A checklist a school can actually work through — no security team assumed, ordered by what protects you most per hour of effort, and printable for the next leadership meeting. Each section notes where it maps to the DfE’s cyber security standard, so the same work counts twice: real protection, and evidence of working towards the standard.
Do first — the biggest protection per hour
- Multi-factor authentication is enforced (not merely available) for every staff account — and you have seen evidence, not just been told. DfE standard: control and secure user accounts.
- The administrator accounts — the ones that control everything else — have MFA, are used only for admin work, and you know how many exist and who holds them.
- A backup exists that someone with full control of the school network could not delete or encrypt, and a named person has done a real restore from it in the last year. DfE standard: back up your data, reviewed yearly.
- Your email domain has SPF, DKIM and DMARC in place — checkable free in a minute from public records, with the fixes handed to whoever runs your DNS.
- Any request to change bank details or make an unusual payment is verified by a phone call to a known number — always, however legitimate the email looks.
Do next — the foundations
- You know your patching position: what updates automatically, what is checked by hand and when, and what is out of support with a plan (or a dated risk acceptance) for it. DfE standard: license digital technology and keep it up to date.
- Every device that touches school data runs supported software with anti-malware on, and a firewall separates the school network from the internet with its default password changed. DfE standard: secure digital technology and data.
- Staff know exactly how to report a suspicious email or a mistake — and reports are met with thanks, never blame, because early reports are the school’s alarm system. DfE standard: cyber awareness plan for students and staff.
- A one-page list exists of every supplier that holds school data (MIS, payments, catering, IT provider…), what each holds, and what they have promised about security.
- Leavers’ accounts are disabled promptly — there is a leaver process that includes IT, and someone has checked for accounts belonging to people who have left.
Prepare — for the bad day
- An incident plan exists that is reachable when systems are down (printed or stored separately), naming who leads, who is called — IT provider, insurer, and the ICO within 72 hours where personal data is involved — and who communicates with parents.
- The plan names who reports a cyber attack, and to whom — including Report Fraud, and your insurer or the RPA where conditions apply. DfE standard: report cyber attacks.
- The plan has been rehearsed at least as a conversation: “it is 8am and nobody can log in — what do we each do?” takes twenty minutes and finds the gaps for free.
- Someone has read your cyber insurance (or RPA cover) conditions against reality in the last year — cover often depends on specific controls being demonstrably in place.
Govern — keeping it true
- A named leader is accountable for cyber security, distinct from whoever operates the controls, and the governing body knows both names.
- A cyber risk assessment has been done in the last year and reviewed each term — the DfE standard’s own cadence — and cyber risk appears on the school’s risk register.
- Governors hear about cyber security on a standing slot (termly is proportionate), with a report a non-specialist can read — the governors’ guide gives them the ten questions to ask.
- Everything above leaves evidence — dated documents, not memories — filed where an auditor, an insurer or the DfE could be shown it.
This checklist stands on its own, and a school that works through it with its IT provider needs nothing from us. The wider orientation — why these items and not others — is the complete guide.


