Ransomware for Schools: What Would an Attack Do to Yours?
A ransomware attack on a school usually runs in three stages. An attacker gets in quietly, moves through the network for several days, then encrypts servers and steals data before demanding payment. Dwell time is typically four to six days, which is long enough to find your backups and short enough that nobody notices.
When it lands, MIS access goes with it: no registers, no safeguarding records, no parent contact details. Email, printing, cashless catering, door entry and CCTV often fail too, because they share the same network and the same identity system.
Realistic recovery to a usable teaching service is two to four weeks, with full restoration of systems and data commonly taking a term or longer. The bill lands in forensic investigation, staff overtime, temporary devices, legal advice, ICO notification and rebuilt infrastructure. It cannot land in the ransom, because academy trusts are not permitted to pay one. The heaviest losses never appear on an invoice: lost coursework, disrupted assessments, and the confidence of families whose children’s records were leaked.
Who This Is For
This is written for headteachers, executive heads, trust CEOs, COOs and CFOs, and school business managers who carry accountability for cyber risk without holding the technical detail themselves.
It will be most useful if you sit in a multi-academy trust of three to fifteen schools, with one or two internal IT staff, a mix of inherited infrastructure from pre-conversion days, and a support contract you did not personally sign. If your governance calendar includes a risk register review, an RPA renewal and a DfE cyber security standards self-assessment that nobody has fully evidenced, you are in exactly the position this post is meant to address.
The Gap Between the Self-Assessment and What Happens on a Tuesday Morning
Most trust leaders we speak to say a version of the same thing: “We think we’re covered, but I couldn’t tell you who would do what at 7am on a Tuesday.” The DfE cyber security core standard sits ticked on a spreadsheet, backups are “running”, and the MIS is “in the cloud”, so the assumption is that this is somebody else’s problem.
Then the detail surfaces. Backups authenticate against the same domain the attacker just compromised. Multi-factor authentication is on for staff email but not for the remote access tool the support provider uses. Nobody has ever restored a server end to end and timed it, even though the standard asks you to test and log backups termly.
If you want an honest answer to the 7am question rather than a spreadsheet, book a free cyber risk assessment and we will map your current position against the DfE cyber security standards in plain English.
What Reducing the Cost of an Attack Actually Takes
Cutting the impact of an attack on a school is mostly about shortening two clocks: dwell time and recovery time.
Dwell time is the period an attacker spends inside your network before encryption, harvesting credentials and quietly deleting backups. At typically four to six days, there is a real window to catch them, but only if something is watching. Endpoint detection and response, which monitors device behaviour rather than scanning for known viruses, closes that window to hours when alerts are genuinely monitored out of hours rather than logged for review on Monday.
The second clock is recovery, and it is decided months in advance by choices nobody notices at the time. Two of those choices are no longer optional. The DfE core standard requires backups to be immutable, meaning they cannot be changed once created, and requires multi-factor authentication on all staff accounts with access to cloud services or remote access to on-site systems, as well as on IT administrative accounts.
The rest is preparation. Whether backups are separated from your main identity system. Whether you hold spare device images. Whether staff know the fallback process for registers and safeguarding with no network at all.
Our assessment work starts at school level rather than trust level, because averages hide the one site running an unsupported server in a cupboard. You get a prioritised, costed plan tied to the standards your auditors and RPA or insurance provider will actually ask about. For the wider picture, our guidance on cyber security for schools and trusts covers how these controls fit together.
What RPA and Cyber Insurance Won’t Cover
The Risk Protection Arrangement is not an insurance scheme. It is a DfE arrangement in which the department covers losses rather than a commercial insurer, and that distinction matters when you plan for an incident. RPA cyber cover is set at £250,000 for each and every loss, with a £750,000 aggregate for a group network, under the September 2026 membership rules.
RPA cyber cover carries four conditions. Members must hold offline backups, complete NCSC cyber security training, register with Police CyberAlarm, and have a cyber response plan in place. If you cannot evidence those at the point of claim, cover may not apply.
Commercial cyber policies set their own conditions precedent, which typically include multi-factor authentication on remote and privileged access, separated or offline backups, documented staff training and a written incident response plan. Multi-factor authentication is not an RPA condition, but DfE warns separately that weak account controls could leave you without cover for cyber attacks and incidents, and MFA is a requirement of the core standard in its own right.
Either way, the evidence requested at claim stage is logs and policy documents, not assurances. Cover also tends to reach incident response and forensics first, while the costs that hurt most sit outside it: staff time, supply cover, capital replacement of end-of-life kit, and the cost of running two systems during migration.
Treat cover as a contribution towards recovery, not a business continuity plan. Read your current terms alongside our business continuity planning guide for schools and trusts before renewal.
Step by Step: Testing Whether Your School Could Survive an Attack
- Ask for a restore test, not a backup report. The DfE core standard asks you to test and log backups termly, including the ability to recover and restore. Require your IT team or provider to restore one live server and one staff device this term, time it, and record the result in writing. A green backup dashboard proves the job ran, not that the data is usable.
