Course 10 – Online Safety & Cyber Security
DASC Standard
Technology creates opportunities for learning, communication and creativity.
It also creates risks.
Every member of staff has a responsibility to protect children, colleagues and DASC information from online harm and cyber threats.
Online safety is safeguarding.
Introduction
Technology forms part of everyday life.
Children may use:
- tablets;
- computers;
- interactive displays;
- educational websites;
- digital learning platforms.
Staff also use technology to:
- communicate;
- record attendance;
- access learning records;
- complete safeguarding documentation;
- manage personal data.
Using technology safely protects children, staff and the organisation.
Learning Outcomes
After completing this course you will be able to:
- explain what online safety means;
- recognise common cyber security risks;
- protect children's personal information;
- identify phishing and online scams;
- create strong password habits;
- report cyber incidents appropriately;
- understand your responsibilities when using DASC technology.
Why Online Safety Matters
Poor cyber security can lead to:
- data breaches;
- identity theft;
- safeguarding risks;
- financial loss;
- disruption to services;
- reputational damage.
Children may also be exposed to:
- inappropriate content;
- online grooming;
- cyberbullying;
- scams;
- harmful online behaviour.
Everyone has a role in reducing these risks.
DASC Best Practice
Think before you click.
Think before you share.
Think before you store.
Most cyber incidents begin with a single unsafe decision.
Ofsted Inspection Insight
Ofsted expects staff to understand that online safety forms part of safeguarding.
Inspectors may ask how staff protect children online, use technology safely and safeguard personal information.
Online safety should be embedded in everyday practice.
Reflection
Reflect before continuing.
- How much personal information do you handle during a normal day?
- Could a cyber attack affect children's safety?
- What would you do if you received a suspicious email?
- How does online safety support safeguarding?
Good cyber security begins with informed staff making safe decisions every day.
Understanding Online Risks
The internet provides valuable opportunities for learning, communication and creativity.
However, it also exposes children and organisations to a range of risks.
Understanding these risks helps staff protect both children and DASC systems.
The Four Areas of Online Risk
Online risks are commonly grouped into four categories.
| Risk | Description |
|---|---|
| Content | Exposure to harmful, inappropriate or illegal material |
| Contact | Harmful interaction with other people online |
| Conduct | Unsafe or inappropriate online behaviour by users |
| Commerce | Financial scams, fraud, advertising and exploitation |
Staff should understand all four areas when supporting children.
DASC Standard
Online safeguarding is not only about blocking harmful websites.
It is about teaching safe behaviour, recognising risks and responding appropriately.
Content Risks
Children may accidentally encounter:
- violent material;
- extremist content;
- pornography;
- misinformation;
- hate speech;
- harmful challenges;
- age-inappropriate material.
Staff should supervise internet use and ensure only approved resources are used.
Contact Risks
Children may be contacted online by individuals who:
- pretend to be children;
- attempt grooming;
- encourage secrecy;
- request personal information;
- arrange meetings;
- exploit trust.
Children should never communicate online with unknown individuals during DASC activities.
Any safeguarding concerns must be reported immediately.
Conduct Risks
Children may unintentionally place themselves or others at risk through:
- cyberbullying;
- sharing personal information;
- inappropriate messages;
- offensive comments;
- sharing images without permission;
- unsafe online behaviour.
Online behaviour should reflect the same expectations as behaviour offline.
Commerce Risks
Children and adults may be targeted through:
- fake competitions;
- online scams;
- phishing emails;
- fraudulent websites;
- in-app purchases;
- subscription traps.
Staff should never enter DASC payment or personal information into unverified websites.
DASC Best Practice
Ask three questions before clicking any link:
- Do I know who sent it?
- Was I expecting it?
- Does it look genuine?
If the answer to any question is no, stop and check first.
Age-Appropriate Technology
Technology used with children should always be:
- suitable for their age;
- educationally appropriate;
- supervised;
- secure;
- approved by DASC.
Children should never have unrestricted internet access during club activities.
Digital Footprints
Everything shared online may leave a permanent record.
