Responding to increasing cyber-attacks in the education sector
Introduction
Cyber-attacks in the education sector on UK schools, colleges, and universities are on the rise – and with them, serious risks to data protection. The government’s recent 2025 Cyber Security Breaches Survey revealed that 44% of primary schools, 60% of secondary schools and 85% of further education colleges experienced a cyber breach or attack in the past year. So far this year, the BBC has reported disruptive ransomware attacks on multiple schools in Shropshire and West Lothian.
As learning continues to move online and schools rely on digital systems for everything from teaching to administration, hackers have found new ways to exploit weaknesses. These incidents threaten not only digital systems and continuity of education, but also the sensitive personal data of students and staff.
The challenge for the Veritau schools DPO team
Understanding how to prevent and respond to cyber-attacks in the education sector is now a major priority for schools and multi-academy trusts. As the data protection officer (DPO) for over 700 educational institutions, the team at Veritau has seen first-hand the implications of the increased targeting of schools by cyber criminals.
We also understand that schools face unique challenges which can make them particularly susceptible. Key challenges include:
- Lack of training and awareness can make staff and students vulnerable to ‘social engineering’ tactics in phishing scams and accidental mistakes, such as using weak passwords or clicking malicious links.
- Tight budgets can result in lower investment in cyber-security technology, software, and other measures. Many schools use outdated software and hardware that have known vulnerabilities, making them easier targets.
- The expansion of online learning platforms and cloud services has increased the number of potential vulnerabilities that attackers can exploit.
- Widespread use of various internet-connected devices (like tablets and smartboards) creates a large attack surface. These endpoints are often not secured properly providing easy entry points for attackers.
- Insider threats – unintentional or malicious actions by staff or pupils are significant causes of security incidents. The ICO recently published an article about the increasing number of cyber-attacks caused by students.
- Holding high volumes of personal data, including sensitive data relating to special educational needs and disabilities (SEND) and safeguarding matters.
Helping schools avoid and respond to cyber incidents
With these issues in mind, the team has developed a suite of resources to support our clients to operate safely. This has included:
- Publishing cyber security guidance, along with a model Information Security Policy which sets out how your organisation will protect information from cyber threats
- Issuing reminders and information about cyber security via our monthly bulletin
- Circulating timely alerts about phishing and other cyber-attacks we become aware of
- Providing data breach management materials, including an investigation form, risk matrix and associated guidance
- Recording bite-sized videos providing key information within 3 minutes – including password security, phishing and responding to a data breach.
- Providing an e-learning module about information security on our Veritau Learn platform, so you can upskill and raise awareness amongst staff. We also recommend that all staff complete the National Cyber Security Centre’s cyber security training for school staff annually.
- Publishing posters on cyber security, passwords and phishing – we recommend placing these posters in staff rooms as visual reminders.
The materials above are available to all our school and multi-academy trust DPO clients on our client portal. We also regularly provide advice about cyber security and data breaches via our dedicated schools helpline. For more information about the service visit our Schools data protection officer (DPO) and Data protection support for MATs pages
Supplier due diligence
A key area of risk that has emerged is the increasing reliance on cloud services, online learning platforms and other apps and EdTech. In data protection terms these are usually operating as ‘data processors’ when they hold and process data on behalf of the school.
In recent years, the Veritau team has received several reports of supplier data breaches affecting school data. We have responded by encouraging our client schools and trusts to complete robust due diligence, including providing the following materials as part of the DPO service:
- A contract checks form and related register of contract assurance ratings for popular school platforms and apps. These checks confirm the existence of clauses obliging the supplier to implement technical and organisational security measures and ensure an appropriate flow-down of data protection responsibilities.
- Template data protection impact assessments (DPIAs) for commonly used platforms and apps which identify and mitigate any data security risks associated with the supplier.
- A ‘privacy by design’ checklist which can be used when a DPIA is not mandatory to ensure security (including cyber) risks have been properly considered as part of the project.
We recommend our clients start these assessments as part of the procurement process, to ensure the supplier you choose is suitable and safe. We support the process by reviewing documentation and providing advice via our helpline or a Teams call.
Staying safe in a digital world
Cyber-security is now an essential part of keeping school data safe and the Veritau DPO service has developed to help deliver this. To remain protected against cyber-attacks in the education sector, schools need to take simple but important steps like keeping software updated, teaching everyone how to spot suspicious emails, and having support and processes to follow if something goes wrong.
As a service, we will continue to monitor evolving risks, trends and best practice so we can provide meaningful and actionable advice to our clients.
Cyber-security is a team effort that involves teachers, students, parents, and school leaders working together with your DPO. By building good habits and awareness, schools can create a secure digital environment where students can learn with confidence.
Speak to our education data protection experts
Rosie Kelly
Assistant Director - Information Governance
Rosie is an experienced DPO with a background in the legal sector. She is a Fellow of the IAPP and holds the CIPP/E and CIPM certifications. Rosie specialises in UK GDPR compliance in the education sector, including expertise in Edtech and data protection governance in multi-academy trusts. Rosie leads on AI, risk assessments, contract assurances, international data transfers and promoting awareness of legal changes.
Responding to increasing cyber-attacks in the education sector
Amy Stroud
Assistant Director - Internal Audit
Amy has over nine years’ internal audit experience and holds the Certified Internal Auditor (CIA) qualification. Amy oversees the work our internal audit team provides to the children’s trusts and over 30 multi-academy trust clients across Yorkshire, the Humber and the North East.
Becky Dixon
Senior Information Governance Officer
Becky holds qualifications in FOI, data protection, information security, and records management. She supports our school DPO clients with data protection compliance and leads our training offer, including the annual webinar and eLearning packages. Becky also oversees client communications and alerts, keeping schools and trusts updated on regulatory changes, best practice, and emerging risks.