- DfE breach
- ~600,000 records
- Primary schools attacked
- 72% detected an attack
- FE colleges
- 90% detected an attack
- Source
- DSIT Breaches Survey 2025/26
Three incidents, three months
Education has had a bruising year, and the incidents are worth looking at together rather than individually.
In June 2026, Powys County Council confirmed a cyber security incident involving the theft of personal data belonging to pupils, staff and others connected to schools in mid-Wales.
In July 2026, the Department for Education confirmed a breach after an extortion group claimed to have taken records from departmental portals. Reporting put the figure at roughly 600,000 records, covering names, job titles, telephone numbers and email addresses of school leaders, university staff and government personnel. NCC Group's Frank van Oeveren noted that the exposure linked to those groups "should not be underestimated", because that combination of details enables convincing phishing and follow-on attacks.
And in May 2026, a Surrey primary school was listed as a ransomware victim. Threat intelligence monitors placed the initial network intrusion around three weeks before the listing went public.
The number that should bother you
Three weeks.
That is the gap between an attacker getting in and anyone finding out, at a small primary school with no security team and no realistic prospect of having one. In that window an intruder maps the network, finds the backups, works out which systems matter, and takes what they want before doing anything visible.
Nobody detected it because nobody was watching. That is not a criticism of the school. It is a description of how most schools in this country operate, and it is the single most useful thing to take from the incident.
The relevant question for your school or trust is not whether you would survive ransomware. It is whether you would notice three weeks of someone quietly moving around your network first. If the honest answer is no, that is where the money goes, not into another tool.
What the government's own numbers say
The DSIT Cyber Security Breaches Survey for 2025/26 found that among education institutions identifying a breach, detection rates were high across the board: 72% of primary schools, 67% of secondary schools, 90% of further education institutions and 73% of higher education institutions reported detecting significant attacks.
Read that carefully. Those are detection figures, not attack figures. The attacks that were not detected do not appear.
The survey also found that senior engagement is genuinely high, with cyber security a very or fairly high priority for governors or senior management at no fewer than 96% of institutions in higher education, comparing favourably with businesses generally. Awareness is not the gap. Capability is.
The second pattern: shared infrastructure
The Powys incident affected schools through a council. Earlier in 2026, three London councils sharing IT infrastructure found that a single compromise reached across all of them, with one writing to hundreds of thousands of households months later.
Shared services are how the public sector affords IT at all. But shared services mean shared blast radius, and for a multi-academy trust the same logic applies internally: schools joined at different times, on inherited infrastructure, connected because connecting them was cheaper than not.
If you are a trust, the useful exercise is not "are our schools secure" but "if one school is compromised on a Tuesday, what can that attacker reach by Friday?" That is a segmentation question, and it is testable.
What we would actually do about it
In order, and stopping when the budget runs out:
- Cyber Essentials first. Multi-factor authentication, patching, supported software, access control. It addresses the attacks that actually happen, and for colleges it is now a College Financial Handbook requirement rather than a nice-to-have. See Cyber Essentials certification.
- Test the segmentation. Can a device on the pupil network reach the MIS or the finance system? This is the highest-value single check in a school estate, and it fails more often than it passes. Covered under penetration testing for schools.
- Review who can see safeguarding data. Almost every school we look at has far too many staff able to see SEN records, free school meals data and safeguarding notes. That is a data protection problem before it is a security one.
- Restore a backup. Not check that it ran. Restore it, time it, and write down the number, because that number is your answer when governors ask how long you would be closed.
- Get something watching. Three weeks of undetected access is the failure mode. Managed detection and response exists precisely to shorten that window.
If you think it has already happened
Do not start deleting things. Preserve what you have, disconnect what you must, and get help. A penetration test tells you what an attacker could do; it does not tell you what one already did. That is incident response, and the order matters.
The honest summary
None of the 2026 education incidents involved anything exotic. They involved ordinary access, held for longer than anyone noticed, across infrastructure that was more connected than anyone had mapped.
That is fixable on a school budget. It is not fixable by buying more software.
Common questions
Is my school actually a target?
Not individually, in most cases. Schools are found by automated scanning that sweeps the entire internet for whatever is exposed and unpatched. The 2026 incidents did not involve attackers choosing those organisations for their significance. That is worth understanding, because it means size offers no protection.
We are a small primary. Where do we start?
Cyber Essentials, and be honest in the self-assessment. It covers multi-factor authentication, patching, supported software and access control, which between them address the overwhelming majority of what actually happens. Everything else comes after.
Does the DfE require penetration testing?
The DfE digital and technology standards cover cyber security, and adherence is increasingly tied to grant funding. For colleges, Cyber Essentials is now a College Financial Handbook requirement. Whether independent testing is explicitly required depends on your circumstances, so check the current standards directly rather than relying on summaries.
How would we even know if someone was in our network?
At most schools, you would not, which is the point of this article. Detection requires either someone watching or a service doing it for you. If neither exists, your first indication is usually the ransom note.
Can you check whether we were affected by any of these?
We can check your public-facing systems and tell you what we find, at no charge. If your data was in the DfE breach specifically, that is a matter for the department's own notifications rather than something we can determine from outside.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day