Staff should remember:
- photographs;
- comments;
- emails;
- messages;
- uploaded documents;
may remain accessible long after they have been deleted.
Professional judgement should always guide online behaviour.
Safe Searching
Where children use the internet:
- use child-friendly search tools where available;
- supervise browsing;
- use approved websites;
- report inappropriate content immediately;
- close unsuitable pages without drawing unnecessary attention.
Children should know they can always tell an adult if something online worries them.
Ofsted Inspection Insight
Inspectors may ask staff how they help children stay safe online.
They expect staff to understand online risks and respond appropriately to concerns rather than relying solely on technical filtering.
Practice Scenario – Unexpected Pop-Up
Inappropriate Website
Practice Scenario – Suspicious Competition
You've Won a Prize!
Manager Coaching Notes
Managers should ensure:
- online filtering is appropriate;
- staff receive annual cyber awareness training;
- online incidents are reported;
- children are supervised online;
- approved digital resources are used;
- cyber risks are reviewed regularly.
Good cyber security combines technology with informed staff.
Reflection
Reflect on today's learning.
- Could you explain the four areas of online risk?
- Would you recognise a phishing email?
- How should staff respond if inappropriate content appears?
- Why is supervision still important even when filtering is used?
Online safety is everyone's responsibility.
Every safe online decision helps protect children and DASC.
Protecting Personal Information
Every day, DASC staff handle personal information about children, families and colleagues.
Protecting this information is both a legal responsibility and an important part of safeguarding.
A data breach can place children, families and the organisation at significant risk.
What is Personal Information?
Personal information is any information that can identify a person directly or indirectly.
Examples include:
- names;
- addresses;
- dates of birth;
- telephone numbers;
- email addresses;
- attendance records;
- photographs;
- safeguarding records;
- medical information;
- assessment reports.
Some information, such as health and safeguarding records, requires an even higher level of protection.
DASC Standard
Only access information you need for your role.
Curiosity is never a lawful reason to view personal information.
Why Data Protection Matters
Good data protection:
- safeguards children;
- protects families' privacy;
- maintains trust;
- supports legal compliance;
- protects DASC's reputation.
Poor data handling may result in:
- safeguarding risks;
- identity theft;
- legal action;
- financial penalties;
- loss of confidence from parents.
Confidential Information
Confidential information should only be shared:
- with authorised colleagues;
- with safeguarding professionals where appropriate;
- with parents where appropriate;
- in accordance with DASC policies.
Never discuss confidential information:
- in public places;
- on public transport;
- in front of other parents;
- on social media.
Professional confidentiality continues outside working hours.
Using DASC Devices
When using DASC devices:
- lock the screen when unattended;
- log out after use;
- keep software updated;
- store devices securely;
- report lost or stolen devices immediately.
Shared devices should never remain logged into personal accounts.
DASC Best Practice
If you walk away—
Lock the screen.
It takes only seconds and protects sensitive information.
Using Personal Devices
Where DASC permits the use of personal devices:
- follow the Acceptable Use Policy;
- avoid storing children's information locally;
- use approved systems only;
- enable screen locks;
- protect devices with strong passwords.
Personal devices should never become unofficial storage locations for DASC records.
Sending Emails Safely
Before sending emails:
- check the recipient carefully;
- verify attachments;
- avoid unnecessary personal information;
- use secure systems where required.
A simple typing mistake can send confidential information to the wrong person.
Always pause and double-check before pressing Send.
Sharing Documents
When sharing documents:
- share only what is necessary;
- use approved systems;
- avoid personal file-sharing accounts;
- confirm recipients before sending.
The principle should always be:
Share the minimum information required.
Printing and Paper Records
Printed documents should be:
- collected immediately;
- stored securely;
- shredded when no longer required;
- kept away from public view.
Leaving confidential paperwork unattended creates unnecessary safeguarding risks.
Ofsted Inspection Insight
Inspectors expect staff to understand that protecting personal information forms part of safeguarding.
Safe information handling demonstrates professionalism, accountability and respect for children and families.
