KCSIE 2026: how Fortinet can help schools meet their online-safety duties
Keeping Children Safe in Education 2026 comes into force on 1 September 2026. It makes online safety part of a school or college’s wider safeguarding responsibility. Appropriate filtering and monitoring are essential, but installing a firewall is not enough. Leaders must choose controls that reflect their pupils, devices and ways of working, check that the controls remain effective and make sure concerns reach the right people quickly.
A well-designed Fortinet solution can provide much of the technical foundation: age- and role-appropriate web filtering, application control, safe search, user-level logging, alerts and reports. It can also extend protection to managed devices away from school. The school still owns its safeguarding decisions, policies, staff training and response to concerns.
What does KCSIE 2026 require for online safety?
KCSIE applies to schools and colleges in England. It expects a whole-setting approach which protects and educates children and provides a way to identify, intervene in and escalate concerns. It groups online risk into the “4 Cs”:
- Content: exposure to illegal, inappropriate or harmful material, including pornography, self-harm, extremism, misinformation and violent content.
- Contact: harmful interaction with other users or generative-AI applications, including grooming, exploitation and peer pressure.
- Conduct: behaviour which causes or increases harm, including online bullying and making, sending or receiving explicit images, including AI-generated images.
- Commerce: gambling, inappropriate advertising, phishing and financial scams.
Online safety should run through safeguarding policies, the curriculum, staff training, the role of the designated safeguarding lead (DSL) and engagement with parents. The child protection policy should include appropriate filtering and monitoring on school devices and networks.
The core filtering and monitoring duties
KCSIE 2026 says governing bodies and proprietors should do all they reasonably can to limit children’s exposure to online risks through the school or college IT system. It points settings to the Department for Education’s filtering and monitoring standard, which schools and colleges should already be meeting.
1. Assign clear roles and responsibilities
The governing body or proprietor retains overall strategic responsibility. A senior leadership team member and a governor should be assigned responsibility for the standards. The DSL should lead on safeguarding and online safety, while in-house or third-party IT support maintains the technology, completes checks and provides reports. These roles must work together, but the DSL remains responsible for safeguarding decisions arising from monitoring.
Relevant staff must understand the systems in place and know how to escalate concerns. Safeguarding and child protection training at induction should include the expectations, roles and responsibilities for filtering and monitoring, with regular updates afterwards.
2. Review the provision and keep evidence
Filtering and monitoring must be reviewed at least once every academic year. KCSIE 2026 says the responsible SLT member should lead the review with support from the DSL and IT support. It should include checks that filtering works on all internet-connected devices in relevant locations, with a record kept of those checks.
The review should reflect pupil age, SEND and EAL needs, local safeguarding risks, curriculum requirements, off-site use, BYOD and the system’s technical limitations. It should also be repeated after significant changes such as new devices, remote-access arrangements, generative-AI tools or major configuration changes.
Schools should record when a check happened, who completed it, what was tested and what action followed. This gives governors meaningful assurance and creates useful evidence for inspection.
3. Block harmful content without blocking learning
Filtering should cover school-managed devices, devices taken off-site, BYOD users, guests and every internet feed, including backup connections. It should use the Internet Watch Foundation (IWF) and Counter-Terrorism Internet Referral Unit (CTIRU) lists, block adult content and allow local rules for additional risks.
One blanket policy is not appropriate for everybody. As a minimum, staff and pupils should have different profiles; many settings will need further differences by age, subject or risk. Safe search should be enforced, while legitimate teaching, administration and pupils’ ability to learn about risk should not be unreasonably restricted.
4. Use monitoring that leads to action
Filtering is preventative: it attempts to stop access. Monitoring is reactive: it identifies activity which needs attention. The DfE standard says a monitoring plan should include weekly incident reports and immediate reporting of high-risk incidents. Users should be identifiable where possible, and the school needs a documented process for escalation, action and recording the outcome.
Technical monitoring sits alongside good classroom supervision and staff reporting. Depending on the school’s risk assessment, device-level monitoring may also be needed because network filtering cannot see every action inside mobile apps, encrypted services or content created locally on a device.
How Fortinet supports KCSIE 2026
FortiGate and FortiGuard: the filtering foundation
A FortiGate next-generation firewall, using the FortiGuard Web Filtering service, can classify and control websites across more than 90 categories. Fortinet provides dedicated Child Sexual Abuse and Terrorism categories for the IWF and CTIRU feeds, with blocking and logging. Policies can also cover pornography, extremism, self-harm, gambling, malware, phishing and other categories selected through the school’s risk assessment.
