Back to Resources
Beyond the Gates 2: From scattered warning signs to school intelligence and cyber safeguarding capability
OSINT

Beyond the Gates 2: From scattered warning signs to school intelligence and cyber safeguarding capability

A practical sequel to "Beyond the Gates". The Coalition of Cyber Investigators sets out how schools can move from scattered warning signs to a governed, intelligence-led safeguarding capability - receiving, grading, corroborating, sharing and acting on information lawfully, while protecting children from both genuine threats and careless suspicion. Includes a practical ninety-day start for schools and six recommended next steps.

Paul Wright & Neal Ysart24 August 202615 min read
Share

A practical sequel to "Beyond the Gates: Using OSINT to Help Prevent School Shootings"

The next maturity step is not only searching for leakage. It must also include a governed process for receiving, grading, corroborating, sharing, and acting on information while protecting children from both genuine threats and careless suspicion.

THE GATE WAS NEVER THE WHOLE PERIMETER

The first Beyond the Gates article made a simple, uncomfortable argument: warning signs do not politely remain on school property. They leak into public posts, gaming communities, video comments, group channels, search results and the odd digital cul-de-sac that adults rarely visit. Lawful open-source intelligence (OSINT) can help schools, education authorities, and law enforcement bodies see some of that leakage. It can also go badly wrong - quickly - if well-intentioned curiosity outruns governance.

So, the next question is not whether schools should "do OSINT". That phrase is almost too superficial. The real question is how the authorities turn fragments of intelligence into a safeguarding decision without turning children into suspects, rumours into facts, or a worried teacher into an amateur detective with twenty browser tabs open.

Imagine the start of an ordinary day where someone mentions a post. Someone else remembers a drawing, a grievance, a strange comment made on the bus. None of it is conclusive, and it all may be nothing at all. And yet, when all the pieces are placed on the same table, it provides an opportunity to adopt a structured, more thorough analysis of the available information, rather than a well-intentioned but haphazard approach.

That is where an intelligence-led safeguarding model begins.

FROM INFORMATION TO INTELLIGENCE

Schools already collect information, although they rarely call it intelligence. It could take the form of unexplained attendance changes, pastoral referrals, reports from parents, or a pupil quietly telling a teaching assistant that a friend has become obsessed with an attacker. It may also originate from beyond the school gates, for example, via a public social media account where increasingly specific threats are being posted, or neighbouring schools noticing the same impersonation campaign. Each signal lands in a different system and becomes institutional confetti with nobody joining the dots.

An intelligence capability brings the fragments together through a structured, disciplined cycle: collect only what is relevant; evaluate it; corroborate it; assess meaning and urgency; decide who needs to know; act; then review. While the cycle sounds formal, it should still feel human. A frightened child should never become just another data point, even when their report is entered into a case-management system.

The distinction between raw information and assessed intelligence matters. A screenshot may be authentic but misunderstood. An anonymous tip may be both sincere and false. A public username may belong to three people, or to nobody that the school knows. Context is the oxygen here. Without it, even a technically accurate fact can suffocate good judgment.

This is also why a school intelligence function should sit inside a safeguarding and behavioural threat assessment framework - not in a lonely security silo. The objective is to provide the most effective intervention and support by minimising the chances of missing leakage indicators, while simultaneously protecting the community.

GRADE THE REPORT, NOT THE CHILD

Professional intelligence work accepts something that school gossip often does not: sources vary in reliability, and information varies in credibility. Those are separate questions. However, the importance of grading intelligence consistently cannot be overstated. Even when a school or education authority analyses intelligence in a more structured manner, without grading, it becomes more difficult to ensure that the analysis isn't unduly influenced by emotion, bias, or preconceptions.

For example, a teacher who personally observes a concerning act and can provide evidence of a contemporaneous, publicly accessible post should be graded differently from an anonymous message saying, "everybody knows he is dangerous." Alternatively, a previously reliable source can still be wrong, just as an unknown source can provide information that later proves accurate.

