We use cookies to give you the best experience and to help improve our website

Find out more about how we use cookies

Choose whether to use cookies:

No thanks Yes, I accept

Skip to main content

Jisc

You are in:

  • News
  • New measure in place to curb education sector ransomware attacks

Utilities:

  • Search the Jisc website
    Clear search results

Search the Jisc website
Clear search results

Navigation:

News

New measure in place to curb education sector ransomware attacks

16 December 2022

All UK tertiary education providers and research centres will soon benefit from an extra layer of cyber security protection against ransomware attacks.

At least 50% of major ransomware incidents experienced by the sector since August 2020 have been caused by attackers exploiting the Remote Desktop Protocol (RDP), a common way for users to access their computers or servers remotely from another device. 

Following consultation with the sector during summer 2021, Jisc will automatically block access from outside the UK to RDP (port 3389) from 28 March 2023. Only inbound traffic from known UK IP addresses will be allowed to proceed to port 3389. Existing restrictions will shift from an opt-in control to being on by default. 

This change follows updates to the policies that guide the use of the national research and education network, Janet, to which all UK colleges, universities and research centres are connected.     

Jisc’s director of information security policy and governance, Dr John Chapman, explains why the move is important: 

“The use of ransomware against our sector and globally has ramped up over the past couple of years and some attacks against colleges and universities have been devastating.  

“Organisations can still opt out of restrictions to specific IP addresses if they wish to, but they must accept the greater risk of a serious cyber security incident.  

“Controlling access to a known attack vector will help protect the sector as a whole against this type of attack.” 

Further information 

  • Jisc member organisations that wish to opt out should email irt@jisc.ac.uk with a list of the IP addresses to exclude before 28 February 2023
  • Jisc has launched a campaign, ‘defend as one’, to unite higher and further education in a common cause - to build robust defences across the sector. Members can sign up to receive personalised instructions on how to improve cyber security posture across their organisation 

Share this

Most read
  • Does ChatGPT mean the end of the essay as an assessment tool?
  • Jisc and HESA confirm merger
  • Digital 2030: Jisc supports post-16 sector to develop digital strategy following Welsh Government call to action
  • Jisc announces 2023 community champions
  • Jisc offers free places on assistive technology courses
Related
  • Ransomware: ‘Act now, before it’s too late’
  • New advice helps education and research community prevent ransomware attacks
  • ‘We’re braced to help sector deal with new wave of ransomware attacks'
  • Survey: cyber security at UK colleges and universities remains high priority, but there’s more work to be done
  • Survey helps Jisc target effort to support members in building robust cyber security strategies

Share this

You may also like…

Blog

Why Jisc members shouldn’t pay ransomware demands

This week, the UK’s National Cyber Security Centre (NCSC) and Information Commissioner’s Office (...
Blog

Latest cyber impact report underlines ransomware as a huge threat, but financial cost of attacks is still unclear

Cyber security is never ‘done’. It’s a continuous process of checking and scanning, patching ...

You are in:

  • News
  • New measure in place to curb education sector ransomware attacks

Areas

  • Connectivity
  • Cyber security
  • Cloud
  • Data analytics
  • Libraries, learning resources and research
  • Student experience
  • Trust and identity
  • Advice and guidance

Explore

  • Guides
  • Training
  • Consultancy
  • Events
  • Innovation

Useful

  • About
  • Membership
  • Get involved
  • News
  • Jobs

Get in touch

  • Contact us
  • Sign up to our newsletter
  • Twitter
  • Facebook
  • LinkedIn
  • YouTube
  • Cookies
  • Privacy
  • Modern slavery
  • Carbon reduction plan
  • Accessibility