Cyber security has a vocabulary problem: the words arrive in insurer questionnaires, DfE documents and IT provider emails as if everyone already knew them. Each entry here gives the plain definition — and then the half nobody else writes: what the term actually means for a school.
MFA (multi-factor authentication)
Multi-factor authentication (MFA) means proving who you are with something beyond a password — usually a prompt or code on a phone. A stolen password alone then stops being enough to sign in.
What this means for a school: The word that matters in a school is enforced. MFA that is merely available protects only the people who opted in, and the accounts most worth protecting — the office, the head, the IT administrators — are exactly the ones an attacker tries first. Microsoft's free security defaults give every school baseline MFA; finer control needs Conditional Access and the licence that carries it.
Covered properly in Microsoft 365 security for schools.
DMARC
DMARC is a public DNS record that tells receiving mail systems what to do with email claiming to come from your domain but failing authentication — deliver it, junk it, or reject it — and where to send reports about what they saw.
What this means for a school: Without DMARC at enforcement, anyone can send email as your school and it is the parent's job to spot the fake. At p=reject, the forgery is refused before anyone sees it. The rollout has a safe order — monitor, fix your real senders, then enforce — and skipping it is how trip letters go missing.
Covered properly in Email security for schools.
SPF (Sender Policy Framework)
SPF (Sender Policy Framework) is a public DNS record listing the servers allowed to send email as your domain — the guest list receiving systems check arrivals against.
What this means for a school: A school's real list is longer than anyone remembers: the office, the MIS, the payment system, the catering platform. An SPF record that misses one of them makes legitimate mail look forged; one that is never enforced by DMARC is a list nobody is obliged to read.
Covered properly in Email security for schools.
DKIM (DomainKeys Identified Mail)
DKIM (DomainKeys Identified Mail) puts a cryptographic signature on each legitimate email, so receiving systems can verify the message really came from the domain and was not altered on the way.
What this means for a school: DKIM is the half of email authentication that survives forwarding, which SPF does not. Each service that sends as your school — office mail, MIS, payments — needs its own signing set up, usually one DNS entry per service, done by whoever runs your DNS.
Covered properly in Email security for schools.
EDR (endpoint detection and response)
EDR (endpoint detection and response) watches what is happening on devices — processes, connections, behaviour — to detect, investigate and respond to attacks in progress, where traditional antivirus only blocks known-bad files.
What this means for a school: The practical school question is not "do we have antivirus?" but "if an attacker was moving through our machines, would anything notice, and who would be told?". EDR is the tool that answers it — in Microsoft's world it arrives with specific Defender plans on specific licence tiers, so check what your licence actually includes before assuming.
Covered properly in Cyber security for schools.
Phishing
Phishing is a message crafted to trick the reader into giving away credentials, paying money, or opening something harmful — usually by impersonating someone the reader trusts.
What this means for a school: Schools are phished through their trust relationships: mail that looks like the head, the MIS, or the payment provider. The measure that matters is not the click rate but the report rate — one early report protects the whole school, which is why reporting must be one step and never met with blame.
Covered properly in Email security for schools.
Ransomware
Ransomware is malware that encrypts your files or locks your systems, then demands payment for the way back in. Modern groups usually steal a copy of the data first and threaten to publish it.
What this means for a school: For a school the decisive control is a backup the attacker cannot reach — ransomware hunts backups on the same network before it announces itself. The honest test: could someone with full control of our network delete every copy we have? If yes, the backup is part of the ransom.
Covered properly in Cyber security for schools.
Patch management
Patch management is the discipline of applying software updates — especially security fixes — promptly and knowingly: what updates automatically, what is checked by hand, and what is out of support.
What this means for a school: Most successful attacks use holes that were publicly fixable months earlier. The school-shaped questions: what is our patching cadence, what is out of support, and is the answer written down? The DfE standard expects software licensed, supported and up to date — and the out-of-support decisions are spending decisions, which makes them leadership's, not IT's.
Covered properly in The DfE cyber security standards, explained for schools.
Conditional Access
Conditional Access is Microsoft's rules engine for sign-ins: policies that allow, challenge or block access depending on who is signing in, from where, on what device, and to what. It requires a Microsoft Entra ID P1 licence or above.
What this means for a school: It is the upgrade path from Microsoft's one-size security defaults: a school can require MFA everywhere but make sensible exceptions, protect admin accounts harder than classroom sign-ins, and block risky legacy protocols. Whether you have it depends on your licence tier — an Office 365 A1 school does not; Microsoft 365 A3/A5 schools do.
Covered properly in Microsoft 365 security for schools.
Cyber Essentials Plus
Cyber Essentials Plus is the independently tested version of the UK's Cyber Essentials certification: the same five technical controls, verified hands-on by an assessor rather than self-declared.
What this means for a school: A school chooses Plus when whoever is asking — a framework, a trust, an insurer — needs independently verified assurance rather than a reviewed self-assessment. It follows the standard assessment within a fixed window on the same scope, so the pair should be planned together.
Covered properly in Cyber Essentials for schools.
Incident response
Incident response is the prepared, practised way an organisation handles a cyber attack: who leads, who is called, what gets contained first, who must be notified, and how the lessons get kept.
What this means for a school: The school-specific truths: the plan must be reachable when systems are down (printed, not only on the encrypted server); the ICO clock is 72 hours where personal data is involved; and a twenty-minute walkthrough — "it's 8am and nobody can log in" — finds the gaps for free.
Covered properly in Cyber security for schools.
Cyber governance
Cyber governance is the leadership half of cyber security: named accountability, risk owned on a register, evidence kept, and reporting that lets a board ask useful questions — as distinct from operating the technical controls.
What this means for a school: It is the part a school cannot delegate to an IT provider. Governors do not need to understand firewalls; they need to know what to ask, what a good answer sounds like, and that "we don't know" is a finding rather than a failure.
Covered properly in Cyber security for governors.


