KCSIE 2026: Turning Digital Safeguarding Guidance into Practice

From 1st September 2026, the updated Keeping Children Safe in Education guidance comes into force. As schools prepare for the new academic year, there are some important updates around digital safeguarding that senior leaders, safeguarding teams and those responsible for technology need to be aware of.

Filtering and monitoring, AI, online safety and information security all feature within the updated guidance. While many of these areas won't be new to schools, KCSIE 2026 provides greater clarity around what is expected and importantly, the role of senior leadership in ensuring the right arrangements are in place.

Digital safeguarding isn't something that can simply be delegated to an IT team or provider. Technical expertise is an important part of it, but senior leaders need to understand their school's digital environment, the risks within it and have assurance that the measures in place are appropriate and effective.

So, what do the KCSIE 2026 updates mean in practice and what should schools and trusts consider from September?

Filtering and monitoring: move beyond having a system in place

Schools should already have appropriate filtering and monitoring in place, but KCSIE 2026 provides greater clarity around what these terms mean in practice and how their effectiveness should be reviewed.

It is important to distinguish between the two, as they are often still misunderstood or used interchangeably.

Filtering is the preventative layer. It restricts access to inappropriate or harmful content by blocking or limiting what users can see, search for or access online. This includes websites, search results, applications and online services that have been categorised as unsafe or unsuitable for children. In simple terms, filtering is about stopping access before it happens.

Monitoring, on the other hand, is about oversight. It involves identifying and reviewing activity once a user is online or on a device to help detect potential safeguarding concerns or risky behaviour. This may include alerts, logs, reports or screenshots that highlight concerning searches, language or patterns of use. In simple terms, monitoring is about identifying and responding to what is happening.

Understanding the difference matters, particularly when it comes to reviewing whether your arrangements are effective.

KCSIE 2026 is clear that the effectiveness of filtering and monitoring should be reviewed at least once every academic year by the SLT member responsible for filtering and monitoring, supported by the DSL and IT support.

The review should include checks that filtering is working appropriately across internet-connected devices in all relevant locations, with schools keeping a record of those checks. It should also consider whether monitoring arrangements are working effectively, whether reports and alerts are reaching the right people and whether those responsible have the capacity, understanding and processes in place to review and respond to concerns appropriately and promptly.

This is an important distinction.

Filtering and monitoring can easily become viewed primarily as an IT responsibility. A system is installed, IT manages the technical configuration and there can be an assumption that everything is therefore working as it should.

KCSIE 2026 makes clear that schools need to look beyond whether systems are simply in place and consider how effective those arrangements are in practice. This includes senior leadership oversight, regular review and assurance that the right information is reaching the right people and being acted upon appropriately.

As part of that review, schools should be asking:

  • What devices, users, networks and relevant locations are covered?

  • How do we test that filtering is working as expected?

  • What is our monitoring identifying and who is receiving the reports or alerts?

  • Are the right people receiving that information and do they understand what they are expected to do with it?

  • Are alerts being reviewed and responded to within an appropriate timeframe?

  • Is there a clear route for escalating concerns identified through monitoring into safeguarding processes?

  • When we make changes to technology, do we consider the impact on filtering and monitoring?

Your IT team or provider should be able to support this process with technical checks, evidence and advice. There should also be no hesitation in reviewing arrangements more frequently where circumstances, risks or technology change.

The important distinction is that IT teams support the process. Senior leadership retains oversight and responsibility for ensuring the arrangements are appropriate for the school.

AI: a growing part of the safeguarding picture

AI is another area where KCSIE 2026 has moved on.

The guidance now specifically recognises that nude and semi-nude imagery involving children may be digitally altered or wholly generated using AI, including what are sometimes described as deepfakes or deep nudes.

This is an important development because staff can no longer assume that an image involved in a safeguarding concern is necessarily a genuine photograph or video. It may have been manipulated, created using an existing image or generated entirely using AI.

