Skip to main content

Why cyber security matters for schools

Understand the threats facing schools so you can prepare and protect your organisation.

What is at risk

Management information systems (MIS)

MIS systems are a primary target for data exfiltration in ransomware attacks.

These hold pupil attendance, assessment data, exclusions, medical notes, safeguarding flags and parent contact details.

Safeguarding and SEND records

Child Protection plans, EHCP documents and Early Help records are the highest-sensitivity data in a school. Ransomware groups have published this type of data on criminal leak sites.

Breach of safeguarding data is a mandatory requirement to notify the ICO.

Cloud platforms (Microsoft 365 and Google Workspace)

Email, shared drives, Teams and collaborative documents are all stored the cloud. Common weaknesses include:

  • misconfigured sharing settings
  • lack of multi-factor authentication
  • over-permissive access

Phishing campaigns almost always target school using Microsoft or Google credentials.

Financial systems and payroll

School finance systems and payroll access are targets for business email compromise (BEC) attacks. Financial losses from BEC incidents can range from thousands to hundreds of thousands of pounds.

Because multi-academy trusts combine financial data across many schools, a single compromise can be significant.

Exam and assessment data

GCSE and A-level coursework, predicted grades and awarding body credentials are time-sensitive assets. Destructing or encrypting exam or course materials close to submission deadlines:

  • can have serious consequences for pupils
  • is irreversible without tested backups

Network infrastructure and Active Directory

Active Directory or Entra ID provides control over all user accounts and devices. Many school networks have open systems that are interconnected. This means that attackers can easily move within schools and systems once they have access.

Third-party EdTech and SaaS tools

Schools use third-party tools that hold pupil data, including:

  • apps for communicating with parents and guardians
  • reading platforms
  • mental health check-in tools
  • learning management systems

These are often adopted without IT security review. Even if a third party holds the data, under UK GDPR schools remain the data controller. This means they are responsible for the data, no matter what company stores or handles it for them.

People in schools may also use “shadow IT”. This is when staff use apps, websites, or tools for work that have not been approved by the school. For example, they might use personal email or document storage, messaging tools, or other online tools to store or share work data. This can create security, privacy, and data protection risks for the organisation.