Schools are recovering faster. Prevention has barely moved.
Ofqual's third annual survey is genuinely good news, and it is worth reading closely. Almost all of the improvement is in recovering from incidents rather than avoiding them.
On 1 October Ofqual published the third year of its survey into cyber security in secondary schools and colleges, and the headline is a fair one. Fewer schools reported an incident, and far more of those that did were back on their feet immediately. After two years of fairly grim education reporting, that is a real improvement and the sector deserves the credit. It is worth looking at which number moved, though, because the gain is not evenly spread.
What the survey found
- 27% of secondary schools and colleges reported a cyber incident in 2025-26, down from 29% the year before and 34% in 2023-24.
- 66% were able to recover immediately, up from 55% the previous year.
- 7% reported critical damage.
- 55% said their school had taken protective measures such as policies, risk assessments and backup and recovery procedures.
- On who is responsible, 46% said the IT team, 40% said all staff, and 9% said senior leadership.
The fieldwork was done by Teacher Tapp on 13 July 2026, with 3,775 secondary teachers responding across up to 2,162 schools, one response per school. Amanda Swann, Ofqual's Executive Director of Delivery, made the point that a breach "can still cause real uncertainty for students if coursework or marks are lost", and that cyber security "isn't just an IT problem; it's a leadership responsibility".
The eleven point jump is in recovery, and that matters
Immediate recovery going from 55% to 66% in a single year is a substantial move for any sector, let alone one with the budget pressure schools are under. It also tells you what schools have been working on, because that number is almost entirely about backups and a response plan.
That is the cheapest half of the job and the half with the clearest instructions. The Department for Education's standards are specific about it: at least three copies of important data on at least two devices with one held off-site, and a cyber response plan that is tested rather than written and filed. Schools have evidently done that work, and the survey is the first clear sign of it paying off.
Now read the prevention numbers again
Incidents fell from 34% to 29% to 27%. The direction is right and the trend is slowing, and 27% still means roughly one in four secondary schools reported something in a single academic year. Alongside that, 55% reported protective measures in place, which is another way of saying that a little under half did not.
There is also a limit on what this kind of survey can tell you about prevention. It asks teachers, on one day in July, about incidents at their school. A ransomware outage that closes the network for a week is visible to everyone in the building. A compromised mailbox that the IT lead dealt with quietly on a Tuesday is not. So the rise in recovery is strong evidence, because it describes something the school lived through, while the fall in incidents is softer evidence than it first appears. It may partly reflect what teachers knew about.
None of that undermines the finding. It just means the honest read is that schools have got much better at surviving incidents, and somewhat better at not having them.
The 9% is the number worth taking to governors
46% of teachers see cyber security as the IT team's job. 9% see it as leadership's. Ofqual's own commentary pushes back on exactly that, and the reason is practical rather than rhetorical.
The measures that reduce the number of incidents, as opposed to the damage they do, are not technical decisions. Enforcing multi-factor authentication on every staff account means overruling the people who find it irritating, and some of those people are senior. Patching inside a set window means accepting that a system will be unavailable during the school day occasionally. Retiring an unsupported server means finding capital for the one application that still depends on it. Each of those is a decision about money, policy or inconvenience, and an IT lead cannot take any of them alone.
That is why the responsibility split is not a presentational problem. A school where cyber security sits entirely with the IT team will keep getting better at recovery, because recovery is something the IT team can deliver on its own, and will stay roughly where it is on prevention.
What we tend to find in schools
From assessment and testing work in the sector, the recurring gaps are consistent and none of them are exotic:
- An on-premise server kept alive past end of support because one curriculum application needs it.
- Multi-factor authentication enforced for most staff, with quiet exceptions that were granted a year ago and never reviewed. The exceptions are usually the accounts with the most access.
- Shared departmental accounts that nobody can attribute to a person.
- A flat network where a curriculum device can reach the management information system.
- Remote access left in place for a supplier whose contract ended.
The last two are what turn a single compromised account into a week of closure, which is the scenario the recovery statistics describe from the other side.
Five things worth doing this term
- Restore something and write down the date. A backup that has never been restored is a hypothesis. This is also the evidence an insurer asks for.
- Pull the real list of accounts without multi-factor authentication from your tenancy, rather than asking whether anyone has been excluded. Close it, senior staff included.
- Inventory what is unsupported, servers first, and get the cost of dealing with it into a budget cycle rather than a wish list.
- Check what is reachable from outside. Most schools have more exposed than they think, usually from a project that finished years ago.
- Put it on the governors' agenda with a named owner. Not the IT lead by default. Someone who can authorise spend and policy.
Where certification fits
The DfE standards and the five Cyber Essentials controls cover much the same ground. Firewalls, secure configuration, security update management, user access control and malware protection map closely onto the DfE's requirements for multi-factor authentication on cloud and administrative accounts, critical and high-risk fixes applied within 14 days, controlled accounts and privileges, and anti-malware. A school that genuinely meets the DfE standards is most of the way to Cyber Essentials already, and certification mainly adds an independent check that the controls are actually there rather than written down.
That independent check is the part worth paying for, and it is also the part that gets skipped. We are an appointed IASME Certification Body and we assess and issue directly, which is covered on the Cyber Essentials for schools page. If the concern is what an attacker could reach rather than whether controls are documented, testing answers a different question and is sometimes the better first spend.
Either way, the survey's own conclusion is the right one. Recovery is the half schools have fixed. Prevention is the half that needs a decision from someone who can sign for it.
We wrote about the other side of this earlier in the year in what the 2026 attacks on UK education actually tell us, which looks at dwell time and how far a single compromise reached.
Common questions
Does Cyber Essentials cover what this survey is measuring?
We are a multi-academy trust. Does one certificate cover every school?
Is a penetration test more useful for a school than certification?
The survey covers secondary schools. Does it apply to primaries?
Who should own cyber security in a school?
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.