EdLaw nat/gb/dfe-digital-standards/CYBER-SECURITY.md

language: en · last checked: 2026-09-06

DfE cyber security standards (core standard)

Meeting digital and technology standards in schools and colleges (Department for Education) — the standard set below, reproduced in full (page version: Updated 25 August 2026). KCSIE directs governing bodies to these standards.

This standard is one of the 6 core standards. You should be working towards meeting it by 2030.

You can use the plan technology for your school service to help you meet this standard.

Cyber incidents and attacks have significant operational and financial impacts on schools and colleges. These incidents or attacks will often be an intentional and unauthorised attempt to access, change or damage data and digital technology. They could be made by a person, group, or organisation outside or inside the school or college and can lead to:

Our standards on filtering and monitoring will help schools and colleges to reduce risks related to a cyber incident by preventing access to potentially malicious sites or resources.

Throughout these standards we refer to:

Visit our standards page for more details on how to use the standards to help your school or college meet their digital technology needs.

The difference between these standards and Cyber Essentials

These standards are for all schools and colleges to help build their cyber resilience. They address the core principles of cyber governance, processes and strategy.

Cyber Essentials is a government-backed certification that happens on an annual basis. It provides a level of assurance to organisations across all sectors – not just the education sector – on the technical elements of their cyber security.

Cyber Essentials is a requirement for colleges under their funding agreement. Some schools may wish to complete it as part of their cyber security activities. These standards can help you work towards certification.

Conduct a cyber risk assessment annually and review every term

Why this standard is important

Those in schools and colleges need to know the risks associated with their hardware, software and data to properly mitigate and defend against any potential cyber incidents or attacks.

Assessing cyber risks means you can:

Not identifying and assessing risk, or preparing a response, could lead to:

Who needs to be involved

The senior leadership team (SLT) digital lead will be accountable for, and prioritise and coordinate activity relating to this standard. IT support (who may be an internal support person or external provider) will action this standard.

You can find out more about the role of the SLT digital lead in our standards on digital leadership and governance.

The SLT digital lead will work with:

If you do not have the technical expertise in-house, you will need to get advice from an external support provider or consider training for your internal IT staff to make sure they have the skills needed.

If your IT support is outsourced, then you will need to discuss with them how they are meeting the requirements of this standard. This should include how they will mitigate against any cyber incidents or attacks on their own network impacting on your school or college’s network. As part of this, you may wish to consider asking them whether they are certified with Cyber Essentials or Cyber Essentials Plus.

How to meet this standard

This standard should be a part of your overall digital technology strategy.

Read the digital leadership and governance standards for more information on how to create a digital technology strategy.

Review assets

The SLT digital lead and your IT support will:

Check data processing, access and permissions

The SLT digital lead will work with the DPO to:

Understand your network

The SLT digital lead will oversee this work, but IT support will:

Understand current risk

The SLT digital lead will be responsible for collecting the relevant information from all those listed in the ‘Who needs to be involved’ section of this standard. Together they will:

Create a risk management process and cyber response plan

The SLT digital lead will work with the business professionals or the finance team, estate management and IT support to:

We recommend getting insurance cover to help minimise costs in the event of a cyber incident or attack. You could consider the Department for Education’s (DfE) RPA cover as an alternative to commercial insurance.

To help action this standard, you can also refer to:

When to meet this standard

You should complete any risk assessments as soon as possible and repeat them every year or in the event of:

These risk assessments should then be revisited every term by those listed in the ‘who needs to be involved’ section of this standard to see if anything has significantly changed. This will help highlight vulnerabilities and what actions you need to take to minimise them.

If you have outsourced IT support and they are not currently meeting this standard, then you will need to review how this can be done in future as part of your ongoing service reviews, and no later than your next renewal date.

The following digital standards should also be considered when completing this standard.

Digital leadership and governance:

Cloud solution:

Servers and storage:

Create and implement a cyber awareness plan for students and staff

Why this standard is important

Well-informed users are the best line of defence against cyber criminals. Many cyber incidents and attacks target common processes and human behaviours when using digital technology.

Raising awareness, and training students and staff on cyber security will:

If students and staff do not understand the risks, this could lead to:

Having an acceptable use policy and training in place will help to provide the foundations for a good cyber awareness plan.

Who needs to be involved

The headteacher or principal will be accountable for making sure this standard is met. They will work with the senior leadership team (SLT) digital lead, who will coordinate the delivery of an acceptable use policy and training for their school or college.

