UK schools have improved their ability to bounce back from cyberattacks, with two-thirds now able to restore operations immediately after an incident, according to new government data released October 1 by the Office of Qualifications and Examinations Regulation (Ofqual). The figures, published to mark Cyber Security Awareness Month, show that while schools are responding more effectively when breaches occur, significant weaknesses in cybersecurity readiness persist across the education sector.
The proportion of schools hit by cyber incidents has dropped steadily in recent years, falling from 34% in the 2023-24 academic year to 29% in 2024-25 and down to 27% for 2025-26, the data reveals. When attacks do happen, 66% of schools can now recover right away, a jump from 55% in the previous year. The share of schools suffering critical damage from attacks has declined to 7%. The survey drew responses from 2,162 schools and 3,775 teachers. However, when asked who bears primary responsibility for cybersecurity, nearly half of teachers—46%—pointed to their IT team, 40% said all staff share the burden, and just 9% identified senior leadership as playing a role.
"It's encouraging to see schools recovering faster, but a cyber breach can still cause real uncertainty for students if coursework or marks are lost, and staff confidence can be affected long after systems are back online," said Amanda Swann, Ofqual's executive director of delivery. She emphasized that "cybersecurity isn't just an IT problem; it's a leadership responsibility," noting that routine backups and a well-defined response plan can significantly improve outcomes when incidents strike. Yet the report shows that while 55% of secondary schools surveyed claim to have already implemented protective measures, a substantial portion have not yet put in place basic safeguards such as cybersecurity policies, risk assessments, or backup and recovery protocols.
The gap between IT responsibility and leadership ownership may explain why many schools continue to deprioritize cyber initiatives, industry observers suggest. Mat Pullen, director for education at Jamf and a former secondary school teacher, warned that the 45% of schools that haven't taken preventative action need to act urgently. He argued that schools must first evaluate their risks—understanding which threats target items on their networks—before they can properly tackle the problem. Pullen recommended building an internet safety framework that includes content filtering to block inappropriate material and threat prevention software to stop attacks. Cyberattacks have previously forced schools to close for a week or longer, he noted, compounding disruption in an education system already strained by Covid and affecting the broader economy as parents miss work to care for children.
Moving forward, the analysis indicates that cybersecurity must become a shared responsibility spanning IT staff, teachers, and senior leadership rather than remaining siloed within technology teams. Breaking down these divisions keeps technology secure and lessons running smoothly, experts contend. Schools that have yet to act should immediately assess their vulnerabilities and establish robust policies, the data suggests, transforming cybersecurity from an afterthought into a core operational priority that protects both student outcomes and institutional continuity. For education leaders evaluating resource allocation, the choice between investing in prevention now versus managing costly disruption later grows starker as digital infrastructure becomes inseparable from daily instruction.

