Home › Education › England's schools are getting better at mopping up cyber...
Education

England's schools are getting better at mopping up cyber incidents

England's schools are getting better at mopping up cyber incidents
Key Points

England's secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by exams regulator Ofqual. Twenty-seven percent of schools reported an incident during the 2025/26 academic year, down from 29 percent a year earlier and 34 percent in 2023/24. Ofqual surveyed 3,775 secondary teachers in England in July.

England's secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by exams regulator Ofqual. Twenty-seven percent of schools reported an incident during the 2025/26 academic year, down from 29 percent a year earlier and 34 percent in 2023/24. Ofqual surveyed 3,775 secondary teachers in England in July. For questions concerning whole schools, it counted one response from the most senior participating teacher at each institution, producing a sample of up to 2,162 schools. Phishing was the most commonly reported type of incident, followed by data protection breaches, hacking, and ransomware. Ransomware affected 2 percent of respondents. Staff data was the information most commonly compromised. Student data was affected in 13 percent of incidents, while student work was affected in one percent. Recovery times improved more clearly. Among schools reporting an incident, 66 percent said they recovered "immediately," up from 55 percent the previous academic year. A further 12 percent recovered within half a school term – roughly six or seven weeks – while one percent took longer than half a term and another one percent required at least a full term. The proportion of reported incidents causing what respondents considered "critical damage" also fell from ten to seven percent, Ofqual said. "Critical damage" was not defined. The regulator told The Register that respondents were free to interpret the question in whatever way they felt best. Ofqual could not explain what had driven the apparent improvement. When asked what cybersecurity improvements their school had made during the past year, 54 percent of teachers selected "I don't know." Among the 46 percent who identified at least one change, half said their school had introduced a cybersecurity policy, 22 percent cited new or tested backup procedures, and 20 percent said they had completed or updated an incident response plan. Teachers were divided over who bears primary responsibility for cybersecurity. Forty-six percent pointed to the IT team, while 40 percent said responsibility was shared among all staff. Just nine percent identified senior leadership. Ofqual argued that cybersecurity is a leadership responsibility rather than solely an IT problem. Mat Pullen, director of education at Jamf, said the attack frequency and recovery figures were promising, but the understanding of security responsibility was a concern. "Reducing incidents matters, but so does recovering faster," Pullen said. "Cyberattacks have closed schools for a week or longer in the past, further disrupting an education already hit by Covid and affecting the wider economy as parents take time off work. "Ultimately, cybersecurity is a shared responsibility of IT, teachers and senior leadership, and breaking down these silos keeps technology secure and lessons running." Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had, up from 28 percent a year earlier. A similar proportion said the training they received was not useful. Of those who received training, 65 percent said they made no changes as a result. Ofqual's findings look considerably rosier than the government's Cyber Security Breaches Survey, published in April. That research found that 49 percent of primary schools, 73 percent of secondary schools, 88 percent of further education colleges, and 98 percent of higher education institutions had identified a breach or attempted attack during the previous 12 months. The figures are not directly comparable. Ofqual asked secondary teachers about cybersecurity "incidents," while the government survey counted identified attacks and breaches regardless of whether they succeeded. The latter also covered education institutions across the UK rather than secondary schools in England alone. Even so, the broader survey illustrated how frequently schools are targeted. Twenty-seven percent of further and higher education institutions identified attacks at least weekly, and almost half of those reporting a breach suffered an adverse impact on their systems. Successful attacks can force schools to close while systems are restored. In June, several schools across England and Wales shut temporarily while technicians investigated a malware scare. The ICO said last year that students were responsible for more than half of cyberattacks attributed to a known actor in the UK education sector. ®
England (LOCATION) Ofqual (ORG) Register (ORG) Mat Pullen (PERSON) Jamf (ORG) Pullen (PERSON) Cyberattacks (PERSON) Covid (PERSON)
Originally published by The Register Read original →