Westminster Policy News & Legislative Analysis

Ofqual Urges Stronger School Cyber Plans as Recovery Improves

Ofqual says schools and colleges in England are becoming more resilient when cyber incidents occur, with recovery times improving across the 2025 to 2026 academic year. The regulator used Cyber Security Awareness Month to argue that the next stage is not simply better IT handling, but stronger institutional planning so staff know what to do when systems fail. The message is practical rather than alarmist. Ofqual’s position is that progress is evident, but uneven. Faster recovery reduces disruption, yet the survey suggests too many institutions still treat cyber risk as something that sits mainly with technical teams rather than with senior decision-makers.

The survey data points to a modest but clear fall in reported incidents. Ofqual said 27% of schools experienced a cyber incident in 2025 to 2026, down from 29% in 2024 to 2025 and 34% in 2023 to 2024. Where incidents did happen, schools reported a stronger ability to restore services quickly. Two thirds, or 66%, said they were able to recover immediately, up from 55% in the previous academic year. The proportion reporting critical damage also fell to 7%, suggesting that containment and recovery arrangements are improving even where attacks still get through.

For the qualifications system, the policy concern is not confined to temporary IT disruption. Ofqual’s Amanda Swann said a breach can create uncertainty for students where coursework or marks are affected, and that staff confidence may remain shaken after systems are restored. That matters because school cyber incidents can move quickly from an operational issue to an assessment and continuity issue. Lost access to email, networks or records can interrupt teaching, evidence gathering and internal processes that support awarding and moderation. In that sense, resilience is not only about restoring devices; it is about protecting confidence in the school’s administrative record.

The survey also exposed a governance gap. Asked for the first time who is primarily responsible for cyber security, 46% of responding teachers pointed to the IT team, 40% said all staff, and only 9% identified senior leadership. That split helps explain Ofqual’s emphasis on accountability. Swann’s argument is that cyber security cannot be left to specialist staff alone. In policy terms, the issue is one of organisational ownership: heads, senior leaders and governors are expected to set risk tolerance, approve response arrangements and ensure that backup and recovery procedures are maintained rather than assumed.

Ofqual said more than half of surveyed secondary schools, 55%, have already taken steps to strengthen protection against cyber attacks. Those steps include putting a cyber security policy in place, carrying out risk assessments and establishing backup and recovery procedures. The remaining position is more mixed. Some teachers described effective in-house monitoring and staff training that helped spot attacks early and reduce harm. Others reported far more disruptive incidents, including complete loss of network and email access. One account cited an incident serious enough for police to close the school, underlining how quickly a technical event can become a safeguarding and continuity issue.

The regulator’s advice is deliberately straightforward. Senior leaders are being asked to review current arrangements with their IT lead, use the Department for Education’s cyber response plan template, and make sure the school can recover quickly if systems are compromised. That framing gives schools a clear compliance-style checklist without presenting it as a new regulatory burden. For leadership teams, the immediate task is to confirm who owns response decisions, whether backups are current and tested, and how the school would keep core activity running if email, networks or management systems became unavailable.

The findings are drawn from polling carried out by Teacher Tapp on behalf of Ofqual on 13 July 2026. Percentages relating to teachers are based on responses from 3,775 secondary teachers in England, while school-level findings were limited to one response per school from the most senior teacher, representing up to 2,162 schools. That methodology means the results should be read as a useful system snapshot rather than a full audit of every institution. Even so, the direction of travel is consistent. Recovery is improving, damage appears to be falling, and the main policy question has shifted towards whether school leadership is treating cyber preparedness as a standing management responsibility rather than an occasional IT concern.