Back to School, Back to Basics: IT Security Checklist for Schools and Academies in Sussex

Schools and academies are an increasingly common target for cyberattacks, and the data from UK incidents makes uncomfortable reading. Ransomware has disrupted school operations across the country, with some schools losing months of work, student assessment data, and sensitive records. The NCSC has issued specific guidance for the education sector for good reason: schools represent an attractive target with, in many cases, inadequate security.

This checklist is designed for school business managers, IT coordinators, and senior leaders who want a practical assessment tool to work through ahead of a new academic year.

Why Schools Are Targeted

Schools hold significant quantities of sensitive personal data: student records, welfare and safeguarding information, medical data, and family details. This data is valuable to attackers both for direct exploitation and as leverage in extortion.

At the same time, many schools have limited IT resource. A large secondary school might have one IT coordinator managing hundreds of devices across a complex network. Budget constraints mean security investment is often deprioritised. And the academic calendar creates predictable periods of reduced IT oversight — holiday periods when attacks can go undetected.

The combination of valuable data, limited security resource, and predictable attack windows makes schools genuinely attractive targets.

The Checklist

User accounts and access control

Review all user accounts at the start of each year. Remove or disable accounts for staff and students who have left. Ensure admin accounts are limited to staff who genuinely require admin-level access. Default shared passwords — "school123," classroom logons shared by all students — are an access control failure, not a convenience.

Ensure MFA is enforced for all staff accounts accessing school systems, including Microsoft 365 or Google Workspace. Student accounts should have age-appropriate security requirements applied.

Patch management

All devices used for teaching and administration should be on a current, supported operating system and fully patched. Review the status of any classroom devices that haven't been connected to the network over the summer — they may have missed weeks of security updates.

Legacy software that can no longer receive security patches is a risk that needs to be actively managed. If devices can't run supported operating systems, they need to be replaced or isolated from the main network.

Backup and recovery

This is the most critical control against ransomware. Backups should be isolated from the main network (not just an attached network drive that ransomware can reach), recent (tested at least weekly), and verified recoverable (test the restore process, not just the backup).

Student assessment data, financial records, and HR information are the most critical datasets to protect. Know where they are and confirm they're included in backup processes.

Email security

Schools are targeted by phishing attacks as much as any commercial organisation. Email authentication (DMARC, DKIM, SPF) should be configured correctly. If using Microsoft 365, Safe Links and Safe Attachments should be enabled.

Review who has admin access to your email platform and ensure it's appropriately restricted. Consider whether parent and student communications platforms have appropriate security configurations.

Network security

Student network access should be segregated from staff and administrative network access. A student who compromises a school device shouldn't have a path to administrative systems or sensitive data stores.

Review firewall rules. DNS filtering should be in place — this is particularly important in a school environment where it also provides content filtering for safeguarding purposes.

Review remote access configurations. VPN access for staff working remotely should require MFA and be limited to approved, managed devices where possible.

Endpoint protection

All devices should have EDR-level endpoint protection, centrally managed and monitored. Devices that have been off the network over the summer should be updated and scanned before being returned to service.

Mobile device management (MDM) for school-issued mobile devices ensures that security policies can be enforced and devices can be wiped remotely if lost or stolen.

Data management and GDPR

Review what personal data the school holds and ensure it's documented. Ensure consent is in place for any data uses that require it. Safeguarding records, medical records, and any special category data require particular care.

Review third-party applications — educational software, communication platforms, online learning tools — and ensure data processing agreements are in place with each vendor.

Staff awareness

A brief security awareness session at the start of each year makes a meaningful difference. The minimum topics: what phishing looks like and how to report it, the correct process for reporting a lost device or suspected security incident, and the importance of not sharing credentials.

Teach staff to treat any request to do something unusual with data or money — regardless of who it appears to come from — with scepticism and to verify through a separate channel.

Incident response

Does your school have a documented process for responding to a cybersecurity incident? Who is contacted first? What systems would be isolated? When would you notify the DfE, the ICO, and parents?

If the answer is "we'd figure it out at the time," that's a gap. A one-page incident response process reduces the cost of a breach significantly.

ESFA and DfE Expectations

The Education and Skills Funding Agency and the Department for Education have both published guidance on cybersecurity for schools and academies. Academies and multi-academy trusts have financial management and governance obligations that include appropriate IT controls.

The NCSC's Cyber Essentials is supported as the baseline security standard for schools and is achievable with a structured programme of work. Some local authorities and multi-academy trusts have begun requiring it across their schools.

Getting Support

Many schools have limited IT resource and benefit from specialist support for security assessment and implementation. We work with schools and academies across Sussex and can provide practical, education-sector-specific guidance.

If you'd like to work through this checklist with support, or if you want an independent assessment of your school's current security posture, get in touch. We understand the constraints schools operate under and provide support that's practical and proportionate.

Previous
Previous

The UK Cyber Threat Report: What Sussex Businesses Need to Know This Year

Next
Next

Zero Trust Architecture: A Plain English Guide for SMEs