Tes Schools Improve Cybersecurity Recovery Times, But Leadership Responsibility Lacks Consensus
Article Content
- •27% of schools reported cyber incidents in 2025-26, down from 29% the previous year.
- •66% of schools can now recover from cyber incidents immediately, an increase from 55%.
- •Only 9% of teachers believe senior leadership is responsible for cybersecurity.
According to Ofqual's third annual cybersecurity survey, schools in England are experiencing fewer cyber incidents, with 27% reporting attacks in the 2025-26 academic year, down from 29% the previous year. Recovery times have improved, with 66% of schools able to recover immediately from incidents, compared to 55% the year before. However, there is a significant lack of consensus among teachers regarding who is primarily responsible for cybersecurity, with 46% citing IT teams, 40% all staff, and only 9% senior leadership. Ofqual emphasizes that cybersecurity is a leadership responsibility and encourages schools to adopt robust measures, including regular backups and clear response plans. Despite the improvements, incidents still cause uncertainty for students and staff, particularly when coursework or marks are lost. Over half of secondary schools surveyed have taken protective actions, such as implementing cybersecurity policies and conducting risk assessments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Department For Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What percentage of schools experienced cyber incidents?
How quickly can schools recover from cyber incidents?
Who is primarily responsible for cybersecurity in schools?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…