Skip to main content
10
MandatoryOnline Safety

Online Safety & Cyber Security

Mandatory training on online safety and cyber security for DASC staff, volunteers, and managers.

2h 30min~28 min readall-staff, managersAnnualv1.0 · Updated 1 July 2026

Course 10 – Online Safety & Cyber Security

DASC Standard

Technology creates opportunities for learning, communication and creativity.

It also creates risks.

Every member of staff has a responsibility to protect children, colleagues and DASC information from online harm and cyber threats.

Online safety is safeguarding.


Introduction

Technology forms part of everyday life.

Children may use:

  • tablets;
  • computers;
  • interactive displays;
  • educational websites;
  • digital learning platforms.

Staff also use technology to:

  • communicate;
  • record attendance;
  • access learning records;
  • complete safeguarding documentation;
  • manage personal data.

Using technology safely protects children, staff and the organisation.


Learning Outcomes

After completing this course you will be able to:

  • explain what online safety means;
  • recognise common cyber security risks;
  • protect children's personal information;
  • identify phishing and online scams;
  • create strong password habits;
  • report cyber incidents appropriately;
  • understand your responsibilities when using DASC technology.

Why Online Safety Matters

Poor cyber security can lead to:

  • data breaches;
  • identity theft;
  • safeguarding risks;
  • financial loss;
  • disruption to services;
  • reputational damage.

Children may also be exposed to:

  • inappropriate content;
  • online grooming;
  • cyberbullying;
  • scams;
  • harmful online behaviour.

Everyone has a role in reducing these risks.


DASC Best Practice

Think before you click.

Think before you share.

Think before you store.

Most cyber incidents begin with a single unsafe decision.


Ofsted Inspection Insight

Ofsted expects staff to understand that online safety forms part of safeguarding.

Inspectors may ask how staff protect children online, use technology safely and safeguard personal information.

Online safety should be embedded in everyday practice.


Reflection

Reflect before continuing.

  • How much personal information do you handle during a normal day?
  • Could a cyber attack affect children's safety?
  • What would you do if you received a suspicious email?
  • How does online safety support safeguarding?

Good cyber security begins with informed staff making safe decisions every day.


Understanding Online Risks

The internet provides valuable opportunities for learning, communication and creativity.

However, it also exposes children and organisations to a range of risks.

Understanding these risks helps staff protect both children and DASC systems.


The Four Areas of Online Risk

Online risks are commonly grouped into four categories.

RiskDescription
ContentExposure to harmful, inappropriate or illegal material
ContactHarmful interaction with other people online
ConductUnsafe or inappropriate online behaviour by users
CommerceFinancial scams, fraud, advertising and exploitation

Staff should understand all four areas when supporting children.


DASC Standard

Online safeguarding is not only about blocking harmful websites.

It is about teaching safe behaviour, recognising risks and responding appropriately.


Content Risks

Children may accidentally encounter:

  • violent material;
  • extremist content;
  • pornography;
  • misinformation;
  • hate speech;
  • harmful challenges;
  • age-inappropriate material.

Staff should supervise internet use and ensure only approved resources are used.


Contact Risks

Children may be contacted online by individuals who:

  • pretend to be children;
  • attempt grooming;
  • encourage secrecy;
  • request personal information;
  • arrange meetings;
  • exploit trust.

Children should never communicate online with unknown individuals during DASC activities.

Any safeguarding concerns must be reported immediately.


Conduct Risks

Children may unintentionally place themselves or others at risk through:

  • cyberbullying;
  • sharing personal information;
  • inappropriate messages;
  • offensive comments;
  • sharing images without permission;
  • unsafe online behaviour.

Online behaviour should reflect the same expectations as behaviour offline.


Commerce Risks

Children and adults may be targeted through:

  • fake competitions;
  • online scams;
  • phishing emails;
  • fraudulent websites;
  • in-app purchases;
  • subscription traps.

Staff should never enter DASC payment or personal information into unverified websites.


DASC Best Practice

Ask three questions before clicking any link:

  • Do I know who sent it?
  • Was I expecting it?
  • Does it look genuine?

If the answer to any question is no, stop and check first.


Age-Appropriate Technology

Technology used with children should always be:

  • suitable for their age;
  • educationally appropriate;
  • supervised;
  • secure;
  • approved by DASC.