FortiGate can apply different policies to staff, pupils and guests through user groups and network segmentation. DNS and web filtering can enforce safe search and restricted YouTube modes, while application control can manage services which do not behave like traditional websites. Local allow and block rules make it possible to correct over-blocking or respond to a new risk without replacing the whole system.
Most web traffic is encrypted. Some content-level controls and search reporting therefore require carefully configured SSL inspection. This needs planned certificate deployment, privacy exemptions and a data protection impact assessment rather than simply switching on inspection for every user and service.
FortiAnalyzer: monitoring, alerts and review evidence
FortiAnalyzer turns firewall and security logs into dashboards, scheduled reports and alert workflows. Current FortiAnalyzer releases include safeguarding features which can identify risk-related keywords in web, application-control and email-filter logs. Built-in categories include cyberbullying, extremism, pornography, self-harm and violence or terrorism.
Reports can support the required weekly review, while high-risk events can be routed to nominated staff for prompt attention. Identifying users through directory integration gives the DSL more useful information than an unexplained IP address. Reports and retained logs can also support the annual review and show what was checked, what was found and whether policies need to change.
Alerts are indicators, not safeguarding conclusions. They need appropriate thresholds, access controls and human review, with false positives handled sensitively. The school’s agreed process should determine who receives an alert and what happens next.
FortiClient or FortiSASE: protection beyond the school gate
A perimeter firewall only sees traffic which passes through it. Where school-managed laptops are used at home, FortiClient or FortiSASE can apply web controls away from the school network. The right design depends on device ownership, operating system, existing management tools and whether traffic is routed back to school or secured through a cloud service.
Cyber security as part of safeguarding
KCSIE 2026 also connects the protection of personal information and appropriate cyber security with wider safeguarding. FortiGate can combine filtering with anti-malware, intrusion prevention, application control and protection from malicious or phishing sites. FortiSwitch and FortiAP can separate pupil, staff, guest and unmanaged devices, reducing the chance that one compromised device exposes sensitive school systems.
Three levels of support
The right level depends on the expertise available in-house, the number of sites and devices, and who has time to maintain controls and turn reports into action.
Level 1: design, deployment and handover
This suits a school, college or trust with capable internal IT support. We assess the network, configure the FortiGate and FortiGuard services, create separate staff, pupil and guest policies, enable appropriate logging and safe search, test the main filtering categories and document the configuration. The in-house team then manages routine policy changes, reports and checks.
Level 2: co-managed filtering and monitoring
In a co-managed model, the school retains day-to-day ownership while Bletchley Networks provides technical maintenance, configuration changes, troubleshooting and reporting support. We can help create scheduled weekly reports and technical high-risk alerts, while the DSL reviews safeguarding information and decides what action is required. This model adds specialist support without removing local control.
Level 3: fully managed technical service
For settings without dedicated security expertise, we can provide ongoing management of the Fortinet environment, including policy maintenance, software and subscription oversight, system-health monitoring, multi-site consistency, reporting and technical evidence for the annual review. Off-site filtering and FortiAnalyzer safeguarding workflows can be added where the risk assessment supports them.
“Fully managed” applies to the technology, not the school’s statutory safeguarding role. Governors and leaders still need assurance, staff still need training, and the DSL must own the safeguarding response. Any third party handling monitoring data should have clearly documented responsibilities, appropriate safeguarding training and suitable data protection arrangements.
Questions to ask before choosing a solution
- Does it use the IWF and CTIRU lists, and can local administrators override those protected lists?
- Are staff, pupils, guests and different age groups given appropriate policies rather than blanket policies?
- Does protection cover every site, backup connection, BYOD network and managed device used off-site?
- Can safe search, encrypted traffic and applications be handled without unacceptable privacy or performance impacts?
- Can reports identify a user and provide a clear weekly view, with immediate alerts for agreed high-risk events?
- Who checks alerts, who informs the DSL and how are actions and outcomes recorded?
- What cannot the solution see, and is separate device-level monitoring needed?
- How will the school test, document and review the system throughout the year?
The bottom line
KCSIE 2026 is not a product specification. It is an ongoing safeguarding responsibility supported by appropriate technology, people, policy and evidence. Fortinet can deliver granular filtering, useful network monitoring, off-site protection and strong cyber security in one integrated platform. Bletchley Networks can design, co-manage or fully manage the technical service around the school’s own risk assessment and safeguarding process.
This article provides general information for education settings in England and is not legal or safeguarding advice. Always use the current statutory guidance and your local safeguarding arrangements.