Cyber Security
Cyber Security Policy
The Independent Grammar School: Durham
1. Purpose
The Independent Grammar School: Durham (IGS: Durham) is committed to protecting its digital systems, safeguarding sensitive information, and ensuring the secure delivery of teaching, learning, and examinations. This policy sets out the standards and behaviours required to maintain a secure cyber environment, meet applicable requirements under the Data Protection Act 2018, UK GDPR and current JCQ and awarding-body regulations, and support the school’s safeguarding responsibilities under Keeping Children Safe in Education. It takes account of the DfE’s current digital and technology standards and relevant NCSC guidance.
Scope
This policy applies to:
All staff, students, directors, volunteers, contractors, and third-party providers
All school-owned devices, networks, cloud services, and digital platforms
Personal devices used for school purposes
All digital data, including student records, safeguarding information, exam materials, and operational data
Roles and Responsibilities
Principal
The Principal has overall responsibility for the implementation of this policy.
Board
The Board provides strategic oversight of cyber-security risks and receives assurance from the Principal that appropriate controls, training and response arrangements are in place. A designated Board member oversees cyber security and filtering and monitoring.
Designated Safeguarding Lead
The DSL leads on the safeguarding implications of cyber security and online safety, including filtering and monitoring. The DSL works with the Principal and IT support to review relevant reports and ensure that identified safeguarding concerns are acted upon promptly.
IT Support
The school’s designated external IT support is responsible for maintaining technical security controls, applying security updates, managing access permissions and backups, and supporting incident investigation and recovery.
All Staff
Follow this policy and all related procedures
Protect passwords, devices, and sensitive data
Report suspicious activity immediately
Students
Use school systems responsibly
Follow digital safety rules and exam-related cyber-security requirements
Report concerns to a member of staff
Cyber Security Principles
Access Control
Strong passwords must be used on all accounts
Multi-factor authentication (MFA) is required where available
Access to sensitive data is granted on a “least privilege” basis
Staff must lock screens when leaving devices unattended
Access permissions must be reviewed regularly and removed promptly when no longer required
Device Security
All school devices must use approved antivirus and endpoint protection
Personal devices used for school work must meet minimum security standards
Unauthorised software installations are prohibited
USB storage devices are restricted and encrypted where permitted
Operating systems and applications must remain supported and receive security updates promptly, with urgent vulnerabilities prioritised
Network Security
The school network is monitored for unusual activity
Firewalls and filtering systems must remain active at all times
Remote access is permitted only through secure, approved methods
Appropriate filtering and monitoring must cover staff and pupil use of school systems. Safeguarding alerts must be referred promptly to the DSL
Data Protection
Sensitive data must be stored in secure, approved systems
Emailing personal or confidential data must use encryption or secure transfer
Data must not be stored on unencrypted personal devices
Staff must follow the school’s Data Protection Policy
Backup and Recovery
Important school data must be backed up securely, with a protected copy separated from the live system. Restoration arrangements must be tested regularly
Cyber Security in Examinations
Secure Storage of Digital Exam Materials
Digital exam papers, audio files, and computer-based assessments must be stored in encrypted, access-restricted locations
Only authorised exam officers and designated staff may access digital exam content
Downloading exam materials onto personal devices is strictly prohibited
Computer Based Examinations
Exam workstations must be isolated from the internet unless explicitly permitted by the awarding body
Devices must be checked for malware, unauthorised software, and connectivity risks before each exam session
Students must use school-provided accounts configured for exam conditions
Auto-save and secure backup systems must be enabled to prevent data loss
Preventing Malpractice
Students must not access messaging apps, cloud storage, or unauthorised software during exams
Staff must ensure no digital devices (phones, smartwatches, earbuds) are brought into exam rooms
Any attempt to access restricted materials or communicate digitally during exams will be treated as malpractice
Handling Exam Scripts and Files
Digital scripts must be uploaded using secure awarding-body portals
Staff must not store exam scripts on personal devices or email accounts
Digital exam files must be retained for the period required by current JCQ and awarding-body instructions and then deleted securely
Cyber Security During Exam Emergencies
In the event of:
Network failure
Device malfunction
Cyber-attack
Power outage
The Exams Officer will implement the Exam Contingency Plan, ensuring:
Immediate safeguarding of student work
Secure transfer or recovery of files
Communication with awarding bodies
Staff Training and Awareness
All staff must complete annual cyber-security training covering:
Phishing and social engineering
Password hygiene
Safe data handling
Secure exam administration
Incident reporting procedures
The school will maintain a cyber awareness plan covering staff training, age-appropriate pupil education and acceptable use of technology. At least one designated Board member will complete annual cyber-security training. Training and awareness activities will be recorded.
