Key insights
- One member of staff entering a password into a convincing fake page is how most school incidents begin.
- If data, security settings and backups all sit inside Microsoft 365, one compromised admin account reaches all three.
- Safeguarding records, SEN and pupil health data and family finance information are what make schools worth attacking.
- Email filtering reports what it blocked. Only a simulation tells you whether staff would click.
- Independent protection and immutable backups give the school a route back that does not depend on the affected environment.
A member of staff receives an email that looks entirely legitimate. They enter their Microsoft 365 password into a page that looks like the one they use every day. Nothing appears to happen.
If that account holds privileged access, or if someone can move from it to one that does, the school has a problem that reaches well beyond IT. Files are visible. Forwarding rules get changed quietly. Security settings are weakened. And if the backups are controlled inside the same Microsoft environment, the school's ability to recover is affected at the exact moment it is needed.
Why this lands on your desk
The data is not abstract. It is safeguarding records, SEN and pupil health information, staff files, finance documents and correspondence with parents, governors and external partners. That is what makes schools worth attacking, and it is why an account compromise stops being an IT issue and becomes an operational and safeguarding one.
It also tends to become the Business Manager's problem, because the questions that follow are not technical. They are about who was affected, what has to be reported, what parents are told, and when the school can operate normally again.
Five questions worth asking
You do not need to be a security specialist to get clear answers. Ask whoever manages your Microsoft 365:
- Where are our backups held? If they sit inside the same Microsoft environment, someone with admin access can change or delete them.
- Who has admin access? Privileged accounts should be few, reviewed and protected.
- Have we ever tested staff with a simulated phishing email? If so, how many clicked, and is it improving?
- What happens if an account is compromised? The plan should exist before it is needed, not after.
- When did we last restore from a backup to prove it works? Assuming is not the same as testing.
If any answer is unclear, that is useful information rather than a failure. It is usually where the real gap sits.
Whether your staff would actually click
Most schools have email filtering and assume it is doing the job. It is necessary, but it only reports what it stopped. It says nothing about what happens when a convincing message gets through, which some always will.
A phishing simulation sends safe, realistic test emails and shows you who clicked, who entered their credentials and who reported it. No blame and no consequences, just an honest picture of where the school stands. Most schools have never run one, so they have no idea what their own number is.
Training matters too, but the annual module completed in September is largely forgotten by October. Short, frequent and role-relevant training changes behaviour. A finance officer needs to recognise invoice fraud. A Head's PA needs to recognise impersonation. Everyone needs to know how to report a concern without feeling foolish.
What independent protection means
ARC Managed User Total Security sits outside Microsoft 365. Monitoring, response and recovery do not depend on the same admin controls an attacker is trying to abuse. If account behaviour looks wrong, an independent layer flags it, supports containment and explains the next step in plain English. If recovery is needed, immutable backups provide a clean route back rather than leaving the school dependent on controls inside the affected environment.
This is ARC's Prevent, Respond, Recover approach: prevent what can be prevented, respond quickly when something looks wrong, and recover safely if the worst happens.
This should not become another project
The point of the Health Check is to reduce what sits on your desk, not add to it. It is free, remote, and carries no obligation. ARC works alongside your existing IT team or provider rather than replacing them, and where fixes are needed ARC advises while your IT team implements. ARC is a Microsoft Authorised Education Partner, a G-Cloud supplier and Cyber Essentials certified. If the school decides to act, managed security starts at £5 per user per month with no hidden fees.