What’s the Real Risk and Cost of a Cyber Attack on a School?

The real cost of a cyber attack on a school is rarely a single ransom figure. When an incident goes badly it is lost teaching days, a rebuilt network, safeguarding records you cannot account for, an ICO notification clock running at 72 hours, and a governing body asking why nobody spotted it sooner.

School cyber security risk is now a mainstream operational risk, not an IT department footnote. The Cyber Security Breaches Survey 2025/26 found that 73 percent of secondary schools identified a breach or attack, a significant rise from 60 percent the year before.

Most incidents are absorbed without serious operational damage. The ones that are not tend to run over weeks rather than hours, because recovery depends on backups, documentation and decisions made long before the incident. This post sets out the operational, financial and safeguarding consequences in plain terms, then what the DfE digital and technology standards actually expect you to have in place.

Who This Is For

This is written for the people who carry the consequences of an incident rather than the ones who configure the firewall. School Business Managers and Finance Directors who sign off the insurance renewal and find the premium conditional on controls nobody has evidenced.

It is also for IT Managers and Network Managers in single schools, multi-academy trusts and FE colleges, often supporting 1,500 users with a team of two, and for Headteachers, CEOs and Designated Safeguarding Leads who need to know whether pupil records are genuinely protected. If you are preparing a risk register entry, a trust board paper or a half-term improvement plan, this is pitched at your level, not at a security engineer’s.

Why Schools Underestimate the Damage Until It Happens

Most schools price a cyber attack as a recovery cost and nothing else. It is worth being precise about how often that cost actually lands. In the 2025/26 survey, around one in five secondary schools that identified a breach reported a negative impact on their systems, and ransomware affected 6 percent of them. The majority of incidents are absorbed. A minority are not, and those are the ones that reshape a school year.

At the severe end, the pattern is consistent: SIMS or Arbor inaccessible during census or exams, attendance and safeguarding logs unavailable to the DSL, payroll missed, admissions stalled, and senior leaders spending weeks on incident management instead of teaching and learning.

Then come the slower costs. Insurers scrutinise whether stated controls were actually in place. Parents ask what happened to their child’s data.

A safeguarding data breach is not just a GDPR matter, it is a trust matter, and it is typically the hardest part of an incident to explain publicly. Our guidance on business continuity planning for schools and trusts covers how to plan for the operational side before you need it.

The DMS and Boxphish webinar on school cyber security covers the same questions this post answers, asked live by schools. Watch it on demand and share it with your SLT.

How to Quantify School Cyber Security Risk in Terms Your Board Understands

School cyber security risk becomes manageable the moment you express it as downtime, data and duty rather than as technology. DMS works with schools, trusts and colleges across the sector, so we frame assessments around four questions a governing body can actually interrogate:

  • How long would we be unable to teach?
  • What data would we be unable to account for?
  • What would we have to report, and to whom?
  • What would it cost us in staff time to recover?

That framing changes the conversation. Instead of asking for budget for a product, you present a risk with a measurable exposure and a control that reduces it.

Patching is the clearest example. The Cyber Security Breaches Survey 2025/26 found that 62 percent of secondary schools have a policy to apply security updates within 14 days, up from 56 percent the year before. That is real progress, and it still leaves nearly four in ten without the single control the DfE standard is most explicit about. The same survey found 86 percent of secondary schools use some form of two-factor authentication on networks or applications, which is encouraging but is not the same as multi-factor authentication enforced on every account that needs it.

Both gaps are cheap to close and very hard to defend after an incident. Our education cyber security reviews start here, with evidence rather than assumption.

Legal, Contractual or Expected: Know Which Obligation You Are Meeting

Schools are told to do a great many things, and the word “must” gets used loosely. It helps to separate the three kinds of obligation, because the consequence of missing each one is different.

Legal. UK GDPR requires you to notify the ICO within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in a risk to people’s rights and freedoms. Keeping Children Safe in Education carries a statutory duty that includes having appropriate cyber security measures in place.

Contractual. If you are in the Risk Protection Arrangement, a cyber response plan and backups at the 3-2-1 level are conditions of cover, and members must be able to evidence that relevant users complete the free NCSC training each year. For further education colleges, Cyber Essentials certification is a requirement under the college funding agreement. These are not optional guidance.

Expected. The DfE digital and technology standards are the department’s recommended way of meeting the KCSIE duty. They are not law in themselves, but insurers, auditors and trust boards use them to judge whether a school acted reasonably, and failing to meet them is difficult to justify after an incident.

What the DfE Digital and Technology Standards Expect from Schools

The DfE digital and technology standards for schools and colleges set out what good looks like across cyber security, filtering and monitoring, networks and devices. They apply in England.

The cyber security core standard (https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/cyber-security-core-standard) is more specific than most summaries suggest. It asks for:

  • MFA scope. Multi-factor authentication on all staff accounts with access to cloud services or remote access to on-site systems, and on all IT administrator accounts.
  • Patching. Vulnerabilities fixed within 14 days of an update being released where they are rated critical or high (CVSS 7.0 or above) or are unrated.
  • Backups. At least three copies of your data on at least two devices, with one held off-site, and backups that are immutable, meaning they cannot be changed once created. Backups must be tested and logged termly, including the ability to recover and restore.
  • Risk assessment. An annual cyber risk assessment, revisited every term. The termly revisit is the part schools most often miss.
  • Training. At least annually, covering students, staff, at least one governor or trustee, and anyone else with a login, including supply and agency staff.

