New report reveals the main cybersecurity risks for schools, what schools are doing well and areas to improve on.
Secure Schools has published a new report, The State of School Cybersecurity 2025, which contains data from 600 schools and multi-academy trusts (MATs) on cybersecurity – outlining key insights, risks and actions. Secure Schools describe this year’s research focus as ‘fundamental cybersecurity best practices, policies, and tools schools should use to match national government standards and put themselves in the strongest position to deter, mitigate, and limit the risks of a cybersecurity breach.’ 1
What key risks were identified?
In the report, Secure Schools highlighted five key areas of cybersecurity risks schools were facing (based on the data it had collected): account compromise; ransomware and data lockouts; unpatched systems and supply chain risk; policy rollout and compliance; and phishing attacks.
- Only 46% of schools reported the use of multi-factor authentication (MFA) on all applicable IT team accounts.
- Just 46% of schools shared that they have sufficient backups to operate during unplanned outages and only 25% reported identifying suitable backup methods.
- Less than 75% of schools stated that they conduct regular vulnerability scans and only 27% said they conduct DPIA checks on vendors.
- Only 50% of schools reported that they have active password policies.
- Less than 20% of schools have a dedicated person who is responsible for the school’s cybersecurity.
- Email remains the primary route for cyber-attacks, yet, many schools have not conducted staff training on phishing and other email related threats. 1
What are schools doing well?
Within the report, Secure Schools reported there were three notable areas where schools demonstrated strengths:
- Email security fundamentals – a significant number of schools implemented foundational email security measures, such as Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting, and Conformance (DMARC).
- Password policy – despite this being an area for improvement, half of schools do have established policies covering password usage with details stating how users should use their passwords.
- Account security – whilst this was a risk for many schools, 47% of schools reported that their IT teams use MFA on all accounts where it’s available, and 46% of schools stated their IT team has separate administrator accounts for maintenance and admin activities. 1
What other notable insights were found?
The report has a section dedicated to incident response planning. In this section, it was reported that, ‘less than 15% of schools stated that they have contact details for the relevant department accessible during system unavailability’. However, ‘15% of schools have a business continuity plan, more than other public sector industries have stated in other studies’. 1
For more insights and suggested actions to mitigate cybersecurity risks, read the full report.
References
- Secure Schools (2025) ‘The State of School Cyber Security 2025’. Available at: https://www.secureschools.com/hubfs/The%20State%20of%20School%20Cybersecurity%20report/UK/The%20State%20of%20School%20Cybersecurity.pdf (Accessed: 15 September 2025)