Children should never have unrestricted internet access during club activities.


Digital Footprints

Everything shared online may leave a permanent record.

Staff should remember:

  • photographs;
  • comments;
  • emails;
  • messages;
  • uploaded documents;

may remain accessible long after they have been deleted.

Professional judgement should always guide online behaviour.


Safe Searching

Where children use the internet:

  • use child-friendly search tools where available;
  • supervise browsing;
  • use approved websites;
  • report inappropriate content immediately;
  • close unsuitable pages without drawing unnecessary attention.

Children should know they can always tell an adult if something online worries them.


Ofsted Inspection Insight

Inspectors may ask staff how they help children stay safe online.

They expect staff to understand online risks and respond appropriately to concerns rather than relying solely on technical filtering.


Practice Scenario – Unexpected Pop-Up

Inappropriate Website


Practice Scenario – Suspicious Competition

You've Won a Prize!


Manager Coaching Notes

Managers should ensure:

  • online filtering is appropriate;
  • staff receive annual cyber awareness training;
  • online incidents are reported;
  • children are supervised online;
  • approved digital resources are used;
  • cyber risks are reviewed regularly.

Good cyber security combines technology with informed staff.


Reflection

Reflect on today's learning.

  • Could you explain the four areas of online risk?
  • Would you recognise a phishing email?
  • How should staff respond if inappropriate content appears?
  • Why is supervision still important even when filtering is used?

Online safety is everyone's responsibility.

Every safe online decision helps protect children and DASC.


Protecting Personal Information

Every day, DASC staff handle personal information about children, families and colleagues.

Protecting this information is both a legal responsibility and an important part of safeguarding.

A data breach can place children, families and the organisation at significant risk.


What is Personal Information?

Personal information is any information that can identify a person directly or indirectly.

Examples include:

  • names;
  • addresses;
  • dates of birth;
  • telephone numbers;
  • email addresses;
  • attendance records;
  • photographs;
  • safeguarding records;
  • medical information;
  • assessment reports.

Some information, such as health and safeguarding records, requires an even higher level of protection.


DASC Standard

Only access information you need for your role.

Curiosity is never a lawful reason to view personal information.


Why Data Protection Matters

Good data protection:

  • safeguards children;
  • protects families' privacy;
  • maintains trust;
  • supports legal compliance;
  • protects DASC's reputation.

Poor data handling may result in:

  • safeguarding risks;
  • identity theft;
  • legal action;
  • financial penalties;
  • loss of confidence from parents.

Confidential Information

Confidential information should only be shared:

  • with authorised colleagues;
  • with safeguarding professionals where appropriate;
  • with parents where appropriate;
  • in accordance with DASC policies.

Never discuss confidential information:

  • in public places;
  • on public transport;
  • in front of other parents;
  • on social media.

Professional confidentiality continues outside working hours.


Using DASC Devices

When using DASC devices:

  • lock the screen when unattended;
  • log out after use;
  • keep software updated;
  • store devices securely;
  • report lost or stolen devices immediately.

Shared devices should never remain logged into personal accounts.


DASC Best Practice

If you walk away—

Lock the screen.

It takes only seconds and protects sensitive information.


Using Personal Devices

Where DASC permits the use of personal devices:

  • follow the Acceptable Use Policy;
  • avoid storing children's information locally;
  • use approved systems only;
  • enable screen locks;
  • protect devices with strong passwords.

Personal devices should never become unofficial storage locations for DASC records.


Sending Emails Safely

Before sending emails:

  • check the recipient carefully;
  • verify attachments;
  • avoid unnecessary personal information;
  • use secure systems where required.

A simple typing mistake can send confidential information to the wrong person.

Always pause and double-check before pressing Send.


Sharing Documents

When sharing documents:

  • share only what is necessary;
  • use approved systems;
  • avoid personal file-sharing accounts;
  • confirm recipients before sending.

The principle should always be:

Share the minimum information required.


Printing and Paper Records

Printed documents should be:

  • collected immediately;
  • stored securely;
  • shredded when no longer required;
  • kept away from public view.

Leaving confidential paperwork unattended creates unnecessary safeguarding risks.


Ofsted Inspection Insight

Inspectors expect staff to understand that protecting personal information forms part of safeguarding.

