If you work in the UK’s early years sector, the news about the Kido nursery cyber attack in London should send shockwaves through you.
This is not just a theoretical risk. It is a horrifying reality where cyber criminals, operating under the name Radiant, have proved they are willing to attack vulnerable organisations and exploit the most sensitive data, our children’s records.
The breach is a stark reminder that every nursery, pre-school, and childminder must stop thinking of cyber security as an optional IT expense. It should be treated as the highest level of safeguarding.
The Scale of the Crisis
Radiant did not simply breach a firewall. They shattered the trust between a nursery chain and its families. The group reportedly stole images and data relating to over 8,000 children and their parents. Worse still, they have told news agencies that they are prepared to release another devastating batch of information.
The stolen data includes:
- Children’s most personal records: This is not just names and addresses. It includes confidential medical records, detailed incident reports, and documentation relating to the allocation of drugs and medicine.
- Employee profiles: Staff data is also exposed, including full names, addresses, dates of birth, and critical information such as National Insurance numbers, making identity theft a real risk.
This was not just a financial hit for Kido. It was an attack on the deepest trust parents place in childcare providers.
Why You Cannot Afford to Pay the Ransom

The criminals typically demand a huge payout, often around 1.5% of annual revenue. However, the advice from experts, including former NCSC chief Ciaran Martin, is clear: do not pay them.
As Martin points out, the data is already stolen. Paying a ransom does not guarantee deletion or suppression. Hacking groups often sell the stolen data on to other criminals regardless. Paying only funds the next attack and proves that the early years sector is a soft target.
Your Action Plan: Essential Steps for Every Early Years Setting
It is time to act decisively. Below is a practical, no-nonsense checklist of what your setting must implement immediately to defend against the next inevitable attack.
1. Stop Hoarding: Only Keep What You Need
You cannot lose data you do not have. Many nurseries keep files longer than necessary because of fear they might be needed later.
- Implement a strict data retention policy: Follow ICO guidelines and delete personal records, employee files, and medical reports once they pass their legal or necessary retention date.
- Encrypt your most sensitive files: Any data that absolutely must be retained, such as staff NI numbers, should be stored in an encrypted location. Ideally, use a dedicated secure folder or cloud system that requires a separate access key.
2. Mandatory Tech Defences (No Excuses)
The basics must be non-negotiable for every member of staff.
- Multi-Factor Authentication (MFA): If you only do one thing, make it this. MFA should be mandatory for every account that handles sensitive data — email, HR, and nursery management software. Even if a hacker steals a password, they cannot log in without a secondary code from the staff member’s phone.
- Patch everything: Those little update notifications on laptops or nursery management systems are often security patches. Install updates immediately. Out-of-date software is one of the easiest ways for criminals to gain access.
3. The Non-Negotiable Backup Plan
If ransomware locks your system, a clean backup is the only way to recover without paying criminals.
- Follow the 3-2-1 rule: Keep 3 copies of your critical data, store them on 2 different types of media, and ensure 1 copy is completely offline (physically disconnected from the network or cloud). This “air gap” ensures ransomware cannot reach your backup.
4. Continuous, Realistic Staff Training
People are always the weakest link. Your staff must become your frontline defence.
- Test your team: Do not rely on slideshows. Run fake phishing exercises by sending official-looking but fraudulent emails (such as a “final invoice” from an unknown supplier) and see who clicks. Use mistakes as teaching opportunities, not punishments.
- Phishing awareness: Train staff to spot urgency, unusual senders, and poor grammar. These are classic signs of phishing attacks that often deliver ransomware.
The Lesson from Kido
The Kido attack is a profoundly painful event, but it must not be ignored. Every early years setting in the UK should take this as the wake-up call to improve security.
Protecting the data of children in your care is now as essential as maintaining safe staff ratios and secure premises.
Is your nursery management team reviewing security protocols today, or are you waiting for a hacker to deliver the wake-up call to your door?
