Exam Policies
Cyber Incident Response Policy
Prevention
All Centre staff with access to Awarding Body Secure Portals and / or exam related software will complete a centre approved annual Cyber Security training and downloaded certificates will be held on file for inspection purposes. Staff failing to complete this training and provide certification by the given deadline will have their access to AB secure portals immediately removed until they have completed the training and provided their annual certification.
The centre will make use of multi-factor authentication for access to secure devices and portals to limit the risk of a cyber incident.
Centre staff will not share passwords or login information with anyone. Staff who are found to be in reach of this will have their access suspended and a malpractice report submitted to the applicable Awarding Body.
NEA
Candidates complete work on their own devices for low-level control and would not be impacted during a cyber incident.
Where work has been submitted and marking/moderation has been completed, marks should be provided to candidates as per the policy as quickly as possible.
Work should be submitted as soon as is possible to Awarding Bodies to minimise any disruption.
High Level control NEA should be backed up and securely stored on encrypted portable storage until submitted to Awarding Body. A copy to be held in secure storage and a further back up to be held off site in a secure location (cloud or data centre).
All submissions from candidates will be scanned for virus/malware etc prior to being opened for marking.
Public written exams
Online exam / AA candidates
The impact on exams desktops will depend on the type of attack that we are experiencing, so the below will be worst case scenario.
Exam desktops only need access to a local drive to complete the current exam, so the impact would be based on the IT Teams initial assessment and which servers have been impacted/could be impacted by the breach.
These decisions would need to be made quickly and without consultation in the initial phase and decisions made are to reduce impact not only to the organisation as a whole, but also with future exams and speed of recovery in mind.
Once a cyber incident has been identified, the IT Team will already have engaged the following;
• Identify source and scope of the attack
• Informed the Head of Centre and Exam Officer
• Disconnected any infected devices and removed connectivity from the centre site at the network level– including internet connectivity
• At this Identification and isolation stage the cyber incident containment would take priority over an exam invigilator device or exam desktop user. There is potential for disruption or a need to stop the use of technology during an exam in this phase.
This situation would create critical issues that would need to be discussed discussion with the IT team and HoC;
• Landline phones would all be offline
• Internet would be offline – inability to access Awarding Body platforms
• Email communication to people within the centre would be offline other than via 4G devices
• Exams Officer would be added to this working party discussion in a situation where a cyber incident is affecting exams
We will plan the response including;
• Eradicating the root cause of the cyber attack
• Restoring services and the timeframe that this could take (Estimated to be anything from 2-10 days depending on the risk/spread/likelihood of re-occurrence). Exams would be prioritised where possible to ensure this is the first thing to be fully operational, where practically possible
• Engaging external suppliers if necessary
• Adding relevant people into the working group depending on the type of attack and systems it has impacted (eg – If CCTV is affected the Property Manager would need to be involved) – Exams Officer already included at this point
• Planning communication to candidates, staff, and Awarding Bodies
• Contingency plan for Exams to be put into place during restoration of services – Chnoor to consider switching to paper/special consideration for affected candidates etc.
The process to assess would be as follows;
1. Assess the impact of the cyber incident on the centre and exams
2. Look at the likeliest scenario below given the type of incident
3. IT will work on recovery while exams team implements action plans based on the scenario below. This could include pausing exams/isolating exam candidates while the recovery is processed depending on expected timeframes.
Scenario 1 – The cyber incident affects Wi-Fi connectivity
The Desktops will lose connectivity to the server, which will cause any Exam Writepad software being accessed via the network to crash – standalone exam computers with local access to writepad would remain unaffected. The completed work auto-recovery will have saved at the last manual/autosave point. This file will only be recoverable in a situation where the file server is able to be accessed. This would be entirely dependent on the cyber incident itself. This file may only be recoverable once the cyber incident is over.
With the desktops offline there is no potential for the virus to spread to others, therefore they can be used to continue the exam, but they will need to start from scratch on a notepad or local exam writepad file on a new save if they have been accessing a networked version. It is recommended that they start from the question after the one they were last working on (depending on the type of exam). This will be the candidate’s choice.
Subsequent exams could continue in offline mode with files being saved to a memory stick until IT Services are fully restored
Scenario 2 – The Cyber incident affects the servers including the one that runs the Exam Write Pad software but Wi-Fi connectivity can continue
The Desktops will lose connectivity to the server, which will cause any networked Exam Writepad software to crash. The completed work auto-recovery will have saved at the last manual/autosave point. This file will only be recoverable in a situation where the file server is able to be accessed. This would be entirely dependent on the cyber incident itself. This file may be recoverable before the cyber incident is over depending on what the incident is.
Once the file is recovered the users could continue locally using notepad or local exam writepad file on a new save if they have been accessing a networked version. It is recommended that they start from the question after the one they were last working on (depending on the type of exam). This will be the candidate’s choice.
unless the cyber incident dictates that every device will need to be disconnected from Wifi.
Subsequent exams could continue in offline mode with files being saved to a memory stick until IT Services are fully restored
Scenario 3 – The Cyber incident affects both the Server, Wi-Fi, and has spread to all devices including exam desktops
In this scenario exams will have to pause immediately and will not be able to resume until the cyber incident is over and the dis-infect/patch process is in process. The timeframe for this is dependent on the incident severity and the timeframe of patching which will be discussed by the response team. Exam desktops will be prioritised accordingly to get them back up and running in as highest priority
In this scenario we would either look at moving the exams to being tech free until it is safe to continue, or if IT usage is critical we could look at making an offline/off site setup (in the case of Awarding Body timetabled public exams) or contacting the Awarding Body to postpone and reschedule the exam (in the case of on-demand testing or Awarding Body testing window).
Access to Awarding Bodies, Results etc
Exam Officer has independent access to Awarding Body secure sites, these can be accessed from any machine outside of the centre network if necessary or from another secure location if cyber incident is localised to LPTC.
Files would be stored locally (and encrypted) on Exam Officer’s personal device (or encypted portable storage device) with secure access and moved over to centre device as soon as services restored. Files would then be permanently removed from the personal device.
In all circumstances on exam days relevant Awarding Bodies would be notified and Special Consideration applied for as applicable.
| Name of policy: | Exams – Public: Cyber Incident Response Policy |
| Reviewed by: | Head of Centre |
| Date: | September 2025 |
| Date of next review: | September 2026 |
SUPPORTED BY










© 2023 London Professional Training College is a company registered in England and Wales. Registration number 12881385.
