England's schools recover faster from cyberattacks
Ofqual survey finds secondary schools reporting fewer incidents and quicker recovery, but training and responsibility gaps persist.
Secondary schools across England are reporting fewer cybersecurity incidents and faster recovery times, according to a survey by exams regulator Ofqual. The findings suggest that when attacks do land, schools are getting better at restoring systems quickly — though the survey also reveals persistent gaps in training and confusion over who owns security.
Incident rates edge downward
Twenty-seven percent of secondary schools reported a cybersecurity incident during the 2025/26 academic year, down from 29 percent a year earlier and 34 percent in 2023/24, according to the survey. Ofqual polled 3,775 secondary teachers in England in July. For questions about whole schools, it counted one response from the most senior participating teacher at each institution, producing a sample of up to 2,162 schools.
Phishing was the most commonly reported type of incident, followed by data protection breaches, hacking, and ransomware. Ransomware affected 2 percent of respondents. Staff data was the information most commonly compromised. Student data was affected in 13 percent of incidents, while student work was affected in 1 percent.
Recovery times improve
Recovery times improved more clearly than incident rates. Among schools reporting an incident, 66 percent said they recovered "immediately," up from 55 percent the previous academic year. A further 12 percent recovered within half a school term — roughly six or seven weeks — while 1 percent took longer than half a term and another 1 percent required at least a full term.
The proportion of reported incidents causing what respondents considered "critical damage" also fell from 10 to 7 percent, Ofqual said. The regulator did not define "critical damage," telling The Register that respondents were free to interpret the question in whatever way they felt best. Ofqual could not explain what had driven the apparent improvement.
Most teachers can't name changes
When asked what cybersecurity improvements their school had made during the past year, 54 percent of teachers selected "I don't know." Among the 46 percent who identified at least one change, half said their school had introduced a cybersecurity policy, 22 percent cited new or tested backup procedures, and 20 percent said they had completed or updated an incident response plan.
Teachers were divided over who bears primary responsibility for cybersecurity. Forty-six percent pointed to the IT team, while 40 percent said responsibility was shared among all staff. Just 9 percent identified senior leadership. Ofqual argued that cybersecurity is a leadership responsibility rather than solely an IT problem.
Training gaps persist
Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had, up from 28 percent a year earlier. A similar proportion said the training they received was not useful. Of those who received training, 65 percent said they made no changes as a result.
Wider survey shows frequent targeting
Ofqual's findings look considerably rosier than the government's Cyber Security Breaches Survey, published in April. That research found that 49 percent of primary schools, 73 percent of secondary schools, 88 percent of further education colleges, and 98 percent of higher education institutions had identified a breach or attempted attack during the previous 12 months.
The figures are not directly comparable. Ofqual asked secondary teachers about cybersecurity "incidents," while the government survey counted identified attacks and breaches regardless of whether they succeeded. The latter also covered education institutions across the UK rather than secondary schools in England alone.
Even so, the broader survey illustrated how frequently schools are targeted. Twenty-seven percent of further and higher education institutions identified attacks at least weekly, and almost half of those reporting a breach suffered an adverse impact on their systems.
School closures and internal threats
Successful attacks can force schools to close while systems are restored. In June, several schools across England and Wales shut temporarily while technicians investigated a malware scare. The ICO said last year that students were responsible for more than half of cyberattacks attributed to a known actor in the UK education sector.
Industry reaction to the findings
Mat Pullen, director of education at Jamf, said the attack frequency and recovery figures were promising, but the understanding of security responsibility was a concern.
"Reducing incidents matters, but so does recovering faster. Cyberattacks have closed schools for a week or longer in the past, further disrupting an education already hit by Covid and affecting the wider economy as parents take time off work."
— Mat Pullen, director of education at Jamf
Pullen added that cybersecurity is a shared responsibility of IT, teachers and senior leadership, and breaking down these silos keeps technology secure and lessons running.
Key figures from the survey
- 27 percent of secondary schools reported an incident in 2025/26, down from 29 percent a year earlier and 34 percent in 2023/24
- 66 percent of schools reporting an incident said they recovered immediately, up from 55 percent
- Ransomware affected 2 percent of respondents
- Student data was affected in 13 percent of incidents; student work in 1 percent
- 54 percent of teachers selected "I don't know" when asked what improvements their school had made
- 46 percent pointed to the IT team for primary responsibility, 40 percent said shared among all staff, 9 percent identified senior leadership
- Around a third of teachers had no cybersecurity training or were unsure, up from 28 percent
- 65 percent of trained teachers said they made no changes as a result
What this means for schools and families
The Ofqual data suggests that schools are getting better at the operational side of recovery — restoring systems quickly after an incident. For parents and students, that speed matters: a school that can bounce back immediately avoids the classroom closures that have disrupted education in the past.
But the survey also shows that training and responsibility remain unsettled. Around a third of teachers received no cybersecurity training or found it useless, and 65 percent of those trained changed nothing. That gap could affect how well schools respond when the next incident differs from the last.
The division over who owns cybersecurity — with 46 percent pointing to IT and only 9 percent to senior leadership — sits awkwardly against Ofqual's own position that it is a leadership responsibility. How schools close that gap could determine whether the recovery improvements hold up over time.
Sources
- The Register Original source
Continue Reading
ICO gets new board and a Manchester home
The UK data protection watchdog becomes a corporate body after a leadership scandal and a move from Wilmslow to Manchester.
Zimbra Flaw Exploited Before Disclosure
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.