What's at risk
MIS systems are a primary target for data exfiltration in ransomware attacks.
These hold pupil attendance, assessment data, exclusions, medical notes, safeguarding flags and parent contact details.
Actions to protect MIS data
enable MFA (multi-factor authentication) for administrator accounts
apply least-privilege access and review permissions regularly
check that backup systems are working and test restoration
keep MIS software and supporting infrastructure up to date
monitor access to sensitive pupil and staff records
secure data exports and third-party integrations
Child Protection plans, EHCP documents and Early Help records are the highest-sensitivity data in a school. Ransomware groups have published this type of data on criminal leak sites.
Breach of safeguarding data is a mandatory requirement to notify the ICO.
Actions to protect safeguarding and SEND records
restrict access to staff who need the information for their role
use MFA (multi-factor authentication) for systems containing safeguarding and SEND records
store records in approved systems with audit logging enabled
regularly review user permissions and remove access when staff leave or change roles
ensure backups are encrypted, tested and protected from ransomware
Email, shared drives, Teams and collaborative documents are all stored the cloud. Common weaknesses include:
- misconfigured sharing settings
- lack of multi-factor authentication
- over-permissive access
Phishing campaigns almost always target school using Microsoft or Google credentials.
Actions to protect cloud platforms
enable MFA (multi-factor authentication) for all staff accounts, prioritising administrators
review and restrict external sharing settings
apply least-privilege access so users only have access to what they need
monitor for suspicious sign-ins and account activity
maintain offline or immutable backups of critical data following 3-2-1 backup principles
GCSE and A-level coursework, predicted grades and awarding body credentials are time-sensitive assets. Destructing or encrypting exam or course materials close to submission deadlines:
- can have serious consequences for pupils
- is irreversible without tested backups
Actions to protect exam and assessment data
follow 3-2-1 backup principles
test restoration before key submission periods
restrict access to awarding body accounts and credentials
enable MFA (multi-factor authentication) on assessment and examination systems
keep copies of critical coursework and assessment data separate from production systems
develop contingency plans for cyber incidents during exam periods
Active Directory or Entra ID provides control over all user accounts and devices. Many school networks have open systems that are interconnected. This means that attackers can easily move within schools and systems once they have access.
Actions to protect network infrastructure and Active Directory
change default passwords and disable unused accounts
use MFA (multi-factor authentication) for administrator accounts
apply security updates promptly to servers, network devices and endpoints
limit administrative privileges and use separate admin accounts for privileged tasks
segment networks to reduce the ability of attackers to move between systems
monitor privileged account activity and review permissions regularly
School finance systems and payroll access are targets for business email compromise (BEC) attacks. Financial losses from BEC incidents can range from thousands to hundreds of thousands of pounds.
Because multi-academy trusts combine financial data across many schools, a single compromise can be significant.
Actions to protect financial systems
take extra care at times when payment are made
require independent verification of any supplier bank details changes
use MFA (multi-factor authentication) for finance and payroll software logins
separate financial approval and payment-authorisation responsibilities
monitor for unusual payment requests and impersonation attempts
train staff to recognise business email compromise (BEC) scams
Schools use third-party tools that hold pupil data, including:
- apps for communicating with parents and guardians
- reading platforms
- mental health check-in tools
- learning management systems
These are often adopted without IT security review. Even if a third party holds the data, under UK GDPR schools remain the data controller. This means they are responsible for the data, no matter what company stores or handles it for them.
People in schools may also use “shadow IT”. This is when staff use apps, websites, or tools for work that have not been approved by the school. For example, they might use personal email or document storage, messaging tools, or other online tools to store or share work data. This can create security, privacy, and data protection risks for the organisation.
Actions to protect third-party and SaaS tools
carry out security and data protection due diligence (including Cyber Essentials) before procurement
maintain a register of third-party applications that process school data
ensure suppliers support MFA (multi-factor authentication), strong access controls and incident reporting
review data-sharing arrangements and contracts regularly
establish clear policies governing the use of unapproved (“shadow IT”) applications
provide staff guidance on approved tools and secure handling of pupil data