Practice Scenario – Wrong Email Address
Accidental Recipient
Practice Scenario – Unlocked Laptop
Quick Conversation
Manager Coaching Notes
Managers should ensure:
- staff understand confidentiality;
- devices remain secure;
- data breaches are reported promptly;
- staff follow approved systems;
- paper records are protected;
- regular data protection refresher training is provided.
Strong information security protects children, families and DASC.
Reflection
Reflect on today's learning.
- Could you identify personal information?
- Do you always lock your device before walking away?
- How would you respond if confidential information was sent to the wrong person?
- Why is data protection an important part of safeguarding?
Every piece of personal information belongs to someone who trusts DASC to protect it.
Professional care includes protecting that trust.
Passwords and Account Security
Passwords are one of the most important defences against cyber attacks.
Weak passwords can allow unauthorised access to sensitive information about children, families and DASC.
Strong account security helps protect safeguarding records, attendance systems and organisational data.
Why Password Security Matters
Cyber criminals often attempt to gain access by:
- guessing weak passwords;
- reusing passwords from previous data breaches;
- sending phishing emails;
- installing malicious software;
- stealing login details.
A single compromised account can place the entire organisation at risk.
DASC Standard
Your password protects more than your account.
It protects children's personal information.
Treat it as confidential at all times.
Creating Strong Passwords
A strong password should:
- be long;
- be unique;
- be difficult to guess;
- avoid personal information;
- not contain obvious words.
Avoid using:
- children's names;
- birthdays;
- "password123";
- "Welcome1";
- the organisation's name.
Long passphrases are often easier to remember and more secure than short, complex passwords.
Multi-Factor Authentication (MFA)
Many DASC systems use Multi-Factor Authentication (MFA).
This means logging in requires:
- something you know (your password); and
- something you have (such as a phone or authentication app).
MFA provides an additional layer of protection if a password becomes compromised.
Never approve an authentication request that you were not expecting.
DASC Best Practice
If you receive an unexpected authentication request—
Reject it.
Then change your password and report the incident immediately.
Unexpected login requests may indicate that someone knows your password.
Never Share Passwords
Passwords should never be:
- shared with colleagues;
- written on sticky notes;
- stored in notebooks;
- emailed;
- sent by text message;
- shared over messaging apps.
Every user should have their own account.
Shared accounts reduce accountability and increase security risks.
Password Managers
Password managers help users:
- generate strong passwords;
- store passwords securely;
- avoid password reuse;
- improve overall security.
Where approved by DASC, password managers may be safer than attempting to remember dozens of passwords.
Locking Your Device
Whenever leaving a device unattended:
- lock the screen;
- close confidential documents where appropriate;
- store portable devices securely.
Even a short conversation away from your desk may be enough for unauthorised access.
Logging Out
Always log out:
- when using shared devices;
- at the end of your shift;
- before handing devices to another person.
Closing a browser window does not always sign you out.
Always log out properly.
Recognising Suspicious Login Activity
Possible warning signs include:
- unexpected password reset emails;
- login alerts from unfamiliar locations;
- authentication requests you did not initiate;
- accounts becoming locked unexpectedly.
Report concerns immediately.
Early reporting limits the impact of cyber incidents.
Ofsted Inspection Insight
Inspectors may not ask about password complexity, but they do expect organisations to protect children's personal information appropriately.
Strong cyber security supports effective safeguarding and demonstrates responsible leadership.
Practice Scenario – Shared Password
Can I Use Your Login?
Practice Scenario – Unexpected Login Alert
Was This You?
Manager Coaching Notes
Managers should ensure:
- staff use strong passwords;
- MFA is enabled where available;
- password sharing is prohibited;
- suspicious login activity is reported;
- cyber awareness training is refreshed annually;
- accounts are removed promptly when staff leave.
Strong account security is one of the simplest and most effective cyber defences.
Reflection
Reflect on today's learning.
- Is every password you use unique?
- Would you recognise a suspicious authentication request?
- Why should passwords never be shared?
- How does MFA improve security?
Good password habits protect far more than technology.
