Not ‘just an IT problem’ says Ofqual executive

Ofqual is urging school leaders to continue improving their resilience to cyber attacks, as new survey data suggests schools are getting better at bouncing back from such incidents. The call comes as part of Cyber Security Awareness Month.

Ofqual recently completed its third annual cyber security survey – more than 2,000 schools and 3,775 secondary teachers were surveyed by Teacher Tapp on behalf of Ofqual in July this year. It found that the proportion of schools experiencing a cyber incident fell to 27 per cent during the 2025/26 academic year, down from 29 per cent in 2024/25 and 34 per cent in 2023/24. And when incidents do occur, schools seem to be recovering faster, with 66 per cent able to recover immediately, up from 55 per cent the previous year. However, not all schools were so fortunate – one teacher reported losing network and email access entirely, while another described an incident that led to police temporarily closing the school. Amanda Swann, Ofqual’s executive director of delivery, said: ‘It’s encouraging to see schools recovering faster, but a cyber breach can still cause real uncertainty for students if coursework or marks are lost, and staff confidence can be affected long after systems are back online.’

More than half of the secondary schools surveyed (55 per cent) have already taken action to protect against cyber attacks. Measures included implementing a cyber security policy, carrying out risk assessments, and setting up backup and recovery procedures. Ofqual is urging the remaining schools to take similar steps, and placing particular emphasis on the role school leaders can play. Ms Swann commented: ‘Cyber security isn’t just an IT problem; it’s a leadership responsibility. Regular backups and a clear response plan can make a huge difference when things go wrong.’

For the first time this year, the survey asked who respondents saw as primarily responsible for cyber security. 46 per cent of responding teachers said their IT team, 40 per cent said all staff, and just 9 per cent pointed to the role played by senior leadership. Ofqual suggests that senior leaders should schedule a review with their IT lead, and visit the Department for Education’s Cyber Security Hub, where they can download the DfE’s cyber response plan template. Advice for schools is also available from the National Cyber Security Centre.

Recent months have seen a number of high-profile cybersecurity incidents linked to education. In April, an attack on the C2K system, an IT system used by schools in Northern Ireland, affected more than 400,000 user accounts, including those of pupils, teachers and non-teaching staff. Meanwhile, in July hackers obtained around 607,000 records in an attack on the DfE itself – data taken included telephone numbers and email addresses relating to individuals and organisations. And last year in Scotland, West Lothian council’s education network was hit by a ransomware attack that saw the loss of data from around a dozen schools.

Research last year from the Information Commissioner’s Office (ICO) suggested that pupils were very often behind cyber attacks on schools. Almost a third of insider attack incidents were caused by students guessing weak passwords or finding them jotted down on bits of paper, the ICO found. A 16 year old boy was arrested in connection with the C2K system attack, although he was later released pending further inquiries.