The Department for Education's cyber security standards tell every school and college in England what "good" looks like. They are clear and sensible — but they're written for people who already work in IT. This guide translates them into plain English, says who in your school should own each one, and gives you a checklist you can actually evidence.
What the DfE cyber security standards are
The cyber security standards sit inside the DfE's wider Digital and Technology Standards for schools and colleges. They are not law, and there is no certificate at the end. But they are the benchmark Ofsted-adjacent scrutiny, governors, insurers and the DfE's own guidance all point to — so "we meet the DfE cyber standards" is fast becoming the baseline expectation for a well-run school or trust.
The standards are deliberately aligned with NCSC (National Cyber Security Centre) guidance, so working towards them also moves you towards recognised good practice like the NCSC Cyber Assessment Framework and Cyber Essentials.
Who owns this in a school?
This is where most schools stall — everyone assumes "IT" owns it. The DfE is clear that cyber security is a leadership responsibility, delivered with IT support:
- Senior leadership / the SLT digital lead — owns the strategy, the annual risk assessment, and reporting to governors.
- Governors / trustees — provide oversight and challenge; cyber risk should be a standing item, not an annual afterthought.
- IT support (in-house or MSP) — implements the technical controls: firewalls, MFA, patching, backups, monitoring.
The seven standards, in plain English
1. Conduct a cyber risk assessment annually, and review it every term
Know what you hold, what could go wrong, and what you are doing about it — written down, refreshed once a year, and revisited each term. This is the standard everything else hangs off: without it you are guessing at your priorities.
2. Create and implement a cyber awareness plan for staff and students
Train everyone with access to school systems in the basics, and keep doing it. The majority of incidents start with a person rather than a machine, so this is the control that protects you when the technical ones are bypassed.
3. Secure digital technology and data with anti-malware and a firewall
Every device on every network — including home and cloud — should sit behind a properly configured firewall, with anti-malware in place and actually monitored. Nothing should be exposed directly to the internet without a deliberate, documented reason.
4. Control and secure user accounts and access privileges
Accounts should have only the access the role genuinely needs, and accounts should be disabled as soon as someone leaves. Administrative accounts must not be used for routine day-to-day work, and multi-factor sign-in is expected — especially for cloud services like Microsoft 365 or Google Workspace. This is the highest-impact area on the whole list.
5. License digital technology and keep it up to date
Everything online must be licensed and patched. DfE is specific: fixes for vulnerabilities scoring 7.0 or above (CVSS v3.1) should be applied within 14 days of release. Note that a “fix” isn't always a software patch — it can be a firmware or configuration change. Unsupported software is one of the most common ways in.
6. Develop and implement a backup plan, and review it every year
DfE asks for at least three copies of important data on at least two separate devices, with one held off-site. Backups should be immutable — unchangeable once written, so ransomware cannot encrypt them too — and you should test and log a restore every term. A backup nobody has ever restored is a hope, not a plan.
7. Report cyber attacks
Know who to tell before you need to. Report to your RPA or cyber insurance provider, to Report Fraud (formerly Action Fraud), and to the DfE sector cyber team. Where personal data is involved, the ICO within 72 hours. Being clear on this in advance is the difference between a calm first hour and a chaotic one.
Your DfE cyber security checklist
Use this as a governor-ready self-check. If you can honestly tick each one and point to the evidence, you are meeting the standards.
- Every network sits behind a configured firewall, with any exposed service documented.
- You hold an up-to-date inventory of devices, with security features enabled.
- Accounts follow least-privilege; admin rights are rare and reviewed.
- Accounts are disabled as soon as someone leaves, and admin accounts aren't used for routine work.
- MFA is enforced on all staff accounts, especially cloud accounts (Microsoft 365 / Google).
- Anti-malware is deployed, updated and monitored across all devices.
- Third-party app permissions over your cloud tenant have been reviewed.
- All software is licensed and supported, with high-severity fixes (CVSS 7.0+) applied within 14 days.
- Backups: 3 copies, 2 devices, 1 off-site — immutable, with a restore tested and logged every term.
- You know exactly who to report an attack to: RPA/insurer, Report Fraud, the DfE sector cyber team, and the ICO within 72 hours if personal data is involved.
- A cyber incident response plan exists, names owners, and has been rehearsed.
- A cyber risk assessment is done annually, reviewed termly, and seen by governors.
- All staff have had cyber-awareness training in the last year.
Turning the checklist into evidence
The hard part is not knowing the standards — it is keeping the evidence current and being able to show governors, auditors and the DfE where you stand at any moment. That is exactly what Ceidwad is built to do: it maps your live posture against the DfE standards (and NCSC guidance), turns gaps into a prioritised action list, and produces board-ready reporting — in plain English, without a security team.