Key insights
- The Department for Education expects cyber risks to be flagged to governors or trustees as part of the school's risk management process, and a named senior leader to be accountable for them.
- A governing body should be able to answer a short set of plain-English questions today, from who holds administrator access to when security was last independently reviewed.
- Training tells staff what to look for. Only a phishing simulation tells you whether it worked, and most boards have never seen that number for their own school.
- Relying on a single vendor to both hold and protect your data is itself a governance risk.
- A security health check is one independent input to oversight. It is not a certification and not a guarantee of compliance.
The Department for Education expects cyber risks to be flagged to your governors or trustees as part of the school's risk management process, and it expects a named member of the senior leadership team to be accountable for them. Governors are not expected to run the technology. They are expected to provide oversight, which in practice means asking clear questions and expecting clear answers.
This guide sets out those questions in plain English. It is written for Heads, CEOs and operations leaders who report to a governing body, and for the governors and trustees they answer to. None of it requires technical expertise, and all of it is fair to raise at your next meeting.
A board-level checklist: what you should be able to answer today
Who has access, and who is accountable?
- Do we know exactly who holds administrator access to our core systems, and is that list up to date? Over-broad admin access is one of the most common ways a single compromised account becomes a full breach. The DfE also expects administrative accounts not to be used for routine day-to-day work.
- Is multi-factor authentication switched on? The DfE requires it for all staff accounts with access to cloud services or remote access, and for IT administrative accounts. It is one of the single most effective controls available.
- What happens to a leaver's account on their last day? Dormant accounts are an open door. Offboarding is a safeguarding and data-protection matter, not only an HR one.
- Have we named a senior person responsible for digital technology and cyber risk? The DfE expects a senior leadership team digital lead to be accountable, with a clear line of escalation to governors.
Do we know what we are protecting?
- Do we hold an up-to-date record of the systems and devices that store personal or sensitive data? The DfE points schools towards an information asset register and a record of processing activities, a log of the personal data you hold and why.
- When did we last carry out a cyber risk assessment? The standard is annually, reviewed each term, and repeated after any significant technology or process change.
Are our people the gap?
- Are staff trained to recognise threats? Human error sits behind the large majority of breaches, and the DfE expects a cyber awareness plan with training at least annually. Worth asking whether that training is one annual module or something short and frequent, because the first is largely forgotten by half term.
- Have we ever tested whether staff would actually click? Training tells people what to look for. A phishing simulation tells you whether it worked. It sends safe, realistic test emails and reports who clicked, who entered their credentials and who reported it, with no blame attached. Most boards have never seen that figure for their own school, and it is usually the most revealing single number available.
What happens when something goes wrong?
- Do we have a written incident response plan, and does it sit within our business continuity plan? The DfE expects this, and in the state sector a cyber response plan is a condition of cover under the risk protection arrangement, which is a useful signal of what insurers now expect more generally. Worth checking what your own cyber cover actually requires. The hours after an attack are the worst possible time to improvise, especially where children's data is involved.
- Could we recover our data without paying a ransom? This comes down to backups. The DfE points schools to National Cyber Security Centre advice: three copies of your data, two of them on separate devices, and one held offsite.
- Are our backups independent of our main systems? Here is a question few boards think to ask. If email, files and the backups themselves all live inside a single Microsoft environment, one compromised administrator account could reach all of them at once. Relying on a single vendor to both hold and protect your data is itself a governance risk worth examining.
How do we know our assurance is real?
- When did we last have an independent review of our security, and who carried it out? Internal reassurance is not the same as independent scrutiny. Boards routinely commission external audit for finance; cyber risk deserves the same discipline. Asking the people who configured your systems to assess their own work puts them in an awkward position, however capable they are.
- Are we working towards a recognised benchmark? For colleges, Cyber Essentials is a requirement under their funding agreement, and many schools adopt it too. The DfE standards are themselves the closest governance benchmark, and being able to show steady progress against them is a reasonable expectation.
Turning questions into assurance
If your leadership team can answer these confidently, that is a strong signal of a healthy security posture. If some prompt an uncomfortable pause, that is precisely the value of asking. Far better to surface a gap in a governance meeting than in the aftermath of an incident.
One practical way to get independent answers is a security health check: a structured, external review of access, backups, response planning and staff awareness that gives the board a clear picture of where the school stands. It is worth being clear about what this is and is not. A health check is not a certification, and it does not by itself make a school compliant with any standard. It is one useful, independent input into your oversight, a way to replace assumption with evidence before you sign off your next risk report.
Should the school decide to act on what it finds, ARC's managed security starts at £5 per user per month with no hidden fees, and works alongside your existing IT team or provider rather than replacing them. ARC is a Microsoft Authorised Education Partner, a G-Cloud supplier and Cyber Essentials certified.
That is the spirit in which cyber risk belongs on the board agenda: not as a source of alarm, but as one more area where good governance means asking clear questions and expecting clear answers.
Book a Free Security Health Check for an independent view of where your school stands.
Sources