Incident Reporting and Response
Reporting
All suspected cyber incidents must be reported immediately to the Principal and designated IT support. The DSL must also be informed immediately where an incident has safeguarding implications. Incidents include:
Phishing attempts
Unauthorised access
Lost or stolen devices
Malware infections
Exam-related digital breaches
Response
The school will:
Contain the incident
Preserve evidence
Notify affected individuals where required
Report to external agencies (e.g., ICO, Police) when appropriate
Review and strengthen controls
Assess and record any personal data breach, notifying the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, affected individuals must be informed without undue delay
Third Party Services and Cloud Platforms
Only approved platforms may be used for storing or processing school data
Contracts must include data-processing and breach-notification clauses
Monitoring and Review
The school monitors network activity, system logs, and security alerts
This policy is reviewed annually or following a significant incident
Findings from audits or incidents will inform future improvements
A documented cyber risk assessment will be completed annually, reviewed each term, and reconsidered following significant changes or incidents. Actions, responsible persons and timescales will be recorded and significant risks reported to the School Board
Filtering and monitoring provision will be reviewed and documented at least once every academic year by the Principal, DSL, designated Board member and IT support, including checks of effectiveness and consideration of emerging risks
Cyber incident response and recovery arrangements will form part of the school’s business continuity planning and will be tested regularly
Related Policies
Data Protection Policy
Online Safety Policy
Exam Contingency Plan
Safeguarding Policy
Mobile Phone Policy
May 2026, revised Sep 2026, next revision Sep 2027.
Cyber Security Policy
The Independent Grammar School: Durham
1. Purpose
The Independent Grammar School: Durham (IGS: Durham) is committed to protecting its digital systems, safeguarding sensitive information, and ensuring the secure delivery of teaching, learning, and examinations. This policy sets out the standards and behaviours required to maintain a secure cyber environment, meet applicable requirements under the Data Protection Act 2018, UK GDPR and current JCQ and awarding-body regulations, and support the school’s safeguarding responsibilities under Keeping Children Safe in Education. It takes account of the DfE’s current digital and technology standards and relevant NCSC guidance.
Scope
This policy applies to:
All staff, students, directors, volunteers, contractors, and third-party providers
All school-owned devices, networks, cloud services, and digital platforms
Personal devices used for school purposes
All digital data, including student records, safeguarding information, exam materials, and operational data
Roles and Responsibilities
Principal
The Principal has overall responsibility for the implementation of this policy.
Board
The Board provides strategic oversight of cyber-security risks and receives assurance from the Principal that appropriate controls, training and response arrangements are in place. A designated Board member oversees cyber security and filtering and monitoring.
Designated Safeguarding Lead
The DSL leads on the safeguarding implications of cyber security and online safety, including filtering and monitoring. The DSL works with the Principal and IT support to review relevant reports and ensure that identified safeguarding concerns are acted upon promptly.
IT Support
The school’s designated external IT support is responsible for maintaining technical security controls, applying security updates, managing access permissions and backups, and supporting incident investigation and recovery.
