- Accreditation
- CREST
- Scheduling
- Around the school day or holidays
- Report written for
- Business managers and governors
- Retest
- Included as standard
What educational penetration testing covers
Educational penetration testing differs from commercial testing because school networks are unusual. A single site can carry a management information system holding safeguarding records, a finance system, a curriculum network used by hundreds of pupils, staff laptops, a wireless network open to personal devices, and a set of internet-facing services for remote access and parent portals. Very few commercial environments mix that much sensitivity with that much open access.
A test scoped for a school normally covers:
- External infrastructure. Everything reachable from the internet — remote access, parent and pupil portals, mail gateways, and the services published during the pandemic that were never withdrawn.
- Internal network and segmentation. Whether a device on the pupil network can reach the finance server or the MIS. This is the single most valuable check we run in a school, and it fails more often than it passes.
- MIS and access control. Who can see safeguarding records, SEN information and free school meals data, and whether their role requires it. Almost every school we look at has far too many staff with far too much visibility.
- Wireless. Separation between pupil, staff and guest networks, and whether the guest network genuinely is one.
- Build and device configuration. Whether a pupil can escape the managed desktop, and whether staff laptops are configured as intended.
Scoping to a real budget
We would rather scope a school honestly than sell a programme it cannot fund. For most schools the sensible first engagement is external infrastructure testing plus an MIS access review — that combination addresses the exposure an opportunistic attacker actually finds and the data protection risk that would matter most if it went wrong.
Internal network testing and wireless follow when budget allows, or on a rolling basis across a trust. We will tell you what a given number of days can genuinely cover rather than spreading a small budget thinly across everything.
Maintained schools, academies and independent schools
The label changes what a test needs to look at, and who the report has to satisfy.
Maintained schools
Usually supported by a local authority IT service or a shared traded service, which means the network is partly outside your control and testing needs the authority's cooperation. We help establish who authorises what before scoping, because that is normally the thing that delays a first engagement.
Academies and multi-academy trusts
Budget and IT decisions sit with the trust, which makes scoping simpler but the estate more varied. Trustees carry the risk, so the report needs to work at board level. Scoping across a trust is covered in more detail below.
Independent and private schools
A different risk profile, and often an underestimated one. Independent schools hold fee payment data and parent bank details, which makes them a direct target for payment redirection fraud rather than just data theft. Boarding schools hold pastoral, medical and immigration records on pupils living on site. Development and alumni databases hold donor information on high-net-worth individuals — a dataset with real value that rarely gets the protection it deserves.
Inspection sits with ISI rather than Ofsted, and there is no DfE funding condition driving security investment, so the pressure usually comes from insurers, parents or the governing body instead. Testing is commonly commissioned to give governors assurance rather than to satisfy a regulator, which changes how the report should be written.
Multi-academy trusts
Trusts create a scoping problem that single schools do not: different schools on different systems, joined at different times, with inherited infrastructure nobody has fully documented.
Testing every school every year is rarely affordable and rarely necessary. The usual approach is to test shared central infrastructure properly, sample a representative set of schools, and build a rolling programme so every site is covered over two or three years. That gives trustees a defensible position without a cost that never gets approved.
Scheduling around a school
External testing is invisible to users and can run in term time without anyone noticing. Internal testing is scheduled around the school day, into an INSET day, or into the holidays. We agree rules of engagement in advance, exclude anything fragile, and stay contactable throughout.
We do not run denial-of-service testing unless specifically asked, and we would not ask a school to accept that risk during teaching hours.
The report
Two audiences. Technical detail your IT provider or in-house team can work directly from, and an executive summary that a business manager or headteacher can read, act on, and take to governors without needing it translated.
Retesting is included as standard, so findings can be evidenced as closed rather than simply identified — which is what governors, the DfE standards and any funder or insurer actually want to see.
Where a test is not the right first step
If your school has no multi-factor authentication on staff email, unsupported operating systems still in service, or backups nobody has ever restored, a penetration test will confirm what you already suspect at a cost better spent fixing it. We will say so.
In that situation Cyber Essentials is usually the better purchase, and considerably cheaper.
Common questions
How much does penetration testing for a school cost?
It depends on scope rather than on being a school, but we scope schools to education budgets rather than corporate ones. A focused first engagement covering external infrastructure and an MIS access review is a genuinely useful piece of work at the lower end. We will tell you honestly what a given budget can cover.
Will testing disrupt lessons?
No. External testing is invisible to users and runs in term time. Internal testing is scheduled around the school day, into INSET days or into the holidays. We agree rules of engagement in advance and exclude anything fragile.
Does the DfE require penetration testing?
The DfE's digital and technology standards for schools and colleges cover cyber security, and expectations have tightened. Whether independent testing is explicitly required depends on the current wording and your circumstances, so check the standards directly. In practice, governors and trustees increasingly ask for independent assurance regardless.
We are a multi-academy trust with different systems per school. How does that work?
Usually a representative sample plus any shared central infrastructure, then a rolling programme so every site is covered over two or three years. Testing everything annually is rarely affordable and rarely necessary. We will be honest about what a given budget covers.
Can you test our MIS?
We test access control around it — who can see safeguarding, SEN and pupil data, and whether their role requires it. Testing the vendor's own application usually needs their written authorisation, which we would help you request if it is genuinely in scope.
Who will actually do the testing?
A CREST-qualified tester, named before you commit, and the same person throughout. Not a junior analyst running a scanner. Everyone working on school engagements holds current enhanced DBS clearance.
Do you work with independent and private schools?
Yes. Independent schools carry a different risk profile — fee payment data and parent bank details make them a direct target for payment redirection fraud, boarding schools hold pastoral and medical records on pupils living on site, and development databases hold donor information on high-net-worth individuals. Inspection sits with ISI rather than Ofsted, and testing is usually commissioned for governor assurance rather than a funding condition.
What is educational penetration testing?
Penetration testing scoped for an education environment rather than a commercial one. In practice that means testing segmentation between pupil and staff networks, reviewing who can see safeguarding and SEN data in the MIS, working around the school day, pricing to an education budget, and writing findings so a business manager can take them to governors. The methodology is the same as any CREST engagement; the scoping, scheduling and reporting are not.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day