Tuesday, 26 September 2017

Demystifying Tech: Data breaches

Image of Author

by Will Earp

Will is Digital Experience Manager at SWGfL, he manages the organisations digital output, and specialises in full stack web development

Coming off the back of one of the biggest data breaches in history, it seems not a month goes by without another report of some big hack where millions of customer details have been stolen. It can feel like it is inevitable or par for the course that you could also be hacked at some point.

But with greater responsibility on schools to ensure they have robust data protection systems in place, we must not accept this. These breaches should serve as a warning for us to take action to make sure we are not the next target. So what is a data breach? Who causes them and why? And what can we do to protect ourselves?

In this blog we’ll be looking at what data breaches are, how they happen and what you should be doing to protect your organisation from them.

What constitutes a data breach?

In the new world of fast moving tech, making data globally available at the click of a mouse has obvious advantages, but of course storing and managing vast amounts of personal data comes with risk. As the custodian of potentially valuable personal data, the buck stops with the holder to make sure that only authorised people can access that data.

A data breach occurs when an unauthorised person or persons gain access to the data by exploiting a flaw in the system, or by tricking users into giving them access, at which point they extract a large volume of data out of the system. They will then use this data to their own ends, either to gain financially by selling the data, or to expose the fact that the data custodians didn’t have sufficient security protections in place to stop them doing it.

Who are the hackers and why do they hack?

There are generally two types of hackers, known as white-hat or black-hat hackers.

White-Hat Hackers

Otherwise known as ethical hackers, this group usually consists of security researchers who work for universities or commercial cybersecurity companies, also concerned citizens who have enough technical knowledge to spot vulnerabilities in computer systems.

Their aim is to help the custodians of data to keep that data secure and improve their handling processes. Unfortunately some organisations don’t like these hackers testing the security of their systems, or simply do not take their warnings seriously. So being able to prove that the breach is real is often very helpful in making the data holders do something about it.

Upon discovering a vulnerability, most white-hat hackers, depending on how they think the news will be taken, will notify the system owners of the vulnerability. If the response is not satisfactory or is ignored, they will test the issue further, build something that will exploit the weakness, and extract enough data to prove their point.

This will normally not be used to extract as much data as possible, but just enough to show to the organisation that their system is vulnerable. This may be accompanied by notification that the exploit will be revealed publically within a certain time frame, so the data owners have time to fix it before it can be exploited by anyone else.

Black-Hat Hackers

This is the type of hacker that we should all be taking the necessary steps to protect ourselves from. Black Hat hackers are individuals or hacking groups, who hack for money, power or both. Personal data is extremely valuable if you can find the right buyer, as it can be used to generate more cash.

Stolen login details can be used to access data in other systems where the same password has been used, enabling the harvesting of more personal information, ultimately ending up in identity theft, blackmail, and theft. If somebody gains access to your credit card information along with other personal data, they can steal money from you, your bank, or credit agencies. And there are many other ways your data can be exploited for money.

When hackers discover a vulnerability in your system, they will immediately test and explore them and build something to exploit them. The code or methodology will then be sold to third parties for exploitation, or as much data as possible will be extracted. This will then be sold on the black market, usually a forum on the Dark Web (A hidden anonymous internet only accessible through the Tor Network).

Where it becomes extremely dangerous is if unrestricted access to your system can be valuable over time, to monitor your users or steal from you over time.

How do they steal the data?

Whenever you use a system, for example a school computer, that collects, manages, and serves data, there will be tens to hundreds of millions of lines of code in place to run it.

With such a large volume of code it is inevitable that it will contain bugs, logic errors, and architectural errors that enable the flow of the program to be manipulated to reveal more data or access than it should. How data is mishandled is tested by hackers, who input different pieces of data to see what happens, looking for somewhere where the input is mishandled and can be exploited. The process to gain access may take a number of steps, and so this may be written into a piece of code to automate the process.

On the flipside this is the same methodology used to hack computers through a web browser. Hackers test different pieces of code to see how the browser responds, looking for errors. Once found they build a piece of code that uses this vulnerability to gain access to your computer when you visit a webpage set up by the hacker. This is usually used to install other dangerous software on your computer so they can steal details like bank logins.

