Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Schools in England reported fewer cyber incidents in 2025/2026 than in either of the previous two academic years, and more schools affected by incidents said they recovered immediately. But attacks remain a real risk: 7% of schools reported critical damage, while separate government findings show gaps in school cyber-security controls.

Are UK schools getting better at dealing with cyber attacks?

The latest Ofqual figures, reported by ITPro on 1 October 2026, point to improvement among schools in England on two measures: reported incident prevalence fell, and immediate recovery among affected schools rose. They do not show that schools are safe from attacks or that every school is prepared.

Ofqual data reported by ITPro shows that 27% of schools reported a cyber incident in academic year 2025/2026, compared with 29% in 2024/2025 and 34% in 2023/2024. Among schools reporting incidents, 66% said they could recover immediately in 2025/2026, up from 55% in 2024/2025. However, 7% reported critical damage in 2025/2026.

These are reported survey figures, not a count of every attack. They describe schools in England and should not be treated as a UK-wide result covering all nations or all education institutions. The pattern supports a qualified conclusion: the figures have improved, but the remaining incidents and critical damage show why preparedness still matters.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many schools have a cyber incident?

The Ofqual series reported by ITPro puts the share of schools in England reporting an incident at 34% in 2023/2024, 29% in 2024/2025 and 27% in 2025/2026. That is a decline across three academic years, but more than one in four schools still reported an incident in the latest year.

A separate dataset comes from the Department for Science, Innovation and Technology (DSIT) and Home Office’s Cyber Security Breaches Survey 2025/2026. It reports findings for primary schools, secondary schools, further education (FE) and higher education (HE). Its results reflect incidents organisations identified and were willing to report, so they cannot establish the full number of incidents that occurred. Because the two sources have different scopes and survey methods, their percentages should not be combined into one trend line.

Rank #2
Teacher Record Book
  • Keep track of everything from attendance to test scores
  • Spiral bound
  • Measures 8-1/2" x 11"

Can schools recover quickly from a cyber attack?

In the Ofqual figures reported by ITPro, 66% of incident-affected schools in England said they could recover immediately in academic year 2025/2026, compared with 55% in 2024/2025. The earlier Ofqual release, dated 30 September 2025, also reported that immediate recovery had fallen from 63% in 2023/2024 to 55% in 2024/2025. Read together, these figures suggest a rebound in the latest year after a decline, rather than a consistently rising recovery rate.

Fast recovery is only one measure of impact. The 7% of schools reporting critical damage in 2025/2026 indicates that incidents can still have serious consequences. Ofqual’s Executive Director of General Qualifications, Amanda Swann, said: “Cyber attacks can have a devastating impact on students’ academic work.” The statement appeared in Ofqual’s 30 September 2025 release.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does readiness look like across education?

The government’s 2025/2026 education survey shows that readiness is not uniform. For example, 85% of primary schools and 73% of secondary schools reported having a board member, governor, trustee or senior manager responsible for cyber security. Those figures describe governance ownership, not whether a school has effective technical protection or can restore systems after an attack.

The same survey identifies patch management as a relative weakness in schools. A patch-management policy was reported by 45% of primary schools and 62% of secondary schools in 2025/2026; the secondary-school figure was up from 56% in 2024/2025. These school findings sit alongside separate results for FE and HE institutions, which should not be presented as school results.

The DSIT and Home Office education findings are useful for comparing institution types, but the key measures answer different questions: incident reporting concerns experience, senior responsibility concerns governance, continuity planning concerns recovery arrangements, and patch management concerns a technical control. A stronger result in one area does not prove strength in the others.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should a school do to prepare for a cyber attack?

Preparation should connect responsibility, prevention and recovery rather than rely on a single tool. The National Cyber Security Centre (NCSC) provides resources for school boards, senior leaders and staff through its Cyber Security for Schools collection. The NCSC says its Board Toolkit promotes a methodical, proactive approach and outlines basic safeguards intended to reduce the likelihood and impact of attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Assign clear responsibility. Make sure a named senior leader or governing representative owns cyber-security oversight and knows how to escalate an incident.
  • Keep systems maintained. Establish a process for tracking and applying security updates, including a way to identify systems that have not been patched.
  • Plan for continuity and restoration. Decide how teaching and essential operations will continue if systems or data become unavailable, and ensure staff know the response arrangements.
  • Train staff. Ofqual reported that teacher cyber-security training reached 72% in 2024/2025, compared with 61% in 2023/2024. Training supports readiness, but does not replace technical safeguards or recovery planning.

Use backups as part of a recovery plan

The Department for Education’s Technology in Schools Survey 2024 to 2025 describes the NCSC backup pattern as three copies of important data, across at least two separate devices, with at least one copy offsite. It found that 47% of primary schools and 76% of secondary schools kept important data across at least two devices with one copy offsite. The report also noted that some IT leads were unsure whether their school had a recovery plan.

A backup is useful only if the school can restore from it when needed. A single external drive does not meet the described multi-copy, separate-device and offsite pattern by itself. Schools can use the Department for Education survey alongside NCSC guidance when reviewing how backups fit into a broader recovery arrangement.

Quick Recap

Bestseller No. 2
Teacher Record Book
Teacher Record Book
Keep track of everything from attendance to test scores; Spiral bound; Measures 8-1/2" x 11"
$4.89
SaleBestseller No. 5

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.