and filtering and monitoring.

Designated Safeguarding Lead

The DSL leads on the safeguarding implications of cyber security and online safety, including filtering and monitoring. The DSL works with the Principal and IT support to review relevant reports and ensure that identified safeguarding concerns are acted upon promptly.

IT Support

The school’s designated external IT support is responsible for maintaining technical security controls, applying security updates, managing access permissions and backups, and supporting incident investigation and recovery.

All Staff

  • Follow this policy and all related procedures

  • Protect passwords, devices, and sensitive data

  • Report suspicious activity immediately

Students

  • Use school systems responsibly

  • Follow digital safety rules and exam-related cyber-security requirements

  • Report concerns to a member of staff

  1. Cyber Security Principles

Access Control

  • Strong passwords must be used on all accounts

  • Multi-factor authentication (MFA) is required where available

  • Access to sensitive data is granted on a “least privilege” basis

  • Staff must lock screens when leaving devices unattended

  • Access permissions must be reviewed regularly and removed promptly when no longer required

Device Security

  • All school devices must use approved antivirus and endpoint protection

  • Personal devices used for school work must meet minimum security standards

  • Unauthorised software installations are prohibited

  • USB storage devices are restricted and encrypted where permitted

Operating systems and applications must remain supported and receive security updates promptly, with urgent vulnerabilities prioritised

Network Security

The school network is monitored for unusual activity

Firewalls and filtering systems must remain active at all times

Remote access is permitted only through secure, approved methods

Appropriate filtering and monitoring must cover staff and pupil use of school systems. Safeguarding alerts must be referred promptly to the DSL

Data Protection

  • Sensitive data must be stored in secure, approved systems

  • Emailing personal or confidential data must use encryption or secure transfer

  • Data must not be stored on unencrypted personal devices

  • Staff must follow the school’s Data Protection Policy

Backup and Recovery

Important school data must be backed up securely, with a protected copy separated from the live system. Restoration arrangements must be tested regularly

  1. Cyber Security in Examinations

Secure Storage of Digital Exam Materials

  • Digital exam papers, audio files, and computer-based assessments must be stored in encrypted, access-restricted locations

  • Only authorised exam officers and designated staff may access digital exam content

  • Downloading exam materials onto personal devices is strictly prohibited

Computer Based Examinations

Exam workstations must be isolated from the internet unless explicitly permitted by the awarding body

Devices must be checked for malware, unauthorised software, and connectivity risks before each exam session

Students must use school-provided accounts configured for exam conditions

Auto-save and secure backup systems must be enabled to prevent data loss

Preventing Malpractice

Students must not access messaging apps, cloud storage, or unauthorised software during exams

Staff must ensure no digital devices (phones, smartwatches, earbuds) are brought into exam rooms

Any attempt to access restricted materials or communicate digitally during exams will be treated as malpractice

Handling Exam Scripts and Files

Digital scripts must be uploaded using secure awarding-body portals

Staff must not store exam scripts on personal devices or email accounts

Digital exam files must be retained for the period required by current JCQ and awarding-body instructions and then deleted securely

Cyber Security During Exam Emergencies

In the event of:

  • Network failure

  • Device malfunction

  • Cyber-attack

  • Power outage

The Exams Officer will implement the Exam Contingency Plan, ensuring:

  • Immediate safeguarding of student work

  • Secure transfer or recovery of files

  • Communication with awarding bodies

  1. Staff Training and Awareness

All staff must complete annual cyber-security training covering:

  • Phishing and social engineering

  • Password hygiene

  • Safe data handling

  • Secure exam administration

Incident reporting procedures

The school will maintain a cyber awareness plan covering staff training, age-appropriate pupil education and acceptable use of technology. At least one designated Board member will complete annual cyber-security training. Training and awareness activities will be recorded.

  1. Incident Reporting and Response

Reporting

All suspected cyber incidents must be reported immediately to the Principal and designated IT support. The DSL must also be informed immediately where an incident has safeguarding implications. Incidents include:

  • Phishing attempts

  • Unauthorised access

  • Lost or stolen devices

  • Malware infections

  • Exam-related digital breaches

Response

The school will:

  • Contain the incident

  • Preserve evidence

  • Notify affected individuals where required

  • Report to external agencies (e.g., ICO, Police) when appropriate

  • Review and strengthen controls

Assess and record any personal data breach, notifying the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, affected individuals must be informed without undue delay

  1. Third Party Services and Cloud Platforms

Only approved platforms may be used for storing or processing school data

Contracts must include data-processing and breach-notification clauses

  1. Monitoring and Review

The school monitors network activity, system logs, and security alerts

This policy is reviewed annually or following a significant incident

Findings from audits or incidents will inform future improvements

A documented cyber risk assessment will be completed annually, reviewed each term, and reconsidered following significant changes or incidents. Actions, responsible persons and timescales will be recorded and significant risks reported to the School Board

Filtering and monitoring provision will be reviewed and documented at least once every academic year by the Principal, DSL, designated Board member and IT support, including checks of effectiveness and consideration of emerging risks

Cyber incident response and recovery arrangements will form part of the school’s business continuity planning and will be tested regularly

  1. Related Policies

  • Data Protection Policy

  • Online Safety Policy

  • Exam Contingency Plan

  • Safeguarding Policy

  • Mobile Phone Policy

May 2026, revised Sep 2026, next revision Sep 2027.


Discover more

If you would like to know more about life at IGS, or to book an in-person visit, contact us now.

Discover more

If you would like to know more about life at IGS, or to book an in-person visit, contact us now.