Assessing source reliability and information credibility – in other words, grading the intelligence – will help slow the rush toward unverified certainty or knee-jerk decisions and provide a more measured and consistent way of analysing potentially critical intelligence.

The good news is that intelligence grading doesn't need to be complicated. A simple, well-documented grading scheme is sufficient and will enable the reasons for the grade, any corroboration, any contradictions to the report, and what remains unknown to be recorded and factored into the subsequent analysis of the intelligence. Intelligence can be regarded as facts that change and are reviewed regularly. This creates an audit trail for safeguarding leaders, law enforcement and, if necessary, legal review. More importantly, it protects pupils from conclusions that harden merely because they were typed in bold or made by someone deemed "important" or with a louder voice than others.

And never grade the child. Grade the source and the content. Assess behaviour and circumstances, not identity, awkwardness, politics, disability, music, clothing or a teenager's taste in bleak jokes. The difference is enormous.

THE INTELLIGENCE DESK DOES NOT NEED TO BE A ROOM

Most schools do not need a command centre. They need named ownership and a repeatable, disciplined meeting rhythm. A small coordination group including roles such as a safeguarding lead, senior administrator, pastoral or mental health professional, security representative, and IT/cyber lead can review credible concerns. Other specialists can join when necessary.

From a confidentiality perspective, intelligence analysis should be on a "need-to-know" basis, and that should mean "need-to-know", not "everyone on the email chain."

The group should have one intake route, an escalation threshold, and a case record. It also needs permission to stop. If a concern is not substantiated, they must be able to close it, record why (in a decision log), set a proportionate review point if warranted, and not keep browsing simply because the internet is infinite. Gathering less data isn't laziness or inefficiency – it's good discipline and makes better use of the resources available.

A useful operating question is: "What decision would collecting this additional intelligence change?" If nobody can answer, don't act on it; instead, collect it and make it subject to periodic review.

An effective intelligence capability could be seen as zero-budget security at its strongest. Technology has a place, for example cameras, access control, panic alarms, or analytics, but we shouldn't forget that many failures begin with a propped door, an unreported concern, a visitor waved through, or a policy softened by repetition until it becomes optional.

SPECIALISTS, BOUNDARIES AND THE DARKER CORNERS

We also need to recognise that some enquiries will exceed a school's internal capabilities. Multiple online personas, obfuscated identities, extremist subcultures such as NVE networks, coordinated harassment, stolen credentials or credible discussion of an attack may require a trained cyber investigator. The school's job is then to preserve what it lawfully has, document the safeguarding rationale and refer - what it shouldn't do is improvise.

Focused examination of public communities is a critical component of detecting leakage, especially after a specific concern has been identified. Online sources such as public Reddit communities, open Telegram channels, public Discord servers, gaming forums, image boards, and video platforms often provide context that helps identify potential leakage, or evidence to support or weaken an allegation. However, this is where the specialist skills of cyber investigators and intelligence professionals are essential to avoid the perception of pupil surveillance. The distinction is important and relies on the discipline of professional intelligence gathering methodologies. Professional inquiry is framed by well-documented concerns and performed within the procedural parameters of open-source intelligence gathering – not pupil targeting. It examines only publicly available material; it is proportionate to the threat and consistently documented in a decision log that can withstand scrutiny.

Surveillance, by contrast, is speculative, unstructured, and can be highly personal. Professionals stay on the right side of that line by investigating the concern rather than the child: they assess whether a threat is credible, corroborated and escalating, not whether a teenager's browsing habits are unusual. They work to defined intelligence requirements, close inquiries that are not substantiated, and retain only what the case record justifies. Performed properly and positioned within an effective governance structure, the pupil will never be the subject of monitoring, but the threat will be.

Dark-web work is similar in that it should almost never be performed by school staff. Where intelligence suggests a real nexus - attack planning, ransomware targeting the school, traded credentials, or another serious threat - these types of inquiries belong with law enforcement or an appropriately governed and experienced specialist. At school level, safeguarding specialists should never enter closed communities under false pretences, contact a subject, download unlawful material, or tip people off. Legal and procedural safeguards, not ordinarily available to schools, are essential in these circumstances and not only could a well-intentioned "amateur" put themselves at risk, but they could also interfere with an ongoing investigation or ruin the chance to identify real signals of impending violence.

