Full Report
Two-thirds report immediate recovery, although teachers remain divided over whose job security is
Analysis Summary
# Incident Report: Annual Summary of English Secondary School Cyber Trends (2025/26)
## Executive Summary
During the 2025/26 academic year, 27% of secondary schools in England reported cybersecurity incidents, reflecting a downward trend from previous years. While phishing remains the primary threat vector, the sector demonstrated significant resilience, with two-thirds of affected schools reporting immediate recovery. Despite improved technical recovery, a significant gap remains in staff training and the internal perception of security responsibility.
## Incident Details
- **Discovery Date:** July 2026 (Survey Period)
- **Incident Date:** Academic Year 2025/2024
- **Affected Organization:** Various Secondary Schools (England)
- **Sector:** Education
- **Geography:** England, UK
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing throughout the 2025/26 academic year.
- **Vector:** Predominantly Phishing.
- **Details:** Phishing was cited as the most common entry point, followed by hacking and general data protection breaches.
### Lateral Movement
- **Details:** Specific lateral movement techniques were not detailed in the report, though 2% of schools reported ransomware, which typically involves lateral movement to reach high-value targets.
### Data Exfiltration/Impact
- **Details:** Staff data was the most commonly compromised information. Student data was impacted in 13% of incidents, and student work was compromised in 1% of cases.
### Detection & Response
- **Discovery:** Primarily through internal school monitoring and reporting by staff.
- **Response Actions:** 66% of schools achieved "immediate" recovery. However, 1% of schools required a full term (approx. 12+ weeks) to return to normal operations.
## Attack Methodology
- **Initial Access:** Phishing (Primary), Hacking.
- **Persistence:** Not specified in aggregate data.
- **Privilege Escalation:** Not specified.
- **Defense Evasion:** Not specified.
- **Credential Access:** Likely harvested via phishing campaigns.
- **Discovery:** Not specified.
- **Lateral Movement:** Inferred in ransomware cases (2% of incidents).
- **Collection:** Targeting of staff and student PII (Personally Identifiable Information).
- **Exfiltration:** Not specified.
- **Impact:** Data breaches and ransomware; 7% of incidents resulted in "critical damage."
## Impact Assessment
- **Financial:** Not specified; however, indirect costs include parent work absenteeism during school closures.
- **Data Breach:** Compromise of staff data (high frequency) and student data (13%).
- **Operational:** Ranged from immediate recovery to closures lasting over a week; 7% of schools reported critical operational damage.
- **Reputational:** Increased scrutiny from Ofqual and the Information Commissioner’s Office (ICO).
## Indicators of Compromise
- **Network indicators:** N/A (Aggregate report).
- **File indicators:** N/A.
- **Behavioral indicators:** Increased reports of suspicious emails (phishing) and unauthorized access to staff databases.
## Response Actions
- **Containment measures:** Use of incident response plans (adopted by 20% of schools).
- **Eradication steps:** Not specified.
- **Recovery actions:** Utilization of backup procedures (cited by 22% of schools who made improvements).
## Lessons Learned
- **Siloed Responsibility:** There is a dangerous perception that security is solely an IT task (46%) rather than a leadership or shared responsibility.
- **Training Efficacy:** Approximately one-third of teachers received no training, and 65% of those who did reported making no changes to their behavior, indicating current training methods are largely ineffective.
- **Recovery Speed:** The increase in immediate recovery (from 55% to 66%) suggests that investments in backups and response planning are yielding results.
## Recommendations
- **Leadership Engagement:** Shift the primary responsibility for cybersecurity to senior leadership teams to ensure proper resource allocation.
- **Revamp Training:** Move away from passive training to interactive, role-specific security awareness programs to increase behavioral change.
- **Formalized Planning:** The 54% of teachers who "don't know" what improvements were made suggests a lack of transparency; schools should communicate incident response and backup policies more clearly to all staff.
- **DDoS and Ransomware Readiness:** Given the 2% ransomware rate and historical school closures, schools should conduct tabletop exercises involving both IT and administrative staff.