More broadly, KCSIE continues to recognise that technology is a significant component in many safeguarding and wellbeing issues, with harm taking place both online and offline.

For schools, this means the conversation around AI needs to extend beyond teaching and learning or how it can reduce workload. There is a safeguarding conversation too.

Rather than treating AI as a completely separate issue, schools should consider whether their existing safeguarding arrangements have kept pace with the way the technology is developing.

Do staff understand that AI-generated or manipulated imagery can form part of a safeguarding concern? Would they know how and where to report it, how to contain the situation and what steps to take next if a deepfake or deep nude involving a pupil was identified?

Clear procedures are particularly important here, including how to report a concern without forwarding, sharing or unnecessarily viewing the imagery. Staff need a clear route to escalate concerns while minimising the risk of the content being circulated further or causing additional harm.

It is also worth considering how pupils are being supported to understand deepfakes and AI-generated or manipulated imagery as part of wider online safety education. This could include helping them understand what deepfakes are, how content can be created or altered and the potential impact of creating or sharing this type of content.

There is also an opportunity to reinforce what pupils should do if they receive or become aware of this type of imagery, including not sharing it further, knowing how to report it and where they can go for support.

The fact that an image isn't real doesn't mean the impact isn't real, and building awareness can help pupils recognise the risks and make more informed choices online.

For senior leaders, the important point is to make sure emerging AI risks are understood as part of the school's wider safeguarding responsibilities, rather than being seen solely as a technology issue.

As AI continues to develop, keeping staff awareness, reporting routes and safeguarding responses under review will be increasingly important.

Information and cyber security: understand the connection

Digital safeguarding also goes beyond what pupils can access online.

Schools hold significant amounts of sensitive information digitally, including safeguarding records and personal information about pupils, families and staff. They also rely on digital systems every day to keep the school running.

A cyber incident can therefore be much more than an IT problem. If safeguarding information is compromised or unavailable, sensitive data is accessed or key systems are disrupted, there can be very real safeguarding and operational consequences.

KCSIE 2026 provides greater clarity around information and cyber security as part of wider safeguarding responsibilities. Alongside this, the DfE's updated Cyber Security Core Standard gives schools and trusts clearer expectations around managing cyber risk.

This includes conducting a cyber risk assessment annually and reviewing it regularly, managing accounts and access, keeping technology secure and up to date, maintaining appropriate backups and ensuring staff understand their role in keeping systems and data secure.

One area I would encourage schools to look at is identity and access: who can access your systems, how they prove who they are and how those credentials are protected.

Good password management is a basic but important starting point. Passwords shouldn't be routinely shared or left in notebooks, on desks or alongside devices where they can easily be accessed by someone else. Schools should consider secure password management solutions, single sign-on and other approaches that reduce the number of passwords staff need to manage while keeping credentials protected.

The updated Cyber Security Standard makes MFA a clear requirement for staff accounts accessing cloud services or remotely accessing on-site systems, as well as IT administrative accounts. For some schools, implementing this can present practical challenges, particularly where staff don't use personal devices for work, but there are other options available.

Depending on the technology in place, alternatives can include security keys, restricting access to managed devices and trusted locations or specific IP addresses, passkeys and other secure authentication methods. Schools should work with their IT team or provider to find an approach that is secure, practical and accessible for their teams.

There is also a growing need for everyone within a school to remain vigilant about phishing and social engineering.

Emails designed to steal credentials, deliver malware or encourage someone to make a payment or disclose information are becoming increasingly convincing. They may appear to come from a colleague, neighbouring school. senior leader, supplier or organisation you regularly work with.

Staff should be encouraged to pause before clicking links or opening attachments, particularly when an email is unexpected or a request seems unusual. If in doubt, verify the request independently before taking any action. Start a new email using an address you already know to be genuine, or contact the person or organisation directly using a trusted phone number. Avoid replying to the original message or using contact details provided within a suspicious email.

If something doesn't look right, verify it another way or ask your IT team before taking action.