What can we do to protect ourselves?

There are a number of simple steps you can take, and processes you can put in place to prevent attacks in the first place, and limit the damage should a data breach occur:

Keep software up to date

Keeping your software up to date is critical for mitigating security vulnerabilities, especially known exploits.

Security researchers notify software vendors of vulnerabilities every day, those vendors then patch their software in the next release. After the update is released, the vulnerability will be made public through a database, at which point a black-hat hacker could build an exploit for use against unpatched systems. So if you don’t have the latest software, you’re more likely to be vulnerable to an attack.

Make good passwords

Use strong passwords, the longer you password is, the harder it is to crack if your personal data is stolen. Don’t use any words or dates personal to you as this can massively reduce the security of your password. Best to use something random but easy to remember.

Don’t reuse passwords across multiple systems, as if one of those systems is hacked, it could lead to attackers gaining access to your other accounts.

Never use accounts that get shared across multiple people, if something goes wrong you won’t know who is to blame, and you will have to update everyone with new details should one person’s access need to be revoked.

For more in-depth advice on password management, read The Secret to Secure Passwords, a blog I wrote recently for SWGfL.

Develop data management policy within your organisation

It is critical that everyone in your organisation is reading from the same hymn sheet when it comes to data security. A tool such as 360data can help you to develop policies and procedures around data protection, enabling your organisation to reduce attack vectors, and know what to do if a data breach occurs.

What can I do?

If you’re not already a user of 360data, now may be a good time to sign up and access good-quality advice and guidance from SWGfL, partners in the UK Safer Internet Centre.

Other steps include:

  • Ensure you have an up-to-date backup available (and have tested it)
  • Update your Windows installation
  • Keep your anti-virus up-to-date
  • Be cautious, don’t click on links in emails – do you know the sender?

For more information on how to protect your organisation, please visit 360data.org.uk and sign-up or take our FREE 30-second quiz.



from RSSMix.com Mix ID 8239594 https://www.saferinternet.org.uk/blog/demystifying-tech-data-breaches
via IFTTT

source https://professionalsafetysurface.tumblr.com/post/165762276597

Monday, 25 September 2017

76% of girls are confident in their digital skills

New research from Girlguiding looks at the experiences that girls have in their everyday lives, both online and offline.

A total of 1,906 girls and young women aged between 7 and 21 took part in the girls’ attitude survey from the across the UK, from both inside and outside Girlguiding.

Digital skills and careers in tech

The research found that 76% of girls have confidence in their digital skills. Encouragingly the survey also found that 69% of girls aged 7 to 21 aren’t put off from jobs in tech by a lack of women in the industry.

However, the survey also revealed the barriers that many girls face, with 30% of girls aged 11 to 16 saying that they think computing is more for boys.

One girl aged 11-16 said that

“more girls would be encouraged into tech if you destroyed the stereotype that only boys can use technology loads of girls already use and have jobs in tech, they’re just not talked about enough”.

Schools can provide a variety of opportunities for female students to be involved in different aspects of computing. From YouTube vlogging, to coding, and competitions such as Apps for Good, there is a huge scope of experiences that young people can get involved in.

Upsetting experiences online

The report also explored the negative experiences that girls can face online.

The survey revealed that 48% of girls aged 11-16 years have come across unwanted violent or graphic images online that made them feel upset or disturbed.

These findings echo the UK Safer Internet Centre’s  Power of Image report, published for Safer Internet Day 2017, which explored the risks and pressures that many young people face with image and video sharing.

The Safer Internet Day research also highlighted the positive role that images and videos can play, finding that in the last year, 4 in 5 children aged 8-17 years (80%) said they had been inspired by an image to do something positive.  

It also found that more than 2 in 3 (67%) said that in the last year they have posted an image or video on the internet for a positive reason, including to support friends (40%), to share something interesting with others (31%) and to encourage others to do something positive (17%).

Online empowerment

It is essential that we empower all young people to harness the positive opportunities offered by digital technology, while empowering and supporting them to navigate any risks and pressures they may face.

