VIEWS BRITISH EDUCATIONAL SUPPLIERS ASSOCIATION (BESA)
KCSIE 2026: Five changes schools should be aware of right now
With the new Keeping Children Safe in Education (KCSIE) guidance now in force, BESA has drawn on expertise from within its membership. Here, AL KINGSLEY MBE, CEO of NetSupport and an expert in EdTech and digital safeguarding, covers the changes schools need to know about.
From new requirements around AI and mobile phones to changes affecting volunteers and safeguarding records, there is plenty for schools to get to grips with when it comes to the new KCSIE guidance.
1. Part One of KCSIE must now be read by all staff. Previously, only staff in direct contact with students needed to read this section in full. For 2026, your school’s governing bodies and proprietors will need to ensure that everyone reads Part One at their induction to their role, including catering, site maintenance and administrative members of staff. 2. Recruitment rules have tightened for volunteers. Volunteers play an important part in education, with schools often welcoming them onto the premises to train, instruct or supervise their students. Volunteers will now fall under ‘regulated activity’ and require pre-appointment and DBS checks. Your school will need to review its current volunteers and whether their existing vetting needs to be updated.
3. Schools are expected to be phone-free environments ‘by default’. The guidance plainly states that students should have no access to phones “during lessons, the time between lessons, breaktimes and lunchtime”. It adds that any exception to this would need to be clearly justified. 4. AI is named as a safeguarding issue. This covers both students using generative AI (including AI-generated nudes and semi-nudes, sometimes
LGFL-THE NATIONAL GRID FOR LEARNING The new face of phishing
We hear from GARETH JELLEY, Cyber Security Lead at EdTech charity LGfL – The National Grid for Learning. included in the email.
Schools are facing a new generation of cyber threats as AI changes how criminals target staff and pupils. Today’s phishing attacks are far removed from the poorly written scam emails of the past. AI allows criminals to create highly convincing, personalised messages that replicate the tone, language and identity of trusted colleagues, suppliers or organisations.
AI tools can generate professional, realistic emails with no obvious spelling or grammar errors. Messages may imitate senior staff or external organisations, and attackers are increasingly using compromised email accounts belonging to colleagues, suppliers or other schools. Known as ‘business email compromise’, these attacks exploit trust by sending malicious emails from genuine accounts.
Using short audio samples found online or recorded from previous calls, attackers can also create deepfake voice messages. These may sound like a headteacher, senior leader or trusted colleague requesting urgent action.
AI can quickly scan websites, social media and online records to build detailed profiles of staff, enabling highly personalised scams. Practical steps for staying safe from AI-driven scams If you receive an unexpected request involving money, sensitive information or changes to payment details, the safest first step is to pause, then confirm the request using a different communication method, such as a known phone number or face-to-face conversation. Speak to the person directly where possible.
If a supplier asks you to change bank details, verify the request using an existing telephone number already held by the school rather than one
October 2026
AI phishing often relies on pressure tactics such as urgency and deadlines, fear and threats, or impersonating authority. Pause and ask yourself: does this really need doing now? Am I being pressured into acting? Can I verify this before responding?
Voice cloning and AI-generated video calls make impersonation more convincing than ever. If you receive a call requesting urgent action, end the call politely and call back using a trusted number from school records. It’s worth reviewing your digital footprint. Attackers often gather information from school websites, social media profiles and public events and announcements. Strong security habits make a difference, too; use strong, unique passwords and enable multi-factor authentication (MFA) wherever available.
If something feels suspicious, report it to your school’s IT support or network manager immediately and follow your school’s agreed cyber incident reporting process. Rapid reporting allows IT teams to reset passwords, revoke compromised devices, investigate unusual logins and prevent attackers from gaining further access The key message
AI-powered phishing represents a major shift in the cyber threats facing schools. Because these scams are more realistic, more personalised and increasingly use trusted communication channels, the traditional “spot the scam” approach no longer offers the protection it once did. Instead, the strongest defence is a culture of verification, where unusual requests are routinely checked through another communication channel, suspicious activity is reported immediately and staff feel confident questioning even apparently genuine messages.
www.education-today.co.uk 19
called ‘deepfakes’) and staff use of AI tools. So, check your school’s online safety policies, staff training and filtering and monitoring systems with this in mind. A named senior leader must also check and review your school’s filtering and monitoring systems annually – and you need to keep a written record of that review.
5. Information-sharing and safeguarding record duties are clearer. This year’s KCSIE sets out clearer details about information sharing (paragraphs 138-150) that aim to give staff more confidence to act when they need to do so. There’s also a requirement for child protection files to transfer to a new school within five days (whether that’s for an in-year move or at the start of a new term) – and there’s a stronger expectation that schools will have clear cover arrangements for when its designated safeguarding lead is unavailable. What’s next?
As educators, we must not only provide a safe environment for students to learn and thrive, but also be empowered to reach out to others when a safeguarding issue falls outside the school’s remit. KCSIE covers all this – and more.
As society becomes more complex and technology evolves, safeguarding children has never been more important than it is now. This guidance brings real support in helping your school do just that and I’d encourage everyone to dedicate some time to ensuring your school meets the wider guidance where appropriate.
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36 |
Page 37 |
Page 38 |
Page 39 |
Page 40 |
Page 41 |
Page 42 |
Page 43 |
Page 44 |
Page 45 |
Page 46 |
Page 47 |
Page 48