27 June, 2024
The Department for Education (DfE) states that protecting user accounts and related data is a critical defence against cyber incidents and attacks. In this article, we outline how your school, college or trust can meet the DfE’s cybersecurity standards when controlling and securing user accounts.
DfE sets out specific cyber security standards for schools and colleges in the UK. One of these standards focuses on controlling and securing user accounts and access privileges.
At Salamander, we’ve had 15+ years of provisioning and managing user accounts for schools, colleges and trusts, so we have created this guide, breaking down the standards set by DfE when it comes to securing your user accounts.

Cybersecurity has always been crucial for schools, colleges and multi academy trusts. However, in recent years, we have seen a dramatic rise in cyberattacks on the education sector:
The Cyber Security Breaches Report found:
As you can probably imagine, cyber incidents have a severely detrimental effect on schools, resulting in safeguarding issues, student outcomes, disruption to teaching and learning, financial loss and reputational damage.
What’s more, cyber incidents are not always carried out by an external group or organisation; they can be caused by accidents within your school or college.
Not meeting the DfE’s standard on controlling and securing user accounts and access could lead to your school:
The Senior Leadership Team (SLT) digital lead is accountable for meeting the DfE’s cybersecurity standards, and the school’s IT support (whether internal or external) is responsible for implementing them.
Your IT support will work with any digital technology suppliers, the data protection officer (DPO), whoever is responsible for movers, joiners and leavers and any other IT leads in your school or multi academy trust.

The SLT digital lead must agree on a plan with IT support on key elements of your user account management, such as who should access what, password policies and security features such as multi-factor authentication.
The DfE states all your school users must be authenticated with unique credentials before they access devices or services.
Your IT support must enforce password strength at the system level and the NCSC suggests using a three random word system or machine-generated passwords.
Any passwords that are compromised – or suspected to be – must be changed immediately.
Password protections should also be set, such as a limit to the number of login attempts before locking a device.
Of course, for younger children and some SEND and EAL users, alternatives to passwords may need to be used.
The DfE recommends PIN codes or a separate account accessed by the teacher using the student’s login so that the student can still be identified.
Meanwhile, networking devices and servers should use a password or PIN of at least 6 characters when physically accessing network switches and boot-up settings.
A process must be agreed upon with SLT and IT support on securing access to key system passwords and pins in the event of an emergency.

Senior leaders and staff must use multi-factor authentication (MFA) if working with confidential, financial, personal and sensitive data.
Of course, MFA may not always be accessible for SEND students and younger students, so you may need to discuss alternatives or extra support when logging in.
You may also want to consider MFA for cloud and online services, all staff accounts, and all student accounts (if verification does not need to be completed on a mobile phone).
MFA should include at least two of the following:
If MFA is not available, a more complex password should be used.

IT support must control user accounts and access privileges by:
The Salamander Integration Suite helps schools and trusts meet the DfE’s cybersecurity standards.
We automate all user account provisioning, integrating your MIS data with your systems and software. This means:

To summarise, here’s a checklist of responsibilities of IT support when securing user accounts in schools, colleges and trusts:
More resources:
Marketing and Social media
Courtney supports SalamanderSoft in creating engaging digital content for its website and social channels. Her content studio - Bloom Creative - specialises in heart-led copywriting for purpose-driven brands.