Just as importantly, staff need to know what to do if they do click something or receive an email they are concerned about. Report it to your IT team or provider as soon as possible, but don't forward the suspicious email to them or to colleagues, as this can increase the risk of someone else clicking a malicious link or opening an attachment.

Instead, follow your school's agreed reporting process. If helpful, take a screenshot showing the sender and relevant details, without opening links or attachments. If you have already clicked a link, opened a file or entered your password, make this clear when reporting it so your IT team can take the appropriate action quickly.

This is also where MFA provides an important additional layer of protection. If a password is compromised through phishing, MFA can help prevent an attacker from gaining access using those credentials alone. It isn't a substitute for vigilance, but it can significantly reduce the risk of a compromised password leading to unauthorised access.

Early reporting, MFA and good staff awareness all work together to help contain potential incidents and protect school systems and data.

The DfE standards also reinforce the importance of regular cyber awareness training, including phishing, password security, social engineering, MFA and how to report a cyber incident.

For senior leaders, the focus is on oversight rather than technical configuration: understanding what protections are in place, where the risks are and where further action may be needed.

For senior leaders, some useful assurance questions include:

  • How are passwords and credentials being managed across the school?

  • Is MFA enabled for staff cloud accounts, remote access and administrative accounts?

  • What alternatives are available where personal devices aren't appropriate?

  • Are access and permissions reviewed when staff join, change roles or leave?

  • Are staff regularly reminded how to recognise and report phishing attempts?

  • Do staff know what to do if they accidentally click a suspicious link or open an unexpected attachment?

  • Are systems and devices supported, secure and kept up to date?

  • Are backups secure, including cloud-based systems, and regularly tested to ensure they can support recovery? Do not assume that because a system is cloud-based (e.g. Microsoft or Google) that backup and recovery is automatically covered.

  • When was our last cyber risk assessment and what actions came from it?

Cloud-based shouldn't automatically be taken to mean backed up. Schools should understand what their cloud provider protects, what can be recovered and whether additional backup arrangements are needed for services such as Microsoft 365 or Google Workspace.

This is where IT teams and providers can support senior leaders with the technical evidence, risk information and recommendations they need. The focus for leadership is not technical configuration, but having clear oversight of the school's cyber security position, understanding the controls in place and knowing where further action or investment may be required.

Bring safeguarding, leadership and IT together

Across all of these areas, one thing becomes increasingly important: regular communication between safeguarding, leadership and IT partners. Your DSL understands safeguarding. Your IT team or provider understands the technology. Senior leaders understand the school, its pupils and its wider priorities and hold responsibility for the decisions being made.

Each sees the digital environment from a slightly different perspective.

These conversations don't need to create additional meetings or processes. They can form part of existing safeguarding, digital strategy and leadership reviews. What matters is that the right information is reaching the right people, risks and concerns are being shared and there is clarity around what happens next.

If monitoring begins to identify a pattern of concerning behaviour, that information needs to reach the DSL. When a new platform, system or device is introduced, its potential safeguarding impact should form part of the conversation and where IT identifies a weakness, limitation or emerging risk, senior leaders need to understand what it means and whether action is required.

It is these connections between safeguarding, leadership and technology that help turn digital safeguarding from individual responsibilities into a joined-up approach.

Turning guidance into practice

The digital environment pupils are growing up in will continue to change. AI will develop, new platforms will emerge and the risks schools encounter will evolve alongside them.

Schools won't be able to anticipate every new risk, but they can build strong digital leadership around the technology they use. That means understanding what is in place, asking the right questions, reviewing and testing arrangements and acting where improvements are needed.

Most importantly, it means making sure safeguarding, leadership and IT are working together, with clear responsibilities and the right information reaching the right people.

That is how guidance becomes part of everyday practice, rather than simply another compliance exercise.

Ultimately, senior leaders should be able to answer one key question with confidence:

Do we understand our digital safeguarding arrangements, can we evidence them and are they effective in practice?

Next
Next

Everyone's Talking About AI in Secondary Schools. What About Primary?