English Schools Show Slight Improvement in Cyber Incident Response, But Training Gaps Persist
A survey of English secondary schools reveals a modest decrease in cyber incidents and faster recovery times, yet significant gaps remain in teacher awareness and cybersecurity training.

England's secondary schools are demonstrating a marginal improvement in their cybersecurity posture, with a slight reduction in reported incidents and quicker recovery times during the 2025/26 academic year. According to a survey by the exams regulator Ofqual, 27 percent of schools experienced a cyber incident, a decrease from 29 percent the previous year and 34 percent in 2023/24. This positive trend is further underscored by enhanced recovery capabilities, with 66 percent of affected schools reporting immediate restoration of services, a notable increase from 55 percent in the prior academic year.
Phishing continues to be the most prevalent threat, followed by data protection breaches, hacking, and ransomware, which affected 2 percent of respondents. Staff data was the most frequently compromised information, with student data impacted in 13 percent of incidents and student work in one percent. While the overall number of incidents is down, the types of threats remain consistent with previous years, highlighting the persistent challenges posed by common attack vectors.
The speed of recovery has seen a significant uplift, with 66% of schools able to restore operations immediately after an incident. An additional 12 percent managed recovery within half a school term, and only a small fraction, one percent, required more than half a term. The proportion of incidents deemed "critical" also fell from ten to seven percent, although the definition of critical damage was left to the interpretation of the respondents, making direct comparisons difficult.
Despite these improvements, a significant portion of educators remain unaware of the cybersecurity measures being implemented within their institutions. A substantial 54 percent of teachers surveyed indicated they did not know what cybersecurity improvements their school had made in the past year. Among those who were aware of changes, common measures included the introduction of cybersecurity policies, updated backup procedures, and revised incident response plans.
Responsibility for cybersecurity within schools remains a point of division. While 46 percent of teachers attributed primary responsibility to the IT team, 40 percent believed it was a shared duty among all staff, and only nine percent identified senior leadership. Ofqual, however, emphasized that cybersecurity is fundamentally a leadership responsibility, suggesting a disconnect between perception and best practice.
Furthermore, the survey revealed persistent issues with cybersecurity training. Approximately one-third of teachers reported receiving no training in the past year or were unsure if they had, an increase from the previous year. A similar proportion found the training they did receive to be unhelpful, with 65 percent of those trained making no changes to their practices as a result.
These findings present a more optimistic picture than the government's broader Cyber Security Breaches Survey, which indicated higher breach rates across various educational institutions. However, the Ofqual survey's focus on secondary schools in England and its definition of "incidents" rather than just successful breaches make direct comparisons challenging. Nevertheless, the data suggests a growing, albeit uneven, resilience within the English school system against cyber threats.