They help safeguard children, families and the information entrusted to DASC.
Phishing, Scams and Social Engineering
Most cyber attacks do not begin with sophisticated hacking.
They begin by persuading someone to make a mistake.
Criminals often target people rather than technology because people are easier to deceive than computer systems.
Recognising scams is one of the most important cyber security skills.
What is Phishing?
Phishing is an attempt to trick someone into revealing:
- passwords;
- banking information;
- personal data;
- security codes;
- login credentials.
Phishing messages often appear to come from trusted organisations.
They may arrive by:
- email;
- text message;
- telephone;
- social media;
- messaging applications.
DASC Standard
Never trust a message simply because it looks professional.
Always verify before responding.
Common Warning Signs
Be cautious if a message:
- creates urgency;
- threatens consequences;
- requests confidential information;
- contains unexpected attachments;
- asks you to click a link;
- contains unusual spelling or grammar;
- comes from an unfamiliar sender.
One warning sign may not confirm a scam.
Several together should raise concern.
Social Engineering
Social engineering is when someone manipulates people into giving information or access.
Examples include:
- pretending to be IT support;
- impersonating a manager;
- claiming to be a parent;
- requesting passwords;
- asking for confidential records.
Professional confidence and polite verification help prevent these attacks.
Telephone Scams
A caller may claim to be from:
- Microsoft;
- your bank;
- the police;
- DASC's IT provider;
- another trusted organisation.
If asked for confidential information:
- remain calm;
- do not provide details;
- verify the caller independently;
- report the incident if appropriate.
Never rely solely on caller ID.
DASC Best Practice
If someone pressures you to act immediately—
Slow down.
Cyber criminals rely on panic.
Professional staff verify first and act second.
Suspicious Links
Before clicking a link:
- consider who sent it;
- check whether you expected it;
- look carefully at the web address;
- report suspicious emails if required.
Do not click links simply out of curiosity.
Attachments
Attachments may contain malicious software.
Never open unexpected attachments, especially if they ask you to:
- enable macros;
- install software;
- log into an account;
- bypass security warnings.
If unsure, verify with the sender using a trusted contact method.
QR Code Scams
QR codes can direct users to fraudulent websites.
Before scanning:
- consider where the code came from;
- verify it is genuine;
- avoid scanning unknown public QR codes requesting personal information.
Treat QR codes in the same way as website links.
Reporting Suspicious Activity
If you receive a suspicious message:
- do not respond;
- do not click links;
- do not open attachments;
- report it to your manager or IT support;
- follow DASC reporting procedures.
Early reporting protects everyone.
Ofsted Inspection Insight
Inspectors increasingly expect organisations to understand cyber risks because safeguarding now includes protecting children's personal information and digital systems.
Cyber awareness is part of modern safeguarding.
Practice Scenario – Fake IT Support
Urgent Password Reset
Practice Scenario – Urgent Payment Email
Immediate Action Required
Manager Coaching Notes
Managers should ensure:
- phishing awareness is refreshed regularly;
- suspicious emails are reported promptly;
- staff know how to verify unusual requests;
- cyber incidents are reviewed;
- lessons learned are shared across the organisation.
Cyber security improves when everyone remains alert.
Reflection
Reflect on today's learning.
- Could you recognise a phishing email?
- Would you question an urgent request for confidential information?
- How can social engineering affect safeguarding?
- Why is reporting suspicious activity so important?
Most cyber attacks succeed because someone trusts the wrong message.
Professional curiosity is one of the strongest cyber defences.
Safe Use of Devices and Technology
Technology supports learning, communication and administration throughout DASC.
Whether using a desktop computer, laptop, tablet or mobile device, staff must ensure that technology is used safely, responsibly and professionally.
Every device used for DASC business should protect children's information and support safeguarding.
Using DASC Devices
DASC-owned devices should only be used for authorised purposes.
Staff should:
- follow the Acceptable Use Policy;
- keep devices secure;
- report faults promptly;
- install only approved software;
- avoid personal use where prohibited.
Organisational devices contain valuable information and should always be treated responsibly.
