Jisc
Member story

From crisis to recovery: Blackburn College's cyber-attack story

Blackburn College shares how we helped them contain a ransomware attack, guide recovery efforts, and support communication with key stakeholders.

Technician checking cables in a rack mounted server.

Half-term can be a quieter week than usual for much of the further education sector, but October 2024 proved to be very different for Blackburn College. Despite feeling confident with the security protections in place, at around 8:30 on a Thursday morning staff in IT and operations started to receive alerts signalling a problem with some college systems.

Hussein Lorgat, IT team leader, knew the situation was serious as soon as he picked up a call from his manager.

“I was actually on leave and my phone started pinging with notifications. Shortly after that, my manager called and I knew from the tone of his voice that something was drastically wrong, so I just jumped in the car and came straight to work.”

As an immediate response to the incident, the team started by disconnecting internet access across the college to contain the threat and try to prevent any further unauthorised activity. The aim was to ensure that any attackers still inside the network were effectively isolated and no data could leave the system. With containment in place, the team then shifted focus to investigating the point of entry and assessing the extent of the attack.

Hussein said:

“We operate both physical and virtual servers, so while we couldn’t remotely access any of the virtual environment we could access some physical servers directly. We found ransomware notes and encrypted files confirming that the college had been attacked. At that point, we made the decision that no computers anywhere on campus could be turned on, and any devices that were already powered on should be switched off immediately.”

Support and recovery

After making their insurance company aware of the attack, the team called Jisc who put the college’s internet connection into containment mode. This meant Hussein and other key staff responding to the attack could access Microsoft services and set up a meeting on Teams to start the support process.

Jennifer Eastham, vice principal of finance and corporate services, said:

“I hadn’t fully appreciated what Jisc did until the day we made that call. The support was outstanding. They guided us through what was happening, explained what to expect, reassured us when things felt overwhelming, and helped us navigate unfamiliar terminology. They were brilliant.”

The evidence gathering, from accessing firewall log files to capturing activity spikes on the college servers, allowed the team to start to put together a recovery plan. Hussein said:

“Because Jisc works specifically with the education sector, they've seen this with other institutions. They know how networks and servers are typically structured within our environments and that the priority is obviously getting all the staff and students back up and running. So they helped us prioritise the rebuild process.”

Jennifer said that, while any planning for potential attacks expected there would likely be no system access, the reality hit home harder than expected. With no access to wifi, phone systems, computers or laptops, even finding contact details for staff wasn’t straightforward.

“We had to just work through each challenge one by one, going through a cascade of information of how we could communicate quickly and efficiently and get those core messages out.”

Going back to basics

Jennifer also found herself with a stream of messages and calls while she was on leave and, like Hussein, knew that something serious had happened. Her first reaction was concern for the students returning in a few days and how the teaching staff could proceed with lessons if the wider systems weren’t accessible. She said:

“One of my first thoughts was how do we make sure that it's business as usual, at least as much as possible, for Monday morning? So we called together different groups of management to contact the teachers and started working through the challenges; the first being there were no computers.”

With students the key focus, the staff quickly had to pivot to different teaching methods while the college was offline. From lesson planning to taking the morning register, everything had to be done manually, a change some staff initially found daunting but that ultimately opened up new opportunities for future lessons. Jennifer said:

"Some of our teachers really enjoyed the experience, and the students certainly did. It led to some unexpected changes. One memorable moment was when an overhead projector appeared from the back of a cupboard. We thought we'd got rid of them all. More importantly, teachers found different ways to engage their classes and were able to focus on their craft without relying on computers. In many ways, it was a very enlightening experience."

The human experience

Another unexpected obstacle to navigate shortly after the attack was an upcoming Ofsted inspection, understandably stressful in a time when the college had no working IT systems across teaching and learning. Jennifer and the team put it into perspective by reiterating to staff that student progression was what mattered, not the college’s computer systems.

“Ofsted could look at a thousand files, but if they actually sit a group of students down and hear their experiences first hand, listen to them talk about what they've learnt at college and the experience they're having, it says so much more. So we were absolutely delighted that despite having no systems and being in a very pressurised, challenging environment, the team pulled together and delivered the absolutely amazing result of outstanding.”

Along with the practical and technological stresses came more personal responses to the attack. As Jennifer pointed out, people react very differently to this kind of scenario:

“There were people who came up with their own solutions and went off on a tangent who we then had to bring back. There were people who followed all the rules, did everything to help, and stayed calm. And there were people who really struggled because the situation was unknown and uncharted and we had to support them through it.”

The effect the attack had on some of the team was one of the biggest learnings Jennifer and the leadership team took from the experience, and something she would advise other institutions to consider should they deal with a similar scenario.

“There were some incredibly difficult and emotionally demanding moments. The biggest lesson was that while recovering systems is a process, supporting people is far more complex. Our staff care deeply about their work, and the impact on them was immense. Communication was critical, and as a leadership team we had to draw on all our experience to keep people together, maintain focus, and help the organisation recover.”

The value of Jisc

Both Jennifer and Hussein had high praise for the support Jisc provided during a different time.

Jennifer said:

“Our Jisc membership is worth every penny, they provided an enormous amount of support. I now look at Jisc differently. We encourage our staff to go on training, and when I talk to people, I tell them that Jisc really is your number one contact and the most important when you're dealing with one of these incidents.”

Hussein had similar words:

“They were so dedicated in getting us up and running again. We were still here until 9pm some nights, but if we had a question we would put it on the Teams channel and one of the guys would respond. So the experience that we had in this recovery process and the support that we had from Jisc, I don't think we'd have got it from anywhere else.”

Further information

Continue reading

Sign up to Headlines

Stay at the forefront of technology in education and research with our tailored newsletter.