Education July 27, 2026 6 MIN READ

What KCSIE 2026 means for cyber security and safeguarding in schools

From 1 September 2026, the latest Keeping Children Safe in Education (KCSIE) guidance raises the bar for how schools, colleges and trusts approach online safeguarding. While filtering and monitoring have…

What KCSIE 2026 means for cyber security and safeguarding in schools

From 1 September 2026, the latest Keeping Children Safe in Education (KCSIE) guidance raises the bar for how schools, colleges and trusts approach online safeguarding. While filtering and monitoring have featured in previous versions of the guidance, this year’s updates reflect a bigger shift. Technology is evolving at pace, artificial intelligence (AI) is changing the online landscape, and the expectation is no longer simply that schools have safeguarding technology in place, but that they can demonstrate that it is effective.

For education leaders, this represents a move away from viewing filtering as an IT responsibility and towards recognising it as a core safeguarding function that requires oversight from governors, senior leaders, designated safeguarding leads and IT teams alike.

Safeguarding technology is no longer a ‘set and forget’ exercise

One of the requirements within KCSIE 2026 is that schools must actively review the effectiveness of their filtering and monitoring arrangements.

The guidance states:

“Whilst considering their responsibility to safeguard and promote the welfare of children and provide them with a safe environment in which to learn, governing bodies and proprietors should be doing all that they reasonably can to limit children’s exposure to the above risks from the school or college’s IT system. As part of this process, governing bodies and proprietors should ensure their school or college has appropriate filtering and monitoring systems in place and ensure that a review of their effectiveness is carried out at least once every academic year.”

Importantly, this review is expected to involve the senior leader responsible for filtering and monitoring, the Designated Safeguarding Lead and IT support, with evidence that filtering is working across all internet-connected devices and relevant locations within the school.

While annual reviews are now the minimum expectation, the pace at which online risks evolve means many schools may find that reviewing their arrangements once a year is not enough. Just as safeguarding policies are continually reviewed throughout the year, filtering and monitoring should become part of an ongoing safeguarding conversation rather than an annual compliance exercise.

AI has fundamentally changed the safeguarding landscape

Perhaps the most significant addition to this year’s guidance is the recognition that artificial intelligence is creating entirely new safeguarding risks.

Deepfakes, AI-generated imagery and so-called “nudification” applications are becoming increasingly sophisticated and accessible, making it harder than ever for schools to protect pupils through traditional web filtering alone. The challenge is no longer limited to blocking inappropriate websites; schools now need to consider how they identify harmful AI-generated content before it reaches young people.

This shift highlights a broader reality. Safeguarding technology must now be capable of understanding context, recognising emerging risks and responding in real time. Static filtering rules are becoming less effective against content that can be generated instantly and shared widely across multiple platforms.

Monitoring should support early intervention, not simply record activity

The expanded guidance also places greater emphasis on identifying wider safeguarding concerns, including mental health, exploitation and peer-on-peer abuse.

This reflects an important change in thinking. Monitoring is no longer about observing what pupils have accessed online; it is about recognising behavioural patterns that may indicate a child needs support before concerns escalate.

When implemented appropriately, monitoring becomes another safeguarding tool alongside pastoral care, allowing schools to identify vulnerable pupils earlier and intervene more effectively.

Cyber security and safeguarding are becoming inseparable

The latest guidance also strengthens its focus on cybercrime, describing it as a “significant and rapidly evolving crime landscape” and recognising that young people can become involved in harmful online activity without fully understanding the consequences.

This reinforces something many education technology providers have recognised for some time: safeguarding and cyber security can no longer be viewed as separate disciplines.

Protecting pupils means protecting the digital environment they learn in. Filtering, effective monitoring, secure networks and measures such as multi-factor authentication all contribute to creating safer learning environments, reducing opportunities for both external threats and inappropriate internal activity.

Mobile phone guidance presents new IT security challenges

Alongside the strengthened safeguarding requirements, schools are also preparing for the introduction of statutory mobile phone restrictions from 1st September 2026. The updated guidance reinforces the expectation that schools should create mobile-phone-free learning environments and that staff should model appropriate behaviour, including limiting their own mobile phone use during the school day where appropriate.

While these changes support pupil wellbeing and reduce distraction, they also introduce a practical challenge that many schools may not have considered. Cyber security increasingly relies on multi-factor authentication (MFA), with many systems sending login approval requests or authentication codes directly to a user’s mobile phone. If staff are expected to keep mobile phones out of classrooms or stored away during the day, schools need to consider how this aligns with their cyber security strategy. Finding the right balance between safeguarding, usability and security is becoming increasingly important.

There is no one-size-fits-all solution. Depending on a school’s environment, options may include hardware authentication devices, alternative authentication methods, location-based authentication policies or carefully managed exemptions for staff where appropriate.

Turning guidance into practical safeguarding

For many schools, understanding the new guidance is only the first step. The challenge is translating statutory expectations into practical, day-to-day safeguarding. This is where technology and expertise need to work together.

As an authorised Smoothwall partner at Ask4Support, we work with schools, colleges and multi-academy trusts to implement filtering and monitoring solutions that align with the latest KCSIE guidance. Smoothwall’s technology goes beyond traditional web filtering by combining intelligent content analysis, real-time monitoring and safeguarding insights that support designated safeguarding leads, IT teams and senior leadership.

Alongside this, Ask4Support provides the ongoing technical expertise needed to review systems, test their effectiveness and ensure schools remain aligned with the Department for Education guidance. While KCSIE specifies an annual review as a minimum, we encourage schools to assess their filtering and monitoring arrangements more frequently, particularly as new online risks continue to emerge throughout the academic year.

Get in touch to find out more

The question is no longer whether filtering and monitoring systems are in place. It is whether those systems are providing the level of protection that safeguarding challenges demand. For more information on our services for education, including Smoothwall, speak to a member of the team.

Talk to us

Got a question about anything in this article?

Send us a message and one of the team will come back to you, usually within the hour during business hours.

Your details are safe with us. See our privacy policy.

Get in touch today

Got an IT challenge
to talk through?

Our team is always happy to help: no pressure, no jargon, just honest advice. Call us on +44 1491 712 344 or email [email protected].