News & Insights –

How Secure is Your School Website Security?

School Website Security

Your school website is your window to the outside world. Are you employing school website security best practices to ensure that it is protected from compromise?

Now more than ever, students and parents – both current and prospective – will be visiting your school website. What does it say about your school if your website has been compromised, either remotely by cybercriminals or hackers, or from closer to home – perhaps by a disgruntled teacher or student?

Fortunately, there are best practice measures that you can implement to ensure that your school website remains secure. In this blog post we will cover five security steps that we believe all schools should take to protect their website.

1. Enforce a Strong Password Policy

This may seem obvious, but maintaining a strong password policy is an essential element to securing your school’s website. Weak passwords can be hacked through Internet-facing content management system (CMS) login pages, guessed, or spied on over a user’s shoulder.

We recommend implementing the same password policies for your websites as you have for your IT systems. Typically this means enforcing complex passwords with at least eight characters, uppercase letters, lowercase letters, at least one number and at least one symbol. Users should be forced to change their passwords at least every 90 days.

2. CMS User Roles

Think about the people working at your school, and the access to IT systems that they need. A teacher needs access to curriculum materials but, unlike the Bursar, shouldn’t need access to finance systems. Their access should be setup accordingly.

Your website access should be setup along the same principles. Not all users who need access to your website need the same level of access, and so user roles should be set up in order to provide appropriate access rights to users.

3. User Administration

When a member of staff leaves your school there is a process that is followed to ensure that their access to systems and facilities is revoked. Does this include the removal of website access?

Effective user administration is an essential element in securing your school website. Along with allocating user roles, keeping close control over which users can access your website CMS will mitigate the risk of ex-employees of your school gaining access to your school website.

4. Two Factor Authentication

Together with a strong password policy, implementing two factor authentication provides an additional layer of security for your school website. With two factor authentication in place, a one-time only code is generated and sent to the user’s email address when they login to the CMS. This means that a user’s password alone is not enough to access the CMS.

Two factor authentication can be implemented through plug-ins on most website CMS’s, and it significantly reduces the likelihood of your school website being compromised. We also recommend implementing two factor authentication for any social media platforms your school utilises, such as Twitter or Facebook.

5. Hosting Provider Security

Your website hosting provider should have a number of security measures in place to protect your school website.

Speak to your hosting provider about the security measures they can implement for your website. You may find that there are useful features available to you that aren’t currently in place.

In Summary

Maintaining a secure website is essential to your school’s reputation and data integrity. Sometimes it’s the most straightforward steps – such as enforcing strong passwords and removing users when they leave – that are the most effective. They should always be combined, though, with configuration features such as two factor authentication to ensure that your school’s website is as secure as possible.

For more information about our secure school website design in Kent, get in touch with the Cleverbox team – we’re here to help.