Safe information handling demonstrates professionalism, accountability and respect for children and families.


Practice Scenario – Wrong Email Address

Accidental Recipient


Practice Scenario – Unlocked Laptop

Quick Conversation


Manager Coaching Notes

Managers should ensure:

  • staff understand confidentiality;
  • devices remain secure;
  • data breaches are reported promptly;
  • staff follow approved systems;
  • paper records are protected;
  • regular data protection refresher training is provided.

Strong information security protects children, families and DASC.


Reflection

Reflect on today's learning.

  • Could you identify personal information?
  • Do you always lock your device before walking away?
  • How would you respond if confidential information was sent to the wrong person?
  • Why is data protection an important part of safeguarding?

Every piece of personal information belongs to someone who trusts DASC to protect it.

Professional care includes protecting that trust.


Passwords and Account Security

Passwords are one of the most important defences against cyber attacks.

Weak passwords can allow unauthorised access to sensitive information about children, families and DASC.

Strong account security helps protect safeguarding records, attendance systems and organisational data.


Why Password Security Matters

Cyber criminals often attempt to gain access by:

  • guessing weak passwords;
  • reusing passwords from previous data breaches;
  • sending phishing emails;
  • installing malicious software;
  • stealing login details.

A single compromised account can place the entire organisation at risk.


DASC Standard

Your password protects more than your account.

It protects children's personal information.

Treat it as confidential at all times.


Creating Strong Passwords

A strong password should:

  • be long;
  • be unique;
  • be difficult to guess;
  • avoid personal information;
  • not contain obvious words.

Avoid using:

  • children's names;
  • birthdays;
  • "password123";
  • "Welcome1";
  • the organisation's name.

Long passphrases are often easier to remember and more secure than short, complex passwords.


Multi-Factor Authentication (MFA)

Many DASC systems use Multi-Factor Authentication (MFA).

This means logging in requires:

  • something you know (your password); and
  • something you have (such as a phone or authentication app).

MFA provides an additional layer of protection if a password becomes compromised.

Never approve an authentication request that you were not expecting.


DASC Best Practice

If you receive an unexpected authentication request—

Reject it.

Then change your password and report the incident immediately.

Unexpected login requests may indicate that someone knows your password.


Never Share Passwords

Passwords should never be:

  • shared with colleagues;
  • written on sticky notes;
  • stored in notebooks;
  • emailed;
  • sent by text message;
  • shared over messaging apps.

Every user should have their own account.

Shared accounts reduce accountability and increase security risks.


Password Managers

Password managers help users:

  • generate strong passwords;
  • store passwords securely;
  • avoid password reuse;
  • improve overall security.

Where approved by DASC, password managers may be safer than attempting to remember dozens of passwords.


Locking Your Device

Whenever leaving a device unattended:

  • lock the screen;
  • close confidential documents where appropriate;
  • store portable devices securely.

Even a short conversation away from your desk may be enough for unauthorised access.


Logging Out

Always log out:

  • when using shared devices;
  • at the end of your shift;
  • before handing devices to another person.

Closing a browser window does not always sign you out.

Always log out properly.


Recognising Suspicious Login Activity

Possible warning signs include:

  • unexpected password reset emails;
  • login alerts from unfamiliar locations;
  • authentication requests you did not initiate;
  • accounts becoming locked unexpectedly.

Report concerns immediately.

Early reporting limits the impact of cyber incidents.


Ofsted Inspection Insight

Inspectors may not ask about password complexity, but they do expect organisations to protect children's personal information appropriately.

Strong cyber security supports effective safeguarding and demonstrates responsible leadership.


Practice Scenario – Shared Password

Can I Use Your Login?


Practice Scenario – Unexpected Login Alert

Was This You?


Manager Coaching Notes

Managers should ensure:

  • staff use strong passwords;
  • MFA is enabled where available;
  • password sharing is prohibited;
  • suspicious login activity is reported;
  • cyber awareness training is refreshed annually;
  • accounts are removed promptly when staff leave.

Strong account security is one of the simplest and most effective cyber defences.


Reflection

Reflect on today's learning.

  • Is every password you use unique?
  • Would you recognise a suspicious authentication request?
  • Why should passwords never be shared?
  • How does MFA improve security?

Good password habits protect far more than technology.

They help safeguard children, families and the information entrusted to DASC.