THE STRONGEST SENSOR IS STILL A PERSON – MAKE IT EASY FOR THEM TO REPORT THEIR CONCERNS

Research on averted school attacks has repeatedly found that plots are often preceded by observable behaviour and communications, and that intervention becomes possible when somebody reports what they know. The operative words are "somebody" and "reports". Friends and classmates may see the post first. A bus driver might notice a pupil has stopped sitting with anyone. A school nurse hears something that does not quite fit. The school's sensor network, in other words, is not a system but its people - catering staff, cleaners, coaches, librarians, parents. Different sightlines, same building and all with an equal part to play.

Reporting systems, therefore, must be confidential, easy to find, and safe to use. They must also explain what happens next.

Students will not report if they believe that a disclosure could result in punishment, public drama, or not be taken seriously. In the corporate world, whistleblowing mechanisms have matured to the extent that they have their own international standard (ISO 37002); however, in one aspect, schools face the same dynamic as multinational companies – if you expect people to report concerns, users need to be able to trust the reporting system is confidential and have confidence that concerns will be taken seriously.

Security officers also deserve particular attention. In the face of threats of school violence, guarding a gate is no longer enough, if it ever was. Officers working around children need training in de-escalation, trauma-aware communication, behavioural observation, safeguarding referral, digital evidence preservation and the very unglamorous craft of writing an accurate incident note. Officers trained to read adults are more likely to misread children: young people talk, push boundaries and live online in ways that typical adult-focused security training never anticipated.

SHARE PATTERNS WITHOUT BUILDING A RUMOUR MARKET

Threats of violence do not respect institutional boundaries. Pupils mix across schools, sports clubs, transport routes and online communities; harassment and impersonation campaigns do the same. However, formalising school-to-school intelligence-sharing arrangements can help reveal a pattern that each campus, on its own, sees only as static.

Like all intelligence-sharing mechanisms, a school-to-school system requires robust principles and controls.

Principles and controls for sharing:

  • Share only the minimum necessary information, through named safeguarding contacts, under an agreed legal basis and handling rules.
  • Anonymised intelligence is often the most useful: a fraudulent account format, a harmful challenge circulating locally, a swatting script, a cluster of credential theft, a new method of contacting younger pupils.
  • Once information identifies a real child, the rules tighten: share it only if you can justify why it's needed - "might be useful" is not a governance framework.

Build law enforcement relationships before the sirens:

  • Know who to contact in your local cybercrime or digital investigation unit.
  • Know exactly who to contact when a threat is imminent.
  • Know where to send material that is not urgent but still requires professional assessment.
  • Don't just save the phone numbers – call them.
  • Test how you would transfer evidence before you ever need to.

The 2025 wave of hoax active shooter calls against universities, and the FBI's April 2026 case alleging paid swatting against campuses, underline the point: a false report can be coordinated entirely online, geographically remote - but the panic it triggers at a school can be very real.

TEACH CAPABILITY WITHOUT RECRUITING CHILD INVESTIGATORS

Young people with advanced technical curiosity need an ethical runway. The United Kingdom's Cyber Choices programme offers one model: early education in the UK Computer Misuse Act, the lawful use of technical skills, and routes into cyber careers. A UK National Crime Agency (NCA) commissioned evaluation reported that participants reoffended in cyber-dependent offences at approximately half the rate of a benchmark group, with overall proven reoffending also at less than half that rate. This is not a magical fifty-per cent 'success rate'; the wording matters. It is evidence that early diversion can change trajectories.

Schools can build a parallel culture through cyber-awareness sessions, law enforcement engagement, visits to digital forensics teams, and age-appropriate lessons on privacy, online manipulation, digital ethics, and careers. A Cyber Cadet programme may help too - but cadets must never investigate classmates. They are peer educators and safety ambassadors, full stop. Encourage them to promote strong passwords, reporting routes, critical thinking and respectful online conduct.

