**England's Schools Show Improved Cybersecurity Resilience, But Gaps in Responsibility and Training Remain**
A recent survey by exams regulator Ofqual has revealed that England's secondary schools are reporting fewer cybersecurity incidents and faster recovery times when disaster strikes. The survey, which polled 3,775 secondary teachers in England in July, found that 27% of schools reported an incident during the 2025/26 academic year, down from 29% a year earlier and 34% in 2023/24. While the improvement is a step in the right direction, the survey also highlights ongoing challenges in cybersecurity awareness and responsibility within schools.
Phishing was the most commonly reported type of incident, followed by data protection breaches, hacking, and ransomware. Ransomware affected 2% of respondents, while staff data was the information most commonly compromised. Student data was affected in 13% of incidents, while student work was affected in only 1%. The proportion of reported incidents causing "critical damage" also fell from 10% to 7%.
A notable improvement was seen in recovery times, with 66% of schools reporting immediate recovery, up from 55% the previous academic year. Only 1% of schools required a full term to recover from an incident. However, the survey also found that 54% of teachers were unsure about the cybersecurity improvements their school had made during the past year.
The question of who bears primary responsibility for cybersecurity is a contentious one. While 46% of teachers pointed to the IT team, 40% said responsibility was shared among all staff, and only 9% identified senior leadership. Ofqual argues that cybersecurity is a leadership responsibility rather than solely an IT problem. Mat Pullen, director of education at Jamf, echoed this sentiment, stating that "cyberattacks have closed schools for a week or longer in the past, further disrupting an education already hit by Covid and affecting the wider economy as parents take time off work."
The survey also highlights the need for cybersecurity training and awareness. Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had, up from 28% a year earlier. Of those who received training, 65% said they made no changes as a result.
In comparison, the government's Cyber Security Breaches Survey found that 49% of primary schools, 73% of secondary schools, 88% of further education colleges, and 98% of higher education institutions had identified a breach or attempted attack during the previous 12 months. While the figures are not directly comparable, the broader survey illustrates how frequently schools are targeted.
The Ofqual survey's findings are a mixed bag, highlighting both progress and challenges in cybersecurity awareness and responsibility within England's secondary schools. While the reduction in incidents and improvement in recovery times are promising, the survey also underscores the need for greater emphasis on cybersecurity training and awareness. As cybersecurity threats continue to evolve, it is essential that schools prioritize cybersecurity and ensure that all staff are equipped to handle the challenges of a rapidly changing digital landscape.
**Key Takeaways:**
* 27% of schools reported an incident during the 2025/26 academic year, down from 29% a year earlier and 34% in 2023/24. * Phishing was the most commonly reported type of incident, followed by data protection breaches, hacking, and ransomware. * Ransomware affected 2% of respondents, while staff data was the information most commonly compromised. * Recovery times improved, with 66% of schools reporting immediate recovery. * 54% of teachers were unsure about the cybersecurity improvements their school had made during the past year. * Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had.
**Recommendations:**
* Schools should prioritize cybersecurity and ensure that all staff are equipped to handle the challenges of a rapidly changing digital landscape. * Greater emphasis should be placed on cybersecurity training and awareness, particularly among teachers and senior leadership. * Schools should review and update their incident response plans to ensure they are effective in the event of a cybersecurity incident. * Cybersecurity should be recognized as a shared responsibility among all staff, with clear roles and responsibilities defined.