Phishing, Scams and Social Engineering

Most cyber attacks do not begin with sophisticated hacking.

They begin by persuading someone to make a mistake.

Criminals often target people rather than technology because people are easier to deceive than computer systems.

Recognising scams is one of the most important cyber security skills.


What is Phishing?

Phishing is an attempt to trick someone into revealing:

  • passwords;
  • banking information;
  • personal data;
  • security codes;
  • login credentials.

Phishing messages often appear to come from trusted organisations.

They may arrive by:

  • email;
  • text message;
  • telephone;
  • social media;
  • messaging applications.

DASC Standard

Never trust a message simply because it looks professional.

Always verify before responding.


Common Warning Signs

Be cautious if a message:

  • creates urgency;
  • threatens consequences;
  • requests confidential information;
  • contains unexpected attachments;
  • asks you to click a link;
  • contains unusual spelling or grammar;
  • comes from an unfamiliar sender.

One warning sign may not confirm a scam.

Several together should raise concern.


Social Engineering

Social engineering is when someone manipulates people into giving information or access.

Examples include:

  • pretending to be IT support;
  • impersonating a manager;
  • claiming to be a parent;
  • requesting passwords;
  • asking for confidential records.

Professional confidence and polite verification help prevent these attacks.


Telephone Scams

A caller may claim to be from:

  • Microsoft;
  • your bank;
  • the police;
  • DASC's IT provider;
  • another trusted organisation.

If asked for confidential information:

  • remain calm;
  • do not provide details;
  • verify the caller independently;
  • report the incident if appropriate.

Never rely solely on caller ID.


DASC Best Practice

If someone pressures you to act immediately—

Slow down.

Cyber criminals rely on panic.

Professional staff verify first and act second.


Before clicking a link:

  • consider who sent it;
  • check whether you expected it;
  • look carefully at the web address;
  • report suspicious emails if required.

Do not click links simply out of curiosity.


Attachments

Attachments may contain malicious software.

Never open unexpected attachments, especially if they ask you to:

  • enable macros;
  • install software;
  • log into an account;
  • bypass security warnings.

If unsure, verify with the sender using a trusted contact method.


QR Code Scams

QR codes can direct users to fraudulent websites.

Before scanning:

  • consider where the code came from;
  • verify it is genuine;
  • avoid scanning unknown public QR codes requesting personal information.

Treat QR codes in the same way as website links.


Reporting Suspicious Activity

If you receive a suspicious message:

  • do not respond;
  • do not click links;
  • do not open attachments;
  • report it to your manager or IT support;
  • follow DASC reporting procedures.

Early reporting protects everyone.


Ofsted Inspection Insight

Inspectors increasingly expect organisations to understand cyber risks because safeguarding now includes protecting children's personal information and digital systems.

Cyber awareness is part of modern safeguarding.


Practice Scenario – Fake IT Support

Urgent Password Reset


Practice Scenario – Urgent Payment Email

Immediate Action Required


Manager Coaching Notes

Managers should ensure:

  • phishing awareness is refreshed regularly;
  • suspicious emails are reported promptly;
  • staff know how to verify unusual requests;
  • cyber incidents are reviewed;
  • lessons learned are shared across the organisation.

Cyber security improves when everyone remains alert.


Reflection

Reflect on today's learning.

  • Could you recognise a phishing email?
  • Would you question an urgent request for confidential information?
  • How can social engineering affect safeguarding?
  • Why is reporting suspicious activity so important?

Most cyber attacks succeed because someone trusts the wrong message.

Professional curiosity is one of the strongest cyber defences.


Safe Use of Devices and Technology

Technology supports learning, communication and administration throughout DASC.

Whether using a desktop computer, laptop, tablet or mobile device, staff must ensure that technology is used safely, responsibly and professionally.

Every device used for DASC business should protect children's information and support safeguarding.


Using DASC Devices

DASC-owned devices should only be used for authorised purposes.

Staff should:

  • follow the Acceptable Use Policy;
  • keep devices secure;
  • report faults promptly;
  • install only approved software;
  • avoid personal use where prohibited.

Organisational devices contain valuable information and should always be treated responsibly.


DASC Standard

DASC technology exists to support children and the organisation.

Personal convenience should never compromise security.


