What is at risk
Management information systems (MIS)
MIS systems are a primary target for data exfiltration in ransomware attacks.
These hold pupil attendance, assessment data, exclusions, medical notes, safeguarding flags and parent contact details.
Safeguarding and SEND records
Child Protection plans, EHCP documents and Early Help records are the highest-sensitivity data in a school. Ransomware groups have published this type of data on criminal leak sites.
Breach of safeguarding data is a mandatory requirement to notify the ICO.
Cloud platforms (Microsoft 365 and Google Workspace)
Email, shared drives, Teams and collaborative documents are all stored the cloud. Common weaknesses include:
- misconfigured sharing settings
- lack of multi-factor authentication
- over-permissive access
Phishing campaigns almost always target school using Microsoft or Google credentials.
Financial systems and payroll
School finance systems and payroll access are targets for business email compromise (BEC) attacks. Financial losses from BEC incidents can range from thousands to hundreds of thousands of pounds.
Because multi-academy trusts combine financial data across many schools, a single compromise can be significant.
Exam and assessment data
GCSE and A-level coursework, predicted grades and awarding body credentials are time-sensitive assets. Destructing or encrypting exam or course materials close to submission deadlines:
- can have serious consequences for pupils
- is irreversible without tested backups
Network infrastructure and Active Directory
Active Directory or Entra ID provides control over all user accounts and devices. Many school networks have open systems that are interconnected. This means that attackers can easily move within schools and systems once they have access.
Third-party EdTech and SaaS tools
Schools use third-party tools that hold pupil data, including:
- apps for communicating with parents and guardians
- reading platforms
- mental health check-in tools
- learning management systems
These are often adopted without IT security review. Even if a third party holds the data, under UK GDPR schools remain the data controller. This means they are responsible for the data, no matter what company stores or handles it for them.
People in schools may also use “shadow IT”. This is when staff use apps, websites, or tools for work that have not been approved by the school. For example, they might use personal email or document storage, messaging tools, or other online tools to store or share work data. This can create security, privacy, and data protection risks for the organisation.