Updated March 2025

Cybersecurity remains a critical concern for organisations, especially those handling sensitive learner data and assessment materials. With the increasing frequency and sophistication of cyber threats, it is essential for Centres to remain vigilant and take proactive measures to protect their systems and information.

The Growing Threat of Cybercrime

Recent research commissioned by NatWest in October 2024 highlights the critical need for ongoing vigilance, revealing that 42% of British adults have been targeted by scammers in the past 12 months. The education sector is particularly vulnerable, with cybercriminals targeting institutions due to the sensitive data they hold.

The National Cyber Security Centre (NCSC) has published several advisories on the heightened risk of cyberattacks. It is strongly recommended that Centres review their security measures and ensure adequate safeguards are in place.

Useful Guidance from the National Cyber Security Centre (NCSC)

The National Cyber Security Centre (NCSC) offers valuable resources to help organisations protect their data, including:

For the latest updates, Centres are encouraged to subscribe to various topics, including threats and advisories.

Additional Cybersecurity Resources

In addition to the core guidance provided by the NCSC, Centres can benefit from a range of news articles, research papers, and best-practice recommendations, including:

Reporting Cyberattacks

We would like to remind our Centres that under the Centre Agreement, both parties must notify each other within 24 hours of any cyberattack experienced. This is particularly important when there is any risk of personal data or system access being compromised. As joint data controllers, this reciprocity protects both parties and ensures we work together towards a resolution that does not adversely affect learners.

If you have experienced a cyber incident, please report it immediately via your designated Centre contact or through our online reporting system.

Cybersecurity Training and Qualifications

Educating staff and learners about cybersecurity can significantly reduce risks. Centres may want to integrate cybersecurity training into their curriculum using regulated qualifications, such as:

Level 1 Award in Cybersecurity  Level 2 Award in Cybersecurity

These qualifications offer several benefits, including:

  • Fully funded (subject to learner eligibility),
  • No final external assessment – portfolio-based achievement,
  • Standalone regulated qualification,
  • Can be embedded into various curriculum areas,
  • Covers essential topics relevant to today’s cybersecurity landscape.

For more details on these qualifications, speak to the Business Development team at 01206 911 240 or contact us online.

Further Guidance and Best Practices