Skip to content
School cyber security

Cyber security for schools: the complete plain-English guide

Published 13 August 2026 · Last reviewed 13 August 2026

This guide is for the person who runs the school — the head, the business manager, the trust leader — not the person who runs the network. It explains how schools actually get attacked, what to protect first, and what evidence you should expect to see, in plain English. Each section links to a deeper page when you’re ready for the detail.

Why schools are targeted

It rarely feels believable from inside a school: budgets are tight, the data is children’s, and nobody thinks of themselves as a lucrative target. But from an attacker’s side of the screen a school is attractive for exactly those reasons: it holds sensitive personal data about children and families, it moves money (payroll, suppliers, trips, catering), it runs on a small or outsourced IT function, and it cannot simply close for a fortnight while systems are rebuilt. Most attacks are not aimed at your school in particular — they are aimed at thousands of organisations at once, and the ones with a gap are the ones that get caught.

Official guidance
The National Cyber Security Centre publishes guidance and training specifically for schools, and the Department for Education publishes a cyber security standard that schools and colleges are expected to work towards. Both are linked in the sources at the end of this page — everything here builds on them rather than replacing them.

The routes in

Almost every school incident starts through one of a small number of doors. Knowing them turns “cyber security” from an overwhelming subject into a short list.

Email

The most common door, because it is open to the world by design. Two things matter: what arrives (phishing — messages that trick staff into giving away passwords or paying false invoices) and what pretends to come from you (spoofing — someone sending email that looks like it is from your school). The second one is fixed with three DNS records most schools have never checked. The email security guide covers both, and our free checker will tell you in about a minute whether your records are in place.

Identity — the accounts themselves

If an attacker has a staff password, they do not need to break anything: they sign in. This is why multi-factor authentication (a second check beyond the password) is the single control with the best effort-to-protection ratio a school can deploy, and why the DfE standard expects user accounts to be controlled and secured. The honest question to ask is not “do we have MFA?” but “is it enforced for everyone, including the accounts that manage everything else?” — a school can have MFA available and still have staff who have never registered for it. The MFA guide covers the rollout, and the Microsoft 365 hub the wider identity picture.

Unpatched software and old devices

Most successful attacks use weaknesses that were publicly known — and fixable — months before. Patching is unglamorous and it works. The question for your IT support is simple: what is our patching cadence, what is currently out of support, and what is the plan for it? An honest answer names specific systems; a worrying answer is “it’s all handled” with nothing written down.

Suppliers and the systems you don’t run

Your MIS, your payment system, your catering platform and your IT provider all hold or touch your data. You cannot patch their systems — but you can know which suppliers hold what, what they have promised about security, and who you would call if one of them had an incident. A one-page list of suppliers and what they hold is genuinely useful evidence, and most schools do not have one.

What saves you when it goes wrong

Backups that ransomware cannot reach

Ransomware encrypts what it can touch — and that includes backups sitting on the same network. The test of a backup is not whether it runs; it is whether a copy exists that an attacker with full control of your network still could not delete, and whether anyone has actually restored from it. The DfE standard expects a backup plan reviewed every year; our interpretation is blunter: an untested backup is a hope, not a plan.

An incident plan people can find at 8pm

The first hour of an incident is decided by preparation: who is in charge, who do you call (IT provider, insurer, and — where personal data is involved — the ICO within 72 hours), and what do you say to parents. A plan that exists only on the network that is currently encrypted does not exist. Print it. The DfE standard also expects cyber attacks to be reported — your plan should name who reports, and to whom.

People: the control that isn’t software

Staff awareness is not about making teachers paranoid; it is about making the school easy to warn. The measure of a good awareness culture is not how few people click a bad link — it is how quickly somebody reports one, because one early report protects everyone else. Training once a year at INSET and never mentioning it again does not build that; short, regular, blame-free reminders do — our free printable posters are built for exactly that job.

Governance and evidence — the part leaders own

None of the above needs a leader to configure anything. What it needs from leadership is exactly what safeguarding needed: named accountability, a place on the risk register, a report the governing body actually sees, and evidence that would satisfy an insurer, an auditor or the DfE. If you can answer “who is accountable, when did we last check, and where is that written down?” you are ahead of most. The governors’ guide gives a governing body ten questions to ask, with the answers that should reassure them.

Where to start

One honest caveat about us: Ceidwad builds governance and assurance software. Nothing on this page requires it, and the checklist and checker are free and complete on their own. Where a school wants this picture kept current continuously rather than checked termly, that is the job Ceidwad Atlas exists to do — and it is one way to do it, not the only one.

Want to know where your school stands?

Assess your school’s cyber readiness in about two minutes — no account, and nothing connects to your systems. You’ll get an indicative score and a plain-English list of what to fix first.

Start the free assessment

Sources

Related