Security-Minded Communications for Schools: A Plain Guide to What You Share
By Simon Legrand, Chief Security Officer at Fyrfly Systems·
A school is open and welcoming by design, and that is exactly as it should be. The difficulty is that the same openness which reassures parents can, without anyone intending it, hand a person planning harm a working map of your site. Security-Minded Communications is the simple, no-cost habit of checking what you publish before you publish it. This is a plain guide to it, written for the people who actually run a school's website, newsletters and social media, and drawn from the government's guidance for educational settings.
Prefer a version you can circulate? Download this as a one-page staff and governor briefing, ready to print or attach to a security culture pack.
What Security-Minded Communications actually means
Strip away the jargon and it is one idea: think like the reader you do not want. Almost everything a school puts into the public domain is there for a good reason, to inform parents, promote an event, celebrate a success or advertise a facility for hire. Security-Minded Communications simply asks you to pause and consider whether the same information could also help someone with bad intentions, and whether you can share what is useful to your real audience without gifting what is useful to them.
It works in two directions. The first is denying: not accidentally giving away detail that would help someone plan. The second is deterring: using your communications to show that your school is alert, connected and not an easy target. Neither costs money. Both apply to the ordinary channels you already use, your website, newsletters, social media, noticeboards, leaflets, posters, open day maps and virtual tours.
Who this is protecting against, and what they look for
The official guidance uses the word "hostile" for a person who wants to attack or disrupt an organisation, whether for profit or to make a political or ideological point. It is a broad term, and for a school the more useful way to hold it is simply "someone intending harm", which can range from a persistent nuisance to a genuine threat.
Whatever the motive, the planning tends to follow a pattern: settling on a target, working out the detail, and confirming what they think they know. A large part of that is what specialists call hostile reconnaissance, which is just purposeful watching and information gathering aimed at a specific place. Someone at this stage is trying to answer practical questions. Is this a suitable target? When is it busiest, or emptiest? What method would work? What security is in place, and where are the gaps?
They gather the answers in two ways. Online, from your website, from Google Maps and Street View, from photographs and videos on social media, and from anything published about your events. And in person, by visiting, watching and sometimes by talking to people, including current or former staff, contractors, volunteers, parents and pupils who may share more than they realise.
A documented case. In one real example examined after the fact, an individual who was planning to attack a school assembled much of what he needed from the school's own website, from Google Maps, Street View and YouTube, and topped it up with quiet visits to the site, some made in a work uniform that let him blend in. None of it was challenged or noticed at the time. The lesson is not to frighten anyone. It is that the information was freely available and the watching went unseen, and both of those are things a school can change. (Case documented by Jersey Police, cited in the NPSA guidance.)
Denying useful information: the questions to ask before you publish
Before anything goes out, three questions do most of the work. How much detail do I actually need to share here? Can I give my real audience what they need without handing a planner what they want? And if I genuinely must publish the detail, can I do it in a way that makes it less useful to someone with bad intent?
In practice that turns into a handful of habits worth building into how your communications are produced:
Look back at what is already public, and at what you are about to post, and check you are not quietly gifting something useful. This one review, done honestly, catches most of it.
Keep the most detailed information in closed channels, a mailing list, a private group or a booking system, and publish a lighter version openly with an option to request more. Not everything needs to sit on an open web page.
Be careful with exact numbers. Advertising that an event has "only 100 places" and then filling them tells anyone watching how large the crowd will be.
On maps, open day plans and virtual tours, show public areas only and leave out corridor layouts, internal dimensions, and entrance and exit detail. Ask whether an unescorted stranger could navigate your site from what you have published, and consider whether escorted-only visits are more appropriate.
Avoid publishing named, direct personal contact details, which also help a targeted phishing attempt. Use shared school addresses, central phone numbers and the main site address for public-facing material.
Where you can, talk about an event after it has happened rather than trailing it in advance. You keep the positive story and remove the advance notice, which matters most when a high-profile guest is involved.
Using your communications to deter
The other half is quieter and often overlooked. The same research behind this guidance shows that people planning harm are put off by the sense that a place is switched on, and that ordinary site users actually want to hear that their school takes security seriously. Done with care, deterrence reassures your community and discourages a planner at the same time.
Promote the security you genuinely have, and only that. A short line that you run staff sign-in, keep CCTV or work with local police is a real deterrent. Inventing measures you do not have is worse than saying nothing, because it collapses the moment it is tested.
Choose reassuring words over alarming ones. "Keep an eye out for anything out of the ordinary" lands better than "report suspicious people", and "we work to keep the site secure" better than "we stop criminals and terrorists". You want regular users calmer, not anxious.
Show your connections. A post about a visit from a local officer or Safer Schools contact, or a mention that you work with neighbouring organisations, projects a network of vigilance that reaches beyond your gate.
Be vague about when the site is empty. Posts that appear across evenings and holidays give the impression of activity and make it harder to work out a quiet moment.
In photographs, let staff and volunteers be recognisable as staff, by a lanyard or pass, but avoid showing pass detail clearly enough to be copied.
Make it obvious how to raise a concern, and that it will be taken seriously. Point people to 999 in an emergency, 101 otherwise, the confidential Anti-Terrorist Hotline on 0800 789 321, or reporting online at gov.uk/ACT.
A five-minute starting point
You do not need a project to begin. Run this quick self-check, and treat any "no" as your next small task.
Have we looked at our website, social media and newsletters through the eyes of someone intending harm in the last year?
Do our maps and virtual tours show public areas only, without corridor, exit or dimension detail?
Do our event posts avoid exact capacity and precise timings where they are not genuinely needed?
Do our public materials use central school contact details rather than personal ones?
Do we promote only the security measures we actually have in place?
Is our safety language reassuring rather than alarming?
Do staff and volunteers know what hostile reconnaissance is and how to report something that feels out of place?
Where this sits, and what to do next
This is a layer of security that costs nothing and is not something you buy, from us or anyone else. It is a habit, and the honest advice is to build it before you spend on anything, then keep applying it to everything you publish. When you are ready to go further, the sources below are the right next steps.
See, Check and Notify (SCaN) and the Action Counters Terrorism (ACT) e-learning, free staff training that pairs naturally with this, both signposted from ProtectUK and your local Counter Terrorism Security Adviser.
Our Power-Off Checklist, the companion Preparedness piece on what keeps working when the power or broadband goes down.
Promoting security you can stand behind
Deterrence only works when the measures are real. A free Fyrfly site survey gives you an honest picture of what your school genuinely has in place, so that when you promote it you are on solid ground, and shows you where the practical gaps are. No pressure and no fear-selling.