DASC Standard
DASC technology exists to support children and the organisation.
Personal convenience should never compromise security.
Personal Mobile Phones
Personal mobile phones should only be used in accordance with DASC policies.
Staff should never:
- photograph children using personal phones;
- record videos of children;
- store children's personal information;
- communicate with children through personal accounts;
- use personal messaging apps for official safeguarding matters unless specifically authorised.
Approved systems should always be used.
Tablets and Learning Devices
Children may use tablets or other digital devices for educational activities.
Staff should ensure:
- activities are supervised;
- children access only approved content;
- devices are age appropriate;
- internet filtering is active where applicable;
- sessions remain purposeful.
Technology should enhance learning rather than replace meaningful interaction.
Software Updates
Updates often include important security improvements.
Where appropriate:
- install updates promptly;
- restart devices when requested;
- avoid delaying security updates unnecessarily.
Outdated software is a common cause of cyber attacks.
DASC Best Practice
Updates fix vulnerabilities that criminals actively search for.
Keeping software updated is one of the simplest cyber security measures available.
Public Wi-Fi
Public wireless networks may be less secure than trusted networks.
When working away from DASC:
- avoid accessing confidential information on unsecured public Wi-Fi;
- use approved secure connections where available;
- log out after use;
- avoid downloading sensitive documents unnecessarily.
Always think about who else may be connected to the same network.
Physical Security
Devices should never be left:
- unattended in public places;
- visible inside unattended vehicles;
- unlocked in shared areas;
- accessible to unauthorised individuals.
Portable devices should be stored securely whenever not in use.
Using USB Devices
Only approved storage devices should be connected to DASC equipment.
Unknown USB devices may contain malicious software.
Never insert:
- found memory sticks;
- unapproved external drives;
- unknown accessories.
If unsure, ask before connecting.
Remote Working
Where remote working is authorised:
- use approved systems;
- maintain confidentiality;
- avoid discussing sensitive information where others may overhear;
- secure printed documents;
- lock devices whenever leaving your workspace.
Professional standards apply regardless of location.
Ofsted Inspection Insight
Inspectors increasingly expect organisations to demonstrate good digital governance.
Safe technology use protects children, supports safeguarding and reflects effective organisational leadership.
Practice Scenario – Personal Phone
Quick Photograph
Practice Scenario – Found USB Drive
Car Park Discovery
Manager Coaching Notes
Managers should ensure:
- devices remain secure;
- software updates are completed;
- staff understand the Acceptable Use Policy;
- personal device use complies with policy;
- portable devices are encrypted where appropriate;
- cyber security procedures are reviewed regularly.
Strong technology management protects children, staff and organisational information.
Reflection
Reflect on today's learning.
- Could you explain why personal phones should not be used to photograph children?
- How do software updates improve cyber security?
- What would you do if you found an unknown USB drive?
- How can physical security protect digital information?
Technology is only as secure as the people using it.
Every safe decision strengthens DASC's cyber security.
Responding to Cyber Incidents
Despite strong security measures, cyber incidents can still happen.
The speed and effectiveness of the response often determines how serious the impact becomes.
Every member of staff has a responsibility to recognise potential cyber incidents and report them immediately.
Prompt reporting protects children, colleagues and DASC.
What is a Cyber Incident?
A cyber incident is any event that threatens the confidentiality, integrity or availability of information or technology.
Examples include:
- suspicious emails;
- malware infections;
- ransomware;
- lost or stolen devices;
- accidental disclosure of personal information;
- unauthorised access to accounts;
- data breaches;
- compromised passwords.
Not every incident becomes a major breach—but every incident should be reported.
DASC Standard
Never hide a cyber mistake.
Early reporting protects children and allows problems to be resolved quickly.
Recognising Warning Signs
Possible indicators include:
- unexpected password changes;
- unusual pop-up messages;
- slow or unusual computer behaviour;
- files becoming inaccessible;
- unfamiliar software appearing;
- login alerts from unknown locations;
- colleagues reporting unusual emails from your account.
Trust your instincts.