Anonymous surveys and classroom discussions can help adults understand which platforms pupils use and what they encounter in them. That is education-led insight, not covert monitoring.

SAFETY BY DESIGN, ON AND OFF THE DEVICE

The companion policy paper "Securing Childhood" pushes the perimeter further outward into the home. Parents, it argues, are being asked to police apps and platforms that are open by default, driven by opaque recommendation engines and whose safety controls are buried three menus deep. That is a design flaw, not a parenting failure.

For schools, the practical consequence is twofold. First, schools should play a role in providing parents with specific information on how to protect their children online. This could include advice on how to, for example, configure parental controls such as Family Link or Screen Time, restrict age-inappropriate downloads, understand private messaging, recognise grooming patterns, and recognise when children are bypassing controls. Second, schools should add their institutional voice to calls for safer defaults, meaningful age assurance, understandable and intuitive controls and structured risk assessments of services used by pupils.

Yet restrictions alone are not enough. Children still need trusted adults they can confide in without fear of being shouted at or dismissed. Technical controls block some risks; policy sets minimum standards; but it is relationships that catch what the other two miss. This may sound less impressive than sophisticated metal detectors and security cameras. It is not. Trust is the most difficult safeguard to build, but the effort is worthwhile as it's the one most likely to surface a threat before it reaches the school gates.

Physical standards remain relevant too. Panic-alarm laws such as Alyssa's Law in several US states, Clery Act duties for US higher-education institutions, and occupational-safety frameworks such as ISO 45001 each address different parts of readiness and accountability. The lesson for schools is not to choose between physical and digital safeguards, but to recognise that the expectation of a hard physical perimeter addresses only half the problem: alarms and security guards are prioritised, while the intelligence discipline that might prevent the alarm from ever sounding remains optional.

A PRACTICAL NINETY-DAY START FOR SCHOOLS

Ninety days is enough for schools to build the skeleton of an intelligence capability that will help them identify signs of leakage and detect online threats. None of it requires new software, new staff or sophisticated dashboards. It does, however, require making some decisions, documenting procedures, and maintaining discipline.

Days 1–30:

  • Appoint an intelligence-and-safeguarding lead.
  • Map how concerns currently reach you.
  • Confirm your police contacts.
  • Publish an emergency threshold so that everyone knows what triggers an emergency call.
  • Audit what the internet already knows about your campus.
  • Take down the old floor plan.
  • Blur the lanyard in the staff photo.

These might seem like small fixes, but they deal with real exposure.

Days 31–60:

  • Adopt a two-part information grading method, a standard case note format, and preservation guidance.
  • Provide the coordination group with clear, written terms of reference.
  • Train staff on what to report and what not to investigate.
  • Run one tabletop scenario involving an ambiguous public post, a competing rumour, and a frightened parent.

Days 61–90:

  • Set up a lawful school-to-school sharing arrangement.
  • Run a pupil and parent awareness session.
  • Identify trusted external specialists - checked out in advance - that the school can call on when a case exceeds its in-house expertise.
  • Review retention and deletion decisions so you are clear about what you're keeping and why. Then test the whole chain, end to end.

Measure what matters including: reporting confidence, assessment speed, referral quality, case closures, training reach, and corrective actions made after exercises. Do not measure success by how many pupils you're monitoring. If that number rises, something has gone wrong.

BEYOND THE GATES, AGAIN

A school's security boundary no longer stops at the gates. It extends into pupils' phones, their group chats, their online accounts, their friendships and home life – all of which means it cannot be guarded by locks and cameras alone.

OSINT can help and can proactively identify leakage indicators, but it is only one collection discipline within a larger safeguarding system. The mature capability is quieter: a student knows where to report; a teacher records what was actually observed; an analyst grades rather than guesses; a safeguarding lead brings context; a specialist stays within lawful boundaries; police receive preserved evidence through a familiar route; and an intervention is chosen that protects people without crushing the child at its centre.