Personal Mobile Phones

Personal mobile phones should only be used in accordance with DASC policies.

Staff should never:

  • photograph children using personal phones;
  • record videos of children;
  • store children's personal information;
  • communicate with children through personal accounts;
  • use personal messaging apps for official safeguarding matters unless specifically authorised.

Approved systems should always be used.


Tablets and Learning Devices

Children may use tablets or other digital devices for educational activities.

Staff should ensure:

  • activities are supervised;
  • children access only approved content;
  • devices are age appropriate;
  • internet filtering is active where applicable;
  • sessions remain purposeful.

Technology should enhance learning rather than replace meaningful interaction.


Software Updates

Updates often include important security improvements.

Where appropriate:

  • install updates promptly;
  • restart devices when requested;
  • avoid delaying security updates unnecessarily.

Outdated software is a common cause of cyber attacks.


DASC Best Practice

Updates fix vulnerabilities that criminals actively search for.

Keeping software updated is one of the simplest cyber security measures available.


Public Wi-Fi

Public wireless networks may be less secure than trusted networks.

When working away from DASC:

  • avoid accessing confidential information on unsecured public Wi-Fi;
  • use approved secure connections where available;
  • log out after use;
  • avoid downloading sensitive documents unnecessarily.

Always think about who else may be connected to the same network.


Physical Security

Devices should never be left:

  • unattended in public places;
  • visible inside unattended vehicles;
  • unlocked in shared areas;
  • accessible to unauthorised individuals.

Portable devices should be stored securely whenever not in use.


Using USB Devices

Only approved storage devices should be connected to DASC equipment.

Unknown USB devices may contain malicious software.

Never insert:

  • found memory sticks;
  • unapproved external drives;
  • unknown accessories.

If unsure, ask before connecting.


Remote Working

Where remote working is authorised:

  • use approved systems;
  • maintain confidentiality;
  • avoid discussing sensitive information where others may overhear;
  • secure printed documents;
  • lock devices whenever leaving your workspace.

Professional standards apply regardless of location.


Ofsted Inspection Insight

Inspectors increasingly expect organisations to demonstrate good digital governance.

Safe technology use protects children, supports safeguarding and reflects effective organisational leadership.


Practice Scenario – Personal Phone

Quick Photograph


Practice Scenario – Found USB Drive

Car Park Discovery


Manager Coaching Notes

Managers should ensure:

  • devices remain secure;
  • software updates are completed;
  • staff understand the Acceptable Use Policy;
  • personal device use complies with policy;
  • portable devices are encrypted where appropriate;
  • cyber security procedures are reviewed regularly.

Strong technology management protects children, staff and organisational information.


Reflection

Reflect on today's learning.

  • Could you explain why personal phones should not be used to photograph children?
  • How do software updates improve cyber security?
  • What would you do if you found an unknown USB drive?
  • How can physical security protect digital information?

Technology is only as secure as the people using it.

Every safe decision strengthens DASC's cyber security.


Responding to Cyber Incidents

Despite strong security measures, cyber incidents can still happen.

The speed and effectiveness of the response often determines how serious the impact becomes.

Every member of staff has a responsibility to recognise potential cyber incidents and report them immediately.

Prompt reporting protects children, colleagues and DASC.


What is a Cyber Incident?

A cyber incident is any event that threatens the confidentiality, integrity or availability of information or technology.

Examples include:

  • suspicious emails;
  • malware infections;
  • ransomware;
  • lost or stolen devices;
  • accidental disclosure of personal information;
  • unauthorised access to accounts;
  • data breaches;
  • compromised passwords.

Not every incident becomes a major breach—but every incident should be reported.


DASC Standard

Never hide a cyber mistake.

Early reporting protects children and allows problems to be resolved quickly.


Recognising Warning Signs

Possible indicators include:

  • unexpected password changes;
  • unusual pop-up messages;
  • slow or unusual computer behaviour;
  • files becoming inaccessible;
  • unfamiliar software appearing;
  • login alerts from unknown locations;
  • colleagues reporting unusual emails from your account.

Trust your instincts.

If something feels unusual, report it.


Immediate Actions

If you believe a cyber incident has occurred:

  • remain calm;
  • stop using the affected device if appropriate;
  • disconnect from the network if instructed;
  • inform your manager immediately;
  • follow DASC reporting procedures;
  • do not attempt to investigate independently.