- Verify MFA coverage line by line. List every route into your environment: staff email, MIS, remote desktop, VPN, third-party support tools and admin accounts. The standard requires MFA on all staff accounts with cloud or remote access and on IT administrative accounts. The gaps almost always sit in the supplier access routes.
- Confirm your backups are immutable and cannot be reached with domain admin credentials. Immutability is a DfE requirement, not a preference. If an attacker who compromises your network can also delete your backups, you do not have backups, you have copies.
- Run a 45-minute tabletop exercise with your senior team. Talk through a Monday morning with no MIS, no email and no printing, and note every decision you cannot currently make.
- Write down your incident response plan on paper. Include out-of-hours contacts, your ICO and DfE notification duties, your RPA or insurer notification route, and who speaks to parents. NCSC ransomware guidance (https://www.ncsc.gov.uk/ransomware/home) is a sound starting point, and RPA members need a cyber response plan as a condition of cover in any case.
- Take the gaps to your trust board with costs attached, not just risks. A prioritised, costed list gets a decision. A risk register entry gets noted.
What to Watch Out For
- Assuming cloud MIS means immunity. Attackers reach cloud systems through stolen staff credentials, so identity controls matter more than hosting location.
- Relying on a single named IT person. If recovery depends on one individual’s knowledge, a holiday or a resignation becomes a continuity risk.
- Confusing antivirus with EDR. Signature-based antivirus misses the manual, hands-on activity that precedes most school encryption events.
- Excluding suppliers from scope. Catering, cashless payment, door entry and trust-wide finance systems all hold personal data and all connect to your network.
- Leaving the incident response plan on a network share. If it encrypts with everything else, it is not a plan.
- Treating the ransom as an option of last resort. Paying is prohibited for academy trusts, so any plan that quietly assumes payment as a fallback is not a plan at all.
Quick Checklist
- MFA enforced on all staff accounts with cloud or remote access, all IT administrative accounts and every third-party remote access tool.
- At least one backup copy that is immutable, held offline and separated from your main identity system.
- A dated, documented restore test completed this term, in line with the DfE standard.
- EDR deployed to every server and endpoint, with alerts monitored outside school hours.
- A printed incident response plan held by two named senior leaders off site.
- Paper fallback processes agreed for registers, safeguarding records and parental contact.
- RPA conditions evidenced: offline backups, NCSC training completed, Police CyberAlarm registration, cyber response plan in place.
- Commercial policy conditions checked separately against what you can genuinely evidence today.
- A cyber risk assessment completed per school, not averaged across the trust.
Frequently Asked Questions
How long does it take a school to recover from ransomware?
Two to four weeks to restore enough service for teaching to continue reasonably normally, and often a full term to rebuild every system, reissue devices and clean up data. Trusts with tested immutable backups and current device images have recovered core services inside five days. Those relying on backups sitting on the compromised domain have taken months.
What does a ransomware attack cost a UK school or trust?
Direct recovery costs for a medium-sized trust commonly run into six figures once forensics, legal advice, temporary devices, supply cover and infrastructure replacement are counted. RPA cyber cover is capped at £250,000 for each and every loss, and commercial policies carry their own sublimits, so a significant share of the cost usually stays with the trust.
Do we have to report a ransomware attack to the ICO and the DfE?
Yes, in most cases. Under UK GDPR you must notify the ICO within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people’s rights and freedoms (https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/).
DfE’s reporting standard applies to all schools and colleges, not only academies. Report the incident to your RPA or cyber insurance provider, to Report Fraud on 0300 123 2040, and to the DfE sector cyber team at Sector.Incidentreporting@education.gov.uk. Report to the NCSC as well if the incident causes long-term school closure, the closure of more than one school, or serious financial damage. Check your own RPA or policy notification deadline, which is usually shorter than the ICO’s.
Should a school pay the ransom?
No. Academy trusts must not pay any cyber ransomware demands under the Academy Trust Handbook, and compliance with the handbook is a condition of the funding agreement between each trust and the Secretary of State for Education. The government has also confirmed plans to extend a legal ban on ransom payments across the public sector, including schools, though that is still being finalised through secondary legislation.
The practical case is just as clear. Payment does not guarantee a working decryptor or the deletion of stolen data, and the data has already left your network by the time the demand arrives. Budget instead for the controls that make payment irrelevant.
Find the Gaps on Your Terms
You are almost certainly one of two trusts right now. Either you can produce a restore test dated this term, a full MFA inventory and a printed incident response plan this week, or you cannot.
If you cannot, the decision in front of you is not whether to invest in cyber security. It is whether you find out where the gaps are on your terms in October, or on an attacker’s terms in the middle of exam season. The difference between a five-day recovery and a five-week one is made now, in quiet decisions about backups and identity, long before anyone sees a ransom note. It is also the difference between having an answer at 7am on a Tuesday and finding out you never had one.
Use Cyber Security Awareness Month to get a straight answer.
Request your free cyber risk assessment and DMS will give your senior team a per-school gap report and a costed priority list you can take to your next board meeting.