The standard also covers controlled administrator access, anti-malware, firewalls, a business continuity and disaster recovery plan, and incident reporting.

Step by Step: Running a Half-Term Cyber Risk Review

  1. Pull your current position onto one page. List every system holding pupil or staff data, who administers it, where it backs up to, and when that backup was last restored and verified, not just last run.
  2. Audit accounts and access. Identify every administrator account, every shared login and every account belonging to a leaver. Confirm MFA is enforced wherever the standard requires it, and extend it to email, MIS and remote access as a matter of good practice.
  3. Test the backup, properly. Restore a sample of data to a separate environment and record how long it took. The standard asks you to test and log backups termly. A backup you have never restored is an assumption, not a control.
  4. Map yourself against the DfE digital and technology standards. Mark each area as met, partially met or not met, and note the evidence you would show an insurer or auditor for each one.
  5. Check filtering and monitoring with your DSL and SLT. Confirm the logs are reviewed by a named person, that the review is recorded, and that safeguarding leads know how to escalate.
  6. Write the board paper now, while the detail is fresh. Three risks, three costed actions, three owners, three dates. Take it to the next governors or trust board meeting.

What to Watch Out For

  • Assuming your MAT central team has it covered. Trust-wide policy rarely survives contact with legacy kit in an individual academy, and the breach happens locally.
  • Treating cyber awareness training for schools as a September induction slide. The standard asks for annual training covering students, staff, a governor or trustee and anyone else with a login. Phishing simulations across the year change behaviour. A one-off presentation does not.
  • Declaring unverified controls on a school cyber insurance proposal form. Insurers check at claim stage, and an inaccurate declaration can undermine cover.
  • Leaving backups on the same network as the live data. Ransomware encrypts what it can reach, including the drive labelled backup. The standard asks for three copies, two devices, one off-site, and immutability.
  • Forgetting supplier risk. Catering, transport, HR and parent payment platforms all hold your data.

Quick Checklist

  • Multi-factor authentication enforced on all staff accounts with cloud or remote access and all IT administrator accounts, and extended to email and MIS as good practice.
  • Security updates rated critical or high (CVSS 7.0 or above) or unrated applied within 14 days of release, with a named owner and a documented policy.
  • At least three copies of your data on at least two devices, one held off-site, with backups immutable and a restore tested and logged this term.
  • An annual cyber risk assessment that is revisited every term, not filed and forgotten.
  • An incident response plan that names who calls the ICO, the DfE, the insurer or RPA and parents, with out-of-hours contact numbers.
  • Administrator accounts separated from day-to-day user accounts.
  • Filtering and monitoring logs reviewed and recorded by a named person, with DSL and SLT oversight.
  • Cyber awareness training completed at least annually by students, staff, at least one governor or trustee and anyone else with a login, including supply staff, with completion data you can produce on request. RPA members must be able to evidence the free NCSC training.
  • A risk register entry for cyber that the board has actually discussed this academic year.

Frequently Asked Questions

How much does a cyber attack cost a school?

There is no single figure, because the largest costs are usually indirect. Expect to account for lost teaching and administrative time, specialist incident response, device and server rebuilds, temporary manual processes, legal and regulatory advice, and insurance excess. Schools that recover quickly almost always do so because they had tested backups and a written response plan before the incident.

Do schools have to report a cyber attack?

Yes, in most cases. Under UK GDPR you must notify the ICO within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people’s rights and freedoms (https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/), and you must inform affected individuals where there is a high risk to them.

DfE’s reporting standard applies to all schools and colleges in England. Report the incident to your RPA or cyber insurance provider, to Report Fraud on 0300 123 2040, and to the DfE sector cyber team at Sector.Incidentreporting@education.gov.uk. Report to the NCSC as well if the incident causes long-term school closure, the closure of more than one school, or serious financial damage. Check your own RPA or policy terms for their notification deadline.

Are the DfE digital and technology standards mandatory for schools?

The standards themselves are the department’s recommended way of meeting the statutory duty in Keeping Children Safe in Education, rather than law in their own right. Some of what they describe is binding through another route: RPA members are contractually required to hold a cyber response plan and 3-2-1 backups, and further education colleges must hold Cyber Essentials certification under their funding agreement. Treat the standards as the minimum expected position and check which parts apply to you contractually.

What is the most common way schools get breached?

Compromised credentials and phishing remain the dominant routes, usually through a staff member entering details on a convincing fake login page. That is why multi-factor authentication and regular, realistic staff training deliver more risk reduction per pound than almost any other control available to schools.

Does a MAT need a different approach to cyber security than a single school?

Yes. MAT cyber security has to reconcile central policy with very different estates, budgets and legacy systems in each academy. The practical answer is a trust-wide standard with per-school gap assessments, so the board can see exactly which sites fall short and what it would cost to bring them up.

Two Hours Before Half Term

You now have a choice that half-term makes unusually easy. You can file this alongside the other things to look at later, or you can spend two hours before the break mapping your school against the standards while you still have the headspace.

Schools that get breached are not careless, they are busy, and the gap between knowing and evidencing is where most of them get caught. Most incidents will not reshape your year. The point of the controls is that you cannot tell in advance which one will, and the ones that matter most are not expensive. They are specific, checkable and overdue in more schools than anyone would like to admit.

Book a school cyber risk review with the DMS education team and get a gap report you can take straight to your board.

Alternatively…

Watch our DfE Standards and Cyber Risk Self-Assessment for Schools

Contact us below