Key insights
- Recovery is the cyber question a governing body can actually hold leadership to, because unlike prevention it has a testable answer today.
- If the backups sit inside the same Microsoft 365 environment as the problem, the school's route back is reached through the same administrator login as the breach.
- Immutable backups held outside Microsoft 365 mean a clean copy exists that a compromised administrator account cannot alter or delete.
- A backup nobody has ever restored from is a plan, not a capability. The date of the last successful test restore is the most useful number a board can ask for.
- A Free Security Health Check gives leadership a plain-English answer to the recovery question. It accredits nothing and commits you to nothing.
Most conversations about school cyber security are about prevention: what is blocked, what is filtered, what is patched. That is the right place to start and the wrong place to stop, because prevention is measured by what has not happened yet, and a governing body cannot hold anyone to that.
Recovery is different. It is specific, it is testable, and it has an answer today. If the school's Microsoft 365 environment were compromised tomorrow morning, how long until the school is operating normally, and how confident is anyone in that number?
Why the answer depends on where your backups sit
Email, finance, admissions, safeguarding and pupil records now live in Microsoft 365. A common setup is to protect that environment using Microsoft's own tools and keep the backup in another location inside the same Microsoft account. It looks tidy, and it is how the platform encourages you to work.
The difficulty only shows up at the moment it matters. Data, security settings and the recovery copy sit together, reached through the same privileged accounts. A single compromised administrator login can potentially affect all three, which means the thing the school would use to recover is inside the thing it is recovering from.
Why this belongs in the boardroom
For a governing body this is oversight rather than technology. Governors are accountable for continuity, for the school's reputation and for its duty of care to pupils and families. A serious disruption does not stay in the server room. It means letters to parents, questions from inspectors and insurers, safeguarding information potentially exposed, and days when the school cannot function normally.
Framed that way, "how quickly and safely could we recover?" is a governance measure, and it is one of the few cyber questions a board can ask without needing technical knowledge to judge the answer. We have set out the fuller list of questions a governing body should be able to answer in a separate guide.
Where the incidents that trigger it start
Almost always in the same place: one member of staff, one convincing email, one password entered into a page that looks legitimate. In the government's most recent Cyber Security Breaches Survey, phishing was the main threat behind 96% of secondary school breaches and 90% of primary. Those figures cover state-funded schools, since the survey places independent schools in its business sample, where the picture is less granular. The pattern is the same either way, and it points at people rather than infrastructure.
Which is why the recovery question and the training question are two ends of the same one. Filtering reports what it blocked. It says nothing about what happens when something gets through, which occasionally it will.
What a real recovery position looks like
Three things separate a bad week from a bad term.
An independent copy. Backups held outside Microsoft 365, so the route back does not depend on the environment that has been compromised.
Immutability. Copies that cannot be altered or deleted even by someone holding administrator credentials, so an attacker cannot destroy the way back on their way in.
A tested restore. Assuming a backup works is not the same as knowing it does. Ask for the date of the last successful test restore, and treat "we have backups" as an incomplete answer.
ARC Secure is built this way, following a simple structure: Prevent, Respond, Recover. Prevention includes phishing simulation and staff security-awareness training. Recovery rests on immutable backups held independently of Microsoft 365, so a clean copy and a route back always exist.
A low-commitment first step
None of this requires the board to become technical. It requires one thing: a clear, independent picture of where the school stands today, including how it would recover. The Free Security Health Check is a short, plain-English review that gives leadership and governors an honest view they can act on, or be reassured by. It is not an audit or a compliance sign-off.
If the school does decide to act, ARC's managed security starts at £5 per user per month with no hidden fees, and works alongside your existing IT team or provider rather than replacing them. ARC is a Microsoft Authorised Education Partner, a G-Cloud supplier and Cyber Essentials certified.
Sources