There are a range of resources available to support schools with this, including:

Read the full girls’ attitude survey here



from RSSMix.com Mix ID 8239594 https://www.saferinternet.org.uk/blog/76-girls-are-confident-their-digital-skills
via IFTTT

source https://professionalsafetysurface.tumblr.com/post/165728754012

Friday, 22 September 2017

Internet Watch Foundation wins ICT Excellence award

The Internet Watch Foundation (IWF), wins prestigious award for its work in removing child sexual abuse imagery online.

IWF collecting WITSA award

We are delighted to announce that the Internet Watch Foundation (IWF), one of the partners in the UK Safer Internet Centre, has been given the Public Sector Excellence Award by the World Information Technology and Services Alliance (WITSA) at their 2017 Global ICT Excellence Awards.

What is the WITSA?

WITSA is a leading consortium of ICT industry association members from over 80 countries and economies around the world, representing more than 90 percent of the world ICT market from which the winners were picked.

techUK, which represents and provides tech advice to companies and technologies in the UK nominated the IWF for the award for its huge leaps forward in erasing child sexual abuse content from the internet over the past 20 years.

There were seven award categories including Public Sector, Private Sector, Digital Opportunity, Sustainable Growth, Mobile Excellence, Innovative eHealth Solutions and WITSA Emerging Digital Solutions. Non-profit organisations and government entities from around the world were eligible to be nominated in the Public Sector Excellence category.

Why the IWF won

One of the key components for the IWF winning the award was its work turning child sexual abuse images into unique codes, also known as hashes.

Hashes allow the charity’s members to automatically remove an indecent image of a child as soon as it’s matched with an image on the IWF Hash List – even before it has the chance to appear on the member’s services. This breakthrough in 2015 was a game-changer for the charity, which also continues to assess thousands of reports of online child sexual abuse material from the public every week.

It also has implemented a number of reporting portals internationally so people around the world can report online child sexual abuse material.

Susie Hargreaves OBE, IWF’s CEO, said:

“We are absolutely delighted to have been awarded this year’s prestigious Public Sector Excellence Award by WITSA and we can’t thank techUK enough for nominating us.

“To win the award symbolises the achievements that the IWF and our partners, across the world, have made in tackling the issue of online child sexual abuse imagery.

“In today’s world, a child can be sexually abused on one continent and that abuse can be recorded, stored and shared from another. Offenders across the world can then view the images of the abuse, and this can all happen in a matter of minutes. The internet doesn’t respect borders. It is only through working together that we can tackle this truly global problem.”



from RSSMix.com Mix ID 8239594 https://www.saferinternet.org.uk/blog/internet-watch-foundation-wins-ict-excellence-award
via IFTTT

source https://professionalsafetysurface.tumblr.com/post/165629452632

Thursday, 21 September 2017

Helping schools fulfil filtering and monitoring requirements

Image of Author

by David Wright

David is a Director of the UK Safer Internet Centre at the South West Grid for Learning. He has worked extensively in the area of online safety for many years with children, schools and the wider community.

David Wright, Director of SWGfL and the UK Safer Internet Centre, discusses how we're helping schools fulfil their safeguarding duties by ensuring appropriate levels of monitoring and filtering.

Since July 2015 schools in England and Wales have had the obligation “to ensure children are safe from terrorist and extremist material when accessing the internet in school. This includes by establishing appropriate levels of filtering"[1]. 

For schools in England, this obligation was extended in September 2016 through ‘Keeping Children Safe in Education’ to include that “appropriate monitoring systems are in place”.

This year, schools in Scotland are expected to “have policies in place relating to the use of IT and to use filtering as a means of restricting access to harmful content.”[2]

What is ‘appropriate’?

Given that these expectations are now in place, along with knowledge that no filtering system is 100% effective, it is understandable why one of the most common questions posed to the Professionals Online Safety Helpline is ‘what is appropriate?’.

To help address this we have developed a response template for school broadband providers, and for filtering and monitoring providers.

The templates look at what constitutes ‘appropriate’ levels of filtering and monitoring and enables providers to self-certify their solutions in relation to specific areas, such as preventing access to inappropriate content.

When developing the definitions, the particular challenge was to produce a framework that would work for all schools, their context, environment, risk and users. 

