Mr Patsy McGlone (Mid Ulster): To ask the Minister of Education to detail (i) an update on the current cyber threat level facing schools, including (a) the types of cyber threats encountered; and (b) any significant incidents reported, within the last six months; (ii) any measures being implemented to address and mitigate these risks; and (iii) any consideration his Department has taken on whether schools have adequate resilience and contingency planning in place to respond to a major cyber incident. [Priority Written]
Minister of Education: The Education Authority (EA) provides the ICT infrastructure for schools (known as ‘C2k’) and has advised that:
Current cyber threat level (schools) – types of threats and incidents (last six months)
In common with other public and private sector organisations, the EA continues to observe a sustained and evolving cyber threat environment affecting the education sector. The most prevalent activity targeting school users and services includes phishing, malicious email attachments/links, business email compromise attempts, and opportunistic scanning of internet-facing services. Wider sector reporting also highlights ransomware and data-extortion activity as a persistent risk for education organisations. There have been no other significant incidents in the last six months.
(ii) Measures implemented to address and mitigate risks
C2k maintains a layered set of technical and operational controls designed to reduce risk across centrally provided services. These include, email and web security filtering; anti-malware protections; security monitoring and alerting; protective configuration and patching processes for managed services; account security controls and network protections for centrally managed infrastructure. C2k also provides guidance and communications to schools to support safe use of services and to reinforce user awareness of common threats such as phishing.
(iii) Resilience and contingency planning
C2k keep resilience and continuity arrangements under ongoing review, including backup and recovery capabilities for centrally managed services and documented incident management processes. C2k continues to work with relevant stakeholders to promote preparedness and to ensure that arrangements for responding to and recovering from major cyber incidents are tested and improved over time.
ENDS