If something feels unusual, report it.
Immediate Actions
If you believe a cyber incident has occurred:
- remain calm;
- stop using the affected device if appropriate;
- disconnect from the network if instructed;
- inform your manager immediately;
- follow DASC reporting procedures;
- do not attempt to investigate independently.
Preserving evidence may help identify the cause.
DASC Best Practice
Report first.
Investigate later.
Trying to fix a cyber incident yourself may accidentally make the situation worse.
Data Breaches
A personal data breach occurs when personal information is:
- lost;
- stolen;
- accessed without authorisation;
- sent to the wrong person;
- altered without permission;
- accidentally destroyed.
Not every breach causes harm, but every breach should be assessed promptly.
Lost or Stolen Devices
If a DASC device is lost or stolen:
- report it immediately;
- provide as much information as possible;
- avoid attempting to recover it yourself if unsafe;
- follow management instructions.
Fast reporting increases the chance of protecting information remotely.
Malware and Ransomware
Malware is malicious software designed to damage or compromise systems.
Ransomware is a type of malware that encrypts files and demands payment.
If ransomware is suspected:
- stop using the device;
- disconnect it if instructed;
- report immediately;
- never pay a ransom yourself.
Professional advice should always be sought.
Learning from Incidents
Every cyber incident provides an opportunity to improve.
Managers should consider:
- what happened;
- why it happened;
- whether procedures were followed;
- what improvements are needed;
- whether further training is required.
The goal is continuous improvement—not blame.
Ofsted Inspection Insight
Inspectors expect organisations to demonstrate effective governance, including how incidents are reported, investigated and used to improve future practice.
Strong reporting cultures strengthen safeguarding.
Practice Scenario – Lost Laptop
Train Journey Home
Practice Scenario – Suspicious Computer Behaviour
Files Won't Open
Manager Coaching Notes
Managers should ensure:
- cyber incidents are reported immediately;
- staff know reporting procedures;
- incidents are documented accurately;
- lessons learned are shared;
- policies are reviewed after significant incidents;
- refresher training is provided where required.
A strong reporting culture is one of the most effective cyber security controls.
Reflection
Reflect on today's learning.
- Would you recognise the signs of a cyber incident?
- How quickly should a lost device be reported?
- Why should staff avoid trying to fix cyber incidents themselves?
- How can learning from incidents improve future security?
Cyber security is not about preventing every incident.
It is about recognising problems early, responding professionally and continually improving how we protect children and information.
End of Course Assessment
Instructions
Complete the assessment below.
A pass mark of 80% is required before the course can be marked as complete.
No questions provided.
Competency Declaration
Professional Competency & Compliance Declaration
Statutory standard: UK EYFS / KCSIE / Ofsted Framework
Related DASC Policies
Related Policies & Documents
References
Course References
Course Completion
Congratulations.
You have completed Course 10 – Online Safety & Cyber Security.
Technology is an essential part of modern childcare, but it brings significant responsibilities. Every email you send, every document you access and every device you use has the potential to either strengthen or weaken DASC's safeguarding and cyber security.
Remember the four principles of cyber safety:
- Think Before You Click
- Protect Personal Information
- Report Concerns Immediately
- Use Technology Responsibly
Strong cyber security is not created by technology alone.
It is created by knowledgeable people making safe decisions every day.
Together, we protect our children, our colleagues, our families and our organisation.
References
Legislation
United Kingdom General Data Protection Regulation (UK GDPR) 2018. The Stationery Office. https://www.legislation.gov.uk/eur/2016/679/contents
View source ↗Data Protection Act 2018 2018. The National Archives. https://www.legislation.gov.uk/ukpga/2018/12/contents
View source ↗
Government Guidance
Department for Education (2025). Keeping Children Safe in Education 2025. Department for Education. https://www.gov.uk/government/publications/keeping-children-safe-in-education--2
View source ↗Department for Education (2025). Statutory Framework for the Early Years Foundation Stage (EYFS). Department for Education. https://www.gov.uk/government/publications/early-years-foundation-stage-framework--2
View source ↗