Preserving evidence may help identify the cause.


DASC Best Practice

Report first.

Investigate later.

Trying to fix a cyber incident yourself may accidentally make the situation worse.


Data Breaches

A personal data breach occurs when personal information is:

  • lost;
  • stolen;
  • accessed without authorisation;
  • sent to the wrong person;
  • altered without permission;
  • accidentally destroyed.

Not every breach causes harm, but every breach should be assessed promptly.


Lost or Stolen Devices

If a DASC device is lost or stolen:

  • report it immediately;
  • provide as much information as possible;
  • avoid attempting to recover it yourself if unsafe;
  • follow management instructions.

Fast reporting increases the chance of protecting information remotely.


Malware and Ransomware

Malware is malicious software designed to damage or compromise systems.

Ransomware is a type of malware that encrypts files and demands payment.

If ransomware is suspected:

  • stop using the device;
  • disconnect it if instructed;
  • report immediately;
  • never pay a ransom yourself.

Professional advice should always be sought.


Learning from Incidents

Every cyber incident provides an opportunity to improve.

Managers should consider:

  • what happened;
  • why it happened;
  • whether procedures were followed;
  • what improvements are needed;
  • whether further training is required.

The goal is continuous improvement—not blame.


Ofsted Inspection Insight

Inspectors expect organisations to demonstrate effective governance, including how incidents are reported, investigated and used to improve future practice.

Strong reporting cultures strengthen safeguarding.


Practice Scenario – Lost Laptop

Train Journey Home


Practice Scenario – Suspicious Computer Behaviour

Files Won't Open


Manager Coaching Notes

Managers should ensure:

  • cyber incidents are reported immediately;
  • staff know reporting procedures;
  • incidents are documented accurately;
  • lessons learned are shared;
  • policies are reviewed after significant incidents;
  • refresher training is provided where required.

A strong reporting culture is one of the most effective cyber security controls.


Reflection

Reflect on today's learning.

  • Would you recognise the signs of a cyber incident?
  • How quickly should a lost device be reported?
  • Why should staff avoid trying to fix cyber incidents themselves?
  • How can learning from incidents improve future security?

Cyber security is not about preventing every incident.

It is about recognising problems early, responding professionally and continually improving how we protect children and information.


End of Course Assessment

Instructions

Complete the assessment below.

A pass mark of 80% is required before the course can be marked as complete.

No questions provided.


Competency Declaration

Professional Competency & Compliance Declaration

Statutory standard: UK EYFS / KCSIE / Ofsted Framework

Training Record Verification
  • I have thoroughly read and understood all content, statutory frameworks, and operational guidelines presented in this training course.
  • I confirm my commitment to applying these safeguarding and quality standards rigorously in my day-to-day childcare practice.
  • I understand my legal and organisational reporting responsibilities under UK childcare legislation and DASC policy.

Related Policies & Documents


    References

    Course References


      Course Completion

      Congratulations.

      You have completed Course 10 – Online Safety & Cyber Security.

      Technology is an essential part of modern childcare, but it brings significant responsibilities. Every email you send, every document you access and every device you use has the potential to either strengthen or weaken DASC's safeguarding and cyber security.

      Remember the four principles of cyber safety:

      • Think Before You Click
      • Protect Personal Information
      • Report Concerns Immediately
      • Use Technology Responsibly

      Strong cyber security is not created by technology alone.

      It is created by knowledgeable people making safe decisions every day.

      Together, we protect our children, our colleagues, our families and our organisation.

      References

      Legislation

      1. United Kingdom General Data Protection Regulation (UK GDPR) 2018. The Stationery Office. https://www.legislation.gov.uk/eur/2016/679/contents

        View source ↗
      2. Data Protection Act 2018 2018. The National Archives. https://www.legislation.gov.uk/ukpga/2018/12/contents

        View source ↗

      Government Guidance

      1. Department for Education (2025). Keeping Children Safe in Education 2025. Department for Education. https://www.gov.uk/government/publications/keeping-children-safe-in-education--2

        View source ↗
      2. Department for Education (2025). Statutory Framework for the Early Years Foundation Stage (EYFS). Department for Education. https://www.gov.uk/government/publications/early-years-foundation-stage-framework--2

        View source ↗