Most trust boards would say they take cyber security seriously. They will probably have policies in place, staff will have completed phishing training, and somebody will be responsible for software updates and backups.
But could the trust continue operating safely after a serious cyber incident? That is a harder question to answer.
The Government's Cyber Security Breaches Survey 2025/2026 found that 73% of secondary schools had identified a cyber security breach or attack in the previous 12 months, up from 60% the year before.
When nearly three-quarters of secondary schools have identified a breach or attack, cyber security can no longer be treated as something unlikely that happens elsewhere.
Yet the conversations boards have about cyber security are often focused on the controls in place. Have updates been completed? Do we have antivirus protection? Have staff received training?
These are sensible questions, but they only tell part of the story. Trustees also need to know what would happen if a control failed or somebody clicked on the wrong link.
Would staff still be able to access safeguarding information? Could attendance be recorded? How would the trust contact parents? Would payroll still run?
That is where cyber security moves beyond IT and becomes a question of whether the trust can keep its schools running.
What would disruption actually look like?
Schools rely on technology for almost everything they do. Teaching, attendance, safeguarding, examinations, payroll, finance and communication with parents all depend on systems being available.
If staff arrived on a Monday morning and found they could not access the Management Information System (MIS), the school could not simply wait for somebody to fix it. Pupils would continue arriving, attendance would still need to be recorded and safeguarding concerns would still need to be managed.
The same applies to other systems. A payroll platform being unavailable may not immediately affect what happens in the classroom, but it becomes a serious organisational problem if staff cannot be paid. Losing access to email can make a response plan much harder to follow if all the contact details and instructions are stored in an inbox.
These are practical issues rather than technical ones, and trustees do not need a detailed understanding of firewalls to ask about them. They need to know which systems the trust depends on, what would happen if they became unavailable and whether there is a realistic alternative in place.
The latest government figures suggest that there are still some important gaps. One in five secondary schools does not have a business continuity plan covering cyber security, while only 57% are aware of Cyber Essentials.
The answer is not necessarily to spend more money on technology. Sometimes the most valuable improvements are much simpler: making sure responsibilities are clear, checking that backups can actually be restored and giving people the chance to practise what they would do.
The questions worth asking
No trust can remove every cyber risk, and boards should be cautious of anyone who suggests otherwise. The aim is to reduce the likelihood of an incident and limit the disruption if one occurs.
That means asking questions that go beyond whether a policy exists:
- Which systems would cause the greatest disruption if we lost access to them?
- When did we last restore data from our backups successfully?
- Has our incident response plan been tested with the people expected to use it?
- If email and the MIS were unavailable, how would our schools record attendance, manage safeguarding concerns and contact parents?
- Do we know who would make key decisions and who would communicate with staff, families, insurers and regulators?
- Which suppliers do we rely on, and what would happen if one of them experienced an incident?
- What weaknesses do we already know about, and what is being done to address them?
The answers do not need to be highly technical. What matters is whether they are clear and supported by evidence.
Confirmation that backups run on a real-time mirror system with 30 days of retention is great, but can the trust or school actually restore lost information quickly enough? A response plan may be detailed and regularly reviewed, but if nobody has worked through it, the first real test will come during an incident.
Plans can also contain assumptions that nobody notices until they are put under pressure. Contact details may be out of date. Staff may assume an external IT provider will take the lead while the provider expects the trust to do so. Instructions may be stored on the same network that has become unavailable.
A short practical exercise will usually bring these issues to the surface. It gives people an opportunity to work through what they would actually do, rather than what the policy says should happen.
Where boards can be left exposed
Most trusts are not starting from nothing. They already have security software, policies, backups and some form of staff training.
The gaps tend to sit between those individual measures. Responsibilities exist but are not clearly understood. Plans have been written but never tested. Business continuity arrangements were created several years ago and no longer reflect the systems schools use today. Boards receive reports describing what has been done, with less information about whether it has worked.
That is the assurance gap boards need to be aware of. Receiving confirmation that individual controls are in place is useful, but trustees also need to know whether those measures would work together during a real incident.
None of this means a trust is failing to take cyber security seriously. It does mean trustees may have less assurance than they think.
This is where internal scrutiny can be useful. Someone outside the day-to-day operation of the trust can look at how the different arrangements fit together, test the assumptions behind them and identify questions that may not have been asked internally. For practical next steps, our guide to preparing for cyber security looks at how schools and trusts can assess their risks, strengthen their controls and prepare for disruption.
Is your school or trust prepared?
If a serious cyber incident happened tomorrow, could your organisation continue operating safely?
There may not be a straightforward yes or no answer. Boards should, however, have a clear understanding of the risks, evidence that recovery arrangements have been tested and confidence that people know what they would need to do.
If you are not confident in the answer, an independent review can identify the gaps before a real incident exposes them. Speak to Keystone about reviewing your cyber governance and business continuity arrangements.