A well thought-out plan gives you a structured approach to improving your security posture, identifying weaknesses, and ensuring a rapid response when an incident occurs. The goal is moving from reactive panic to proactive preparedness, and that starts with understanding exactly where you stand today, before building the plan and risk register that gets you further.
Step 1: Understand your cyber posture
Before you can improve your security, you need an honest, thorough evaluation of your existing measures, your vulnerabilities, and the risks you actually face.
For individuals, assess six areas:
- Digital inventory: document all your online accounts and delete unused ones to reduce your attack surface
- Password review: check password strength and uniqueness; use a password manager's audit feature and enable multi-factor authentication (MFA). Current guidance is to use passkeys.
- Privacy settings: check social media and app privacy configurations to limit unintended data sharing
- Device security: verify password protection, up-to-date antivirus software, automatic updates, and biometric controls
- Backup assessment: check the frequency and security of backups for your critical personal files
- Security awareness: honestly assess your ability to recognise phishing attempts and respond to suspected scams
For organisations, assess seven areas:
- Asset discovery: catalogue all hardware and software; maintain device loan agreements with staff
- Vulnerability assessments: run regular scans for security weaknesses
- Penetration testing: simulate attacks to evaluate how well your controls actually hold up
- Risk analysis: assess the potential impact and likelihood of identified threats
- Compliance audit: review adherence to industry regulations and data protection law
- Policy review: ensure security policies are comprehensive and properly implemented
- Employee assessment: measure awareness through surveys or simulated phishing campaigns
An honest, comprehensive assessment gives you a clear baseline, highlighting your strengths and, more importantly, pinpointing what needs immediate attention. This is the essential first step on the journey to stronger digital resilience, and it feeds directly into the risk register below.
Step 2: Build your risk register
A risk register turns "we should probably think about cyber risk" into an actual, prioritised list you can act on and revisit. For each risk identified in Step 1, record:
- The risk itself (e.g. "unpatched staff laptops," "no MFA on finance systems," "no tested backup for MIS data")
- Likelihood and impact, scored consistently so risks can be compared and ranked
- Current controls already in place
- Owner = who is responsible for managing this risk (tying back to the RACI roles from Day 5)
- Action and target date for closing the gap
- Review date: risk registers go stale fast if they're not revisited
Don't want to build this from scratch? We've put together a FREE, ready-to-use Cyber Risk Register for Schools & Multi-Academy Trusts covering all four risk categories above, with pre-written risk descriptions, impact statements, and control recommendations mapped to the DfE Standards, NCSC and ICO guidance: free to download throughout October.
This register is a starting point, not a finished one. The risks, levels and controls listed are generic examples. Review and adapt them in line with your own organisation's risk management approach, governance structure, and existing controls before adopting it as your formal register. Risk levels in particular should be reassessed against your own context rather than taken as given.
Step 3: Build your cyber action plan
Your action plan (Incident Response Plan / Cybersecurity Framework) brings the risk register to life.
For individuals:
- Password management: review important account passwords monthly or quarterly for strength and uniqueness, and enable MFA on key accounts, particularly email. Email is the key to all of your other accounts and where password resets are sent.
- Data backup protocol: choose a backup frequency (weekly external drive or daily cloud storage) and document your method.
- Privacy maintenance: schedule quarterly reviews of privacy settings.
- Software updates: keep a routine for checking and installing updates across all devices, including phones.
- Emergency contacts: keep an accessible list of banks, IT support, and authorities . Remember, legitimate banks won't ask for security details over the phone
- Continuous learning: dedicate time to learning one cyber security topic a month
Not sure where to start personally? Police CyberCheck is a free, police-run service offering step-by-step cybersecurity guidance for individuals and sole traders, based on NCSC guidance. It's built for personal accounts and devices rather than organisational systems, for the school or trust itself, the NCSC Cyber Action Toolkit is the equivalent starting point.
For organisations:
- Risk assessment: regularly identify and evaluate threats and vulnerabilities. This is where the risk register lives.
- Policy development: clear cyber security policies and procedures for staff (templates available through Data Protection Education)
- Employee training: ongoing security awareness training: the DfE Digital Standards mandate annual cyber security training for all staff and students
- Technical controls: firewalls, anti-malware software, MFA, and encryption, with leadership and governing bodies ensuring implementation as part of digital strategy
- Backup & recovery: robust backup procedures with regular testing. Not all data needs backing up, but what does needs testing
- Incident response procedures: documented steps for detecting, containing, eradicating, and recovering from an attack
- Regular testing: penetration testing, vulnerability scans, and tabletop exercises. The regional Cyber Resilience Centres offer affordable testing and free support for schools and colleges
It's a process, not a project
This isn't a one-time exercise, it's an ongoing process of assessment, improvement, and adaptation to the evolving threat landscape. Plan for protection now, rather than waiting for a breach to force the issue.
💡Your Daily Cyber Tip
Block out an hour in your calendar once a month. Use it for a "digital spring clean" . Spend 15 minutes on an old, unused account, either securing it with strong credentials or deleting it, plus checking for updates, testing a backup, or working through one entry on your risk register or action plan.
Simple cyber checklist
A quick maturity check worth running as an organisation: Have staff completed cyber security training? Anyone with network access should receive annual cyber security training covering passwords, data breaches, and information security: a baseline every school and trust should be able to answer "yes" to.
Where this sits in the DfE Digital & Technology Standards
This sits under Cyber Security and Digital Leadership & Governance: both expect schools and trusts to have a structured, maintained approach to managing cyber risk, not an ad-hoc one. For a wider view against national frameworks, see the NCSC Cyber Assessment Framework and The Government Cyber Action Plan.