No school can predict every act of violence, and anyone claiming otherwise isn't being honest. But schools can get better at noticing leakage signals, testing and analysing them, carefully connecting them, and acting before the threat becomes an attack.

RECOMMENDED NEXT STEPS

The next move is not a national surveillance platform, or another hollow promise that a new piece of software can predict violence. It should be a controlled implementation programme with visible ownership and the courage to stop when the evidence says stop. Schools and education authorities should begin with six actions.

  1. Name the accountable lead. Appoint one senior safeguarding owner, supported by a small cross-functional group, and give that person authority to convene assessments, close weak cases and escalate urgent ones. Governing boards should have oversight and demand an initial progress report within a term - this is a governance duty, not an IT project.
  2. Set the boundaries before buying tools. Approve written rules covering lawful sources, necessity, proportionality, information grading, retention, deletion and who may authourise specialist support.
  3. Build the referral network now. Confirm named contacts with neighbouring schools, local safeguarding partners, police cybercrime or digital-investigation teams, and a vetted external specialist for complex public-source enquiries. Test those routes with a scenario before a real incident tests them.
  4. Communicate clearly and succinctly. Tell stakeholders, especially pupils and parents, what the school is doing and why, and importantly, how they can report concerns. A system they don't know exists or how to use is unlikely to be a system that anybody reports into.
  5. Run a limited, measurable pilot. Choose a small number of schools or one academy trust, run the framework for a defined period, and record what changed: reporting confidence, assessment speed, corroboration quality, referrals, closures, deletion decisions and unintended harms.
  6. Review, challenge and scale carefully. At the end of the pilot, invite independent safeguarding, legal and privacy review. Publish the lessons that can safely be shared, correct what drifted, and only then decide whether to scale. Success is not more monitoring. It is earlier support, better decisions and fewer preventable surprises.

The school gate still matters.

It just cannot carry the whole weight, and it should no longer be asked to. Every school already holds fragments of the next warning - in an inbox, a chat log, a hesitant conversation with a teaching assistant. The question is not whether the signal will arrive. It is a question of whether anyone will be ready to hear it.

Start the ninety days on Monday.

Authored by:

The Coalition of Cyber Investigators, Paul Wright (United Kingdom) & Neal Ysart (Philippines).

©2026 The Coalition of Cyber Investigators. All rights reserved.

The Coalition of Cyber Investigators is a collaboration between Paul Wright (United Kingdom) - Experienced Cybercrime, Intelligence (OSINT & HUMINT) and Digital Forensics Investigator; Neal Ysart (Philippines) - Elite Investigator & Strategic Risk Advisor, Ex-Big 4 Forensic Leader; and Lajos Antal (Hungary) - Highly experienced expert in cyberforensics, investigations, and cybercrime. The Coalition unites leading experts to deliver cutting-edge research, OSINT, Investigations, & Cybercrime Advisory Services worldwide.

Our co-founders, Paul Wright and Neal Ysart, offer over 80 years of combined professional experience. Their careers span law enforcement, cyber investigations, open-source intelligence, risk management, and strategic risk advisory roles across multiple continents. They have been instrumental in establishing foundational legal precedents and reported cases in cybercrime investigations and in contributing to the development of globally accepted guidance and standards for handling digital evidence. Their leadership and expertise form the foundation of the Coalition's commitment to excellence and ethical practice.

Alongside them, Lajos Antal, a founding member of our Boiler Room Investment Fraud Practice, brings deep expertise in cybercrime investigations, digital forensics, and cyber response, further strengthening our team's capabilities and reach.

The Coalition of Cyber Investigators, with decades of hands-on experience in cyber investigations and OSINT, is uniquely positioned to support organisations facing complex or high-risk investigations.

Our team's expertise is not just theoretical - it's built on years of real-world investigations, a deep understanding of the dynamic nature of digital intelligence, and a commitment to the highest evidential standards.