Skip to main content

Business email compromise (BEC) playbook 

This playbook has technical guidance for responding to a business email compromise incident. It is not a standalone resource: use it alongside your incident management plan to make sure it works for your school.

Reporting

Report all cyber incidents immediately to the relevant authority.

Your SLT digital lead is responsible for assigning someone to report any suspicious cyber incidents or attacks to the following if applicable:

If a financial loss is identified, immediately report to Report Fraud through their website or by calling 0300 123 2040.

If personal data is involved, you must inform the ICO within 72 hours.

Give as much information as you can about:

  • the nature of the breach
  • how and when it occurred
  • people impacted
  • actions taken
  • relevant contact details

Contact your local police authority if you suspect a financial or safeguarding impact.

Department for Education RPA team

If you are a member of the RPA membership scheme, contact the RPA Emergency Assistance Helpline:

Service providers

If the breach affected a third-party service or system, let the service providers know. They should be involved in a coordinated response to the incident.

Insurance providers

If you have private insurance and your coverage includes cyber incidents, contact your insurer. They may provide direct recovery assistance.