We have recently started to publish these responses and will continue to do so as we receive them. You can find these responses here.

So why did we do this?

 The aim of these templates was to empower schools to make informed decisions about what filtering and monitoring systems they use, especially when faced with persuasive marketing materials.

It was through the response templates that we aimed to provide:

  • Schools with aspects to consider of their current, or future, filtering (and monitoring) provider; the features and performance of the solution in use. 
  • Providers with a framework in which to help describe their solutions together with the opportunity to develop innovative features and services.

The recognition and importance of these definitions is reflected within Keeping Children Safe in Education; the DfE’s statutory guidance document.

We welcome comments and feedback on these definitions and will be looking to update these on an annual basis.

[1] Revised Prevent Duty Guidance: for England and Wales, 2015.

[2] Scottish Government national action plan on internet safety



from RSSMix.com Mix ID 8239594 https://www.saferinternet.org.uk/blog/helping-schools-fulfil-filtering-and-monitoring-requirements
via IFTTT

source https://professionalsafetysurface.tumblr.com/post/165580221712

Tuesday, 19 September 2017

Online Safety Live kicks off

Image of Author

by David Wright

David is a Director of the UK Safer Internet Centre at the South West Grid for Learning. He has worked extensively in the area of online safety for many years with children, schools and the wider community.

Online Safety Live is the UK’s largest online safety professional development programme for the children’s workforce and this week we set off again for another year.

Delivered by the specialists at SWGfL, this coming year Online Safety Live will see more than 40 events delivered right across the UK, each providing delegates with all the latest online safety information, research, resources and tools within the two hour session. It doesn’t stop there either, as all delegates are provided with course content and further reading to build their own knowledge and skills.

Online Safety Live events are free to attend, made possible thanks to the kind support from BT, Sky, Virgin and TalkTalk, as well as those who kindly donate the use of venues, our partners from Welsh and Scottish Governments and co-presenters C2K.

Since starting in 2013, Online Safety Live has gone from strength to strength. We’ve delivered a grand total of 311 events and trained 12,112 members of the children’s workforce. Every one of these sessions has been delivered by the specialist team at SWGfL. The amazing team draws specialists from across education, law enforcement, industry and child protection, ensuring that the information is always relevant and bang up to date.

What’s in it for you?

Positive impact on the children’s workforce and better outcomes for children:

The feedback from 4,951 evaluations has been considerable and extraordinary:

  • 96% said that they are likely to educate children to stay safe online
  • 99% said they will share with their colleagues
  • 98% said they were better equipped to manage online safety

Positive impact for the whole of the UK:

One of the most important aspects of the programme is that it is delivered in venues across the country, from large purpose built theatres to small community halls. Providing access to this information in small rural areas is as important as large audiences. The entire children’s workforce has the right to access information on how to educate and protect young people online.

To find and book your free place at an Online Safety Live event near you visit www.onlinesafetylive.com



from RSSMix.com Mix ID 8239594 https://www.saferinternet.org.uk/blog/online-safety-live-kicks
via IFTTT

source https://professionalsafetysurface.tumblr.com/post/165514469712

Monday, 18 September 2017

Back to School - Top tips for supporting young people in the new academic year

In this blog, Kat Tremlett – Professionals Online Safety Helpline practitioner, looks at the importance of teachers taking a step back amid the mayhem of the new academic year and thinking about young people’s mental wellbeing. She also offers some top tips from the Professionals Online Safety Helpline.

Recent research shows that 91% of young people aged 16-24 use social networks and that the use of these services is associated with increased rates of anxiety (#statusofmind). I’d hazard a guess that six weeks off = a LOT of time spent online. I for one know how easy it is to search for something obscure and fall into a black hole of weird and wonderful content. Before you know it half the day’s gone by and nothing’s been done!

The point is, as an adult I have learnt how to self-regulate (well some of the time) and know when enough is enough for me. Young people are still working this out and won’t necessarily be able to control their impulsive nature to keep watching.

Of course there are positive effects of social media too, such as users reporting being more emotionally supported through their contacts online (another finding of #statusofmind), But it’s worth taking a moment to step back from the mayhem that is the beginning of a new school year and think about your pupils’ mental wellbeing.

