Skip to main content

Cyber security and the education sector

What's at risk

Management information systems (MIS)

MIS systems are a primary target for data exfiltration in ransomware attacks.

These hold pupil attendance, assessment data, exclusions, medical notes, safeguarding flags and parent contact details.

Actions to protect MIS data

  • enable MFA (multi-factor authentication) for administrator accounts

  • apply least-privilege access and review permissions regularly

  • check that backup systems are working and test restoration

  • keep MIS software and supporting infrastructure up to date

  • monitor access to sensitive pupil and staff records

  • secure data exports and third-party integrations

Safeguarding and SEND records

Child Protection plans, EHCP documents and Early Help records are the highest-sensitivity data in a school. Ransomware groups have published this type of data on criminal leak sites.

Breach of safeguarding data is a mandatory requirement to notify the ICO.

Actions to protect safeguarding and SEND records

  • restrict access to staff who need the information for their role

  • use MFA (multi-factor authentication) for systems containing safeguarding and SEND records

  • store records in approved systems with audit logging enabled

  • regularly review user permissions and remove access when staff leave or change roles

  • ensure backups are encrypted, tested and protected from ransomware

Cloud platforms

Email, shared drives, Teams and collaborative documents are all stored the cloud. Common weaknesses include:

  • misconfigured sharing settings
  • lack of multi-factor authentication
  • over-permissive access

Phishing campaigns almost always target school using Microsoft or Google credentials.

Actions to protect cloud platforms

  • enable MFA (multi-factor authentication) for all staff accounts, prioritising administrators

  • review and restrict external sharing settings

  • apply least-privilege access so users only have access to what they need

  • monitor for suspicious sign-ins and account activity

  • maintain offline or immutable backups of critical data following 3-2-1 backup principles

Exam and assessment data

GCSE and A-level coursework, predicted grades and awarding body credentials are time-sensitive assets. Destructing or encrypting exam or course materials close to submission deadlines:

  • can have serious consequences for pupils
  • is irreversible without tested backups

Actions to protect exam and assessment data

  • follow 3-2-1 backup principles

  • test restoration before key submission periods

  • restrict access to awarding body accounts and credentials

  • enable MFA (multi-factor authentication) on assessment and examination systems

  • keep copies of critical coursework and assessment data separate from production systems

  • develop contingency plans for cyber incidents during exam periods

Network infrastructure and Active Directory

Active Directory or Entra ID provides control over all user accounts and devices. Many school networks have open systems that are interconnected. This means that attackers can easily move within schools and systems once they have access.

Actions to protect network infrastructure and Active Directory

  • change default passwords and disable unused accounts

  • use MFA (multi-factor authentication) for administrator accounts

  • apply security updates promptly to servers, network devices and endpoints

  • limit administrative privileges and use separate admin accounts for privileged tasks

  • segment networks to reduce the ability of attackers to move between systems

  • monitor privileged account activity and review permissions regularly

Financial systems and payroll

School finance systems and payroll access are targets for business email compromise (BEC) attacks. Financial losses from BEC incidents can range from thousands to hundreds of thousands of pounds.

Because multi-academy trusts combine financial data across many schools, a single compromise can be significant.

Actions to protect financial systems

  • take extra care at times when payment are made

  • require independent verification of any supplier bank details changes

  • use MFA (multi-factor authentication) for finance and payroll software logins

  • separate financial approval and payment-authorisation responsibilities

  • monitor for unusual payment requests and impersonation attempts

  • train staff to recognise business email compromise (BEC) scams

Third party EdTech and SAAS tools

Schools use third-party tools that hold pupil data, including:

  • apps for communicating with parents and guardians
  • reading platforms
  • mental health check-in tools
  • learning management systems

These are often adopted without IT security review. Even if a third party holds the data, under UK GDPR schools remain the data controller. This means they are responsible for the data, no matter what company stores or handles it for them.

People in schools may also use “shadow IT”. This is when staff use apps, websites, or tools for work that have not been approved by the school. For example, they might use personal email or document storage, messaging tools, or other online tools to store or share work data. This can create security, privacy, and data protection risks for the organisation.

Actions to protect third-party and SaaS tools

  • carry out security and data protection due diligence (including Cyber Essentials) before procurement

  • maintain a register of third-party applications that process school data

  • ensure suppliers support MFA (multi-factor authentication), strong access controls and incident reporting

  • review data-sharing arrangements and contracts regularly

  • establish clear policies governing the use of unapproved (“shadow IT”) applications

  • provide staff guidance on approved tools and secure handling of pupil data