All Staff
Follow this policy and all related procedures
Protect passwords, devices, and sensitive data
Report suspicious activity immediately
Students
Use school systems responsibly
Follow digital safety rules and exam-related cyber-security requirements
Report concerns to a member of staff
Cyber Security Principles
Access Control
Strong passwords must be used on all accounts
Multi-factor authentication (MFA) is required where available
Access to sensitive data is granted on a “least privilege” basis
Staff must lock screens when leaving devices unattended
Access permissions must be reviewed regularly and removed promptly when no longer required
Device Security
All school devices must use approved antivirus and endpoint protection
Personal devices used for school work must meet minimum security standards
Unauthorised software installations are prohibited
USB storage devices are restricted and encrypted where permitted
Operating systems and applications must remain supported and receive security updates promptly, with urgent vulnerabilities prioritised
Network Security
The school network is monitored for unusual activity
Firewalls and filtering systems must remain active at all times
Remote access is permitted only through secure, approved methods
Appropriate filtering and monitoring must cover staff and pupil use of school systems. Safeguarding alerts must be referred promptly to the DSL
Data Protection
Sensitive data must be stored in secure, approved systems
Emailing personal or confidential data must use encryption or secure transfer
Data must not be stored on unencrypted personal devices
Staff must follow the school’s Data Protection Policy
Backup and Recovery
Important school data must be backed up securely, with a protected copy separated from the live system. Restoration arrangements must be tested regularly
Cyber Security in Examinations
Secure Storage of Digital Exam Materials
Digital exam papers, audio files, and computer-based assessments must be stored in encrypted, access-restricted locations
Only authorised exam officers and designated staff may access digital exam content
Downloading exam materials onto personal devices is strictly prohibited
Computer Based Examinations
Exam workstations must be isolated from the internet unless explicitly permitted by the awarding body
Devices must be checked for malware, unauthorised software, and connectivity risks before each exam session
Students must use school-provided accounts configured for exam conditions
Auto-save and secure backup systems must be enabled to prevent data loss
Preventing Malpractice
Students must not access messaging apps, cloud storage, or unauthorised software during exams
Staff must ensure no digital devices (phones, smartwatches, earbuds) are brought into exam rooms
Any attempt to access restricted materials or communicate digitally during exams will be treated as malpractice
Handling Exam Scripts and Files
Digital scripts must be uploaded using secure awarding-body portals
Staff must not store exam scripts on personal devices or email accounts
Digital exam files must be retained for the period required by current JCQ and awarding-body instructions and then deleted securely
Cyber Security During Exam Emergencies
In the event of:
Network failure
Device malfunction
Cyber-attack
Power outage
The Exams Officer will implement the Exam Contingency Plan, ensuring:
Immediate safeguarding of student work
Secure transfer or recovery of files
Communication with awarding bodies
Staff Training and Awareness
All staff must complete annual cyber-security training covering:
Phishing and social engineering
Password hygiene
Safe data handling
Secure exam administration
Incident reporting procedures
The school will maintain a cyber awareness plan covering staff training, age-appropriate pupil education and acceptable use of technology. At least one designated Board member will complete annual cyber-security training. Training and awareness activities will be recorded.
Incident Reporting and Response
Reporting
All suspected cyber incidents must be reported immediately to the Principal and designated IT support. The DSL must also be informed immediately where an incident has safeguarding implications. Incidents include:
Phishing attempts
Unauthorised access
Lost or stolen devices
Malware infections
Exam-related digital breaches
Response
The school will:
Contain the incident
Preserve evidence
Notify affected individuals where required
Report to external agencies (e.g., ICO, Police) when appropriate
Review and strengthen controls
Assess and record any personal data breach, notifying the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, affected individuals must be informed without undue delay
Third Party Services and Cloud Platforms
Only approved platforms may be used for storing or processing school data
Contracts must include data-processing and breach-notification clauses
Monitoring and Review
The school monitors network activity, system logs, and security alerts
This policy is reviewed annually or following a significant incident
Findings from audits or incidents will inform future improvements
A documented cyber risk assessment will be completed annually, reviewed each term, and reconsidered following significant changes or incidents. Actions, responsible persons and timescales will be recorded and significant risks reported to the School Board
Filtering and monitoring provision will be reviewed and documented at least once every academic year by the Principal, DSL, designated Board member and IT support, including checks of effectiveness and consideration of emerging risks
Cyber incident response and recovery arrangements will form part of the school’s business continuity planning and will be tested regularly
Related Policies
Data Protection Policy
Online Safety Policy
Exam Contingency Plan
Safeguarding Policy
Mobile Phone Policy
May 2026, revised Sep 2026, next revision Sep 2027.

Discover more
If you would like to know more about life at IGS, or to book an in-person visit, contact us now.

Discover more
If you would like to know more about life at IGS, or to book an in-person visit, contact us now.