Here are some top tips if something’s concerning you:

Have a conversation

Time moves on but talking about behaviour is still the best way to address any worries you may have. Talk with young people about your concerns and involve them in the outcome of any discussions. Where possible, respect what they want to happen and let them know you want to help.

Current affairs

The local media can be great for spur of the moment debates; perhaps it’s a news story about grooming or a song in the charts with lyrics around misogyny.

Whatever the topic, open up discussions with young people about current affairs; give them a safe space to test their ideals and encourage them to think critically.

Trust your gut

If you have concerns, act now and inform your safeguarding lead. There is a time and place for subtlety and reasoning, but when it comes to young people’s safety, this is not it.

Focus on the behaviour, not the technology

Older generations often shy away from talking about online behaviour for fear of exposing their lack of knowledge about different platforms. The key thing is the life experience adults have, which is far more valuable than any technological solution.

Focusing on behaviour allows you, as an adult, to draw from your experience to provide the support a young person may need.

As SWGfL's Online Safety Director, Ken Corish, wrote in this blog:

“Our children are not born experts in online life. They may have an affinity for technology but they are still children with all of the inexperience and naivety that brings. It is our job to support those things, no matter in which aspect of their life they occur.”

Do some research

There are no expectations on adults to know the ins and outs of every game, app or website in order to protect young people. But by learning the basics about an app, you at least give yourself a better understanding of the potential risks. You may find our social media guides helpful.

Supervise them

Imagine this – you want to play a DVD to your year 9s that’s rated 15. What would be the next steps to take? Would you roll out the DVD player and leave the class to it? Probably not.

More likely that you would have checked with the parents of the children that they were OK with this and, also have checked the DVD to make sure there weren’t any scenes that would be too disturbing for the audience. Finally you’d supervise the viewing so that if any young person did find something a bit overwhelming, you’d be on hand to defuse the situation.

Social media is much the same. Young people need supervision and it’s everyone’s responsibility to be aware of what young people are doing online.

Ask for help

If you know that a young person is struggling online but don’t know what to do, contact the Professionals Online Safety Helpline for further advice and support. Open from 10am – 4pm Monday – Friday, practitioners will help professionals unpick and resolve issues wherever possible:

Phone 0344 381 4772 Email:helpline@saferinternet.org.uk



from RSSMix.com Mix ID 8239594 https://www.saferinternet.org.uk/blog/back-school-top-tips-supporting-young-people-new-academic-year
via IFTTT

source https://professionalsafetysurface.tumblr.com/post/165473719037

Friday, 15 September 2017

PHE launches Rise Above for Schools programme

Public Health England (PHE) has a new set of Personal, Social and Health Education (PSHE) resources, called Rise Above for Schools, to support secondary school teachers when promoting positive health, wellbeing and resilience among young people aged 11 to 16.

These lessons plans are to help secondary school teachers engage pupils with coping strategies for a variety of health and well-being issues, including the pressures they face online.

All Rise Above for Schools resources have been developed in collaboration with teachers and the PSHE Association. The resources have also received the PSHE Association’s Quality Mark. The resources include a range of techniques for teachers to employ to enable pupils to safely learn, explore and discuss coping strategies for dealing with issues, such as:

  • bullying and cyberbullying
  • alcohol use and smoking
  • positive relationships and friendships
  • exam stress
  • online and social media stress
  • body image in a digital world

Rise Above for Schools hosts exclusive content from key influencers including vloggers, Instagram stars, musicians, gamers and TV presenters. The audience of 11 to 16 year-olds co-created films, interactive videos, animations, quizzes and more on topics that really matter to them, such as social media, body image and online stress.

Download the Rise Above for Schools lesson plans on the School Zone at www.NHS.uk/riseabove/schools.



from RSSMix.com Mix ID 8239594 https://www.saferinternet.org.uk/blog/phe-launches-rise-above-schools-programme
via IFTTT

source https://professionalsafetysurface.tumblr.com/post/165377985132

Professional Safety Surface Installers

Lots of organisations have play ground graphics installed to help improve the appeal of the facility, enable the kids to have more fun, and...