- Accreditation
- CREST
- Typical scope
- Multi-campus, BYOD, portals
- Also covers
- Learner records, funding data
- Retest
- Included as standard
Why colleges are not just large schools
The differences are structural, and they change what a test needs to cover.
- Adult learners with personal devices. Colleges cannot run the locked-down managed estate a primary school can. Large numbers of unmanaged devices connect daily, and the network has to assume some are compromised.
- Multiple campuses joined by links that were often built for convenience rather than segmentation, sometimes inherited through merger.
- Open access by design. Libraries, learning resource centres and drop-in areas exist to be used by people the college does not control. Physical access to a network port is a realistic starting point for an attacker.
- Employer and apprenticeship data. Colleges hold commercial relationships and apprenticeship records alongside learner data, which broadens both the value to an attacker and the regulatory exposure.
- Funding assurance. ESFA funding rests on the integrity of learner records. Data integrity is a financial risk here in a way it is not in a school.
What we normally test
- External infrastructure and portals. Learner portals, VLE access, applications systems, remote access and anything published for employers.
- Network segmentation. Whether an unmanaged device on the learner network can reach the finance system, the MIS or another campus. This is the highest-value test in a college estate.
- Wireless and network access control. Whether the separation between learner, staff and guest networks holds, and what an unauthenticated device plugged into an open port can reach.
- Identity and Microsoft 365. Large user populations with high turnover make joiner and leaver process the recurring weak point. Accounts for learners who left two years ago are a routine finding.
- Web applications built in-house or by a partner, which colleges have more of than schools do.
Sixth forms and smaller providers
A standalone sixth form or a small independent training provider sits closer to a school in scale but often carries college-style openness. We scope to what is actually there rather than to the label, and we will tell you when a smaller engagement covers your realistic risk.
Scheduling and disruption
External and application testing has no impact on teaching. Internal testing is scheduled around the timetable, and college calendars usually offer more flexibility than school ones. We agree rules of engagement in advance, exclude fragile systems, and stay contactable throughout.
The report
Written for two audiences: technical detail your IT team can work from, and a summary suitable for a senior leadership team, an audit committee or a governing body. Retesting is included as standard, so findings can be evidenced as closed.
Where testing is being commissioned to satisfy an auditor, a funder or an insurer, tell us at scoping and we will make sure the report answers the specific requirement rather than a general one.
Common questions
How is testing a college different from testing a school?
Scale and openness. Colleges run multi-campus networks with large numbers of unmanaged personal devices and areas open to the public by design. Segmentation matters more, and physical access to a network port is a realistic attack path rather than a theoretical one.
We have merged with another college. Does that change anything?
Considerably, and it is one of the better reasons to test. Merged estates carry inherited infrastructure, joined networks and duplicated identity systems that nobody has fully documented. Segmentation testing across the join is usually where the significant findings are.
Can you test during term time?
External and application testing, yes, with no impact on teaching. Internal testing is scheduled around the timetable, and college calendars usually allow more flexibility than schools. We agree the window in advance.
Do you cover apprenticeship and employer data?
Yes, as part of scoping. Colleges hold commercial relationships and apprenticeship records alongside learner data, and that changes both what an attacker is after and what your regulatory exposure looks like.
Is this needed for ESFA funding assurance?
Funding assurance rests on the integrity of learner records, so data integrity is a financial risk in FE in a way it is not elsewhere. Whether independent testing is explicitly required depends on your circumstances and current guidance — send us the requirement and we will tell you what would satisfy it.
Who will do the testing?
A CREST-qualified tester, named before you commit, and the same person throughout. Everyone working on education engagements holds current enhanced DBS clearance.
Is educational penetration testing different for colleges?
Yes. Educational penetration testing in further education has to account for large numbers of unmanaged personal devices, multi-campus networks often joined through merger, and areas open to the public by design. Segmentation carries more weight than in a school, and physical access to a network port is a realistic attack path rather than a theoretical one.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day