Security News

English Secondary Schools Recovering Faster From Cyber Incidents, Survey Finds

The Register · 1 Oct 2026
Key Takeaway Small businesses, like schools, should ensure leadership takes ownership of cybersecurity policy and incident response rather than leaving it solely to IT staff.

A survey of English secondary school teachers by exams regulator Ofqual has found a gradual decline in reported cybersecurity incidents, down to 27 percent of schools in 2025/26 from 34 percent two years earlier. Phishing remains the most common incident type, followed by data protection breaches, hacking and ransomware, which affected 2 percent of respondents. Staff data was the most frequently compromised information, though student data and work were also affected in some cases.

Recovery has notably improved, with 66 percent of affected schools reporting they bounced back immediately, up from 55 percent the previous year. The share of incidents causing what teachers described as critical damage also dropped from 10 to 7 percent, though Ofqual did not define this term and could not pinpoint what drove the improvement.

Despite these gains, awareness of specific security improvements remains patchy: 54 percent of teachers said they did not know what changes, if any, their school had made. Among those who did know, introducing a cybersecurity policy, testing backups and updating incident response plans were the most common steps. Teachers were also split on who owns cybersecurity responsibility, with 46 percent pointing to IT teams and only 9 percent naming senior leadership, a split Ofqual says is misplaced, arguing cybersecurity should be a leadership priority.

education sector incident response phishing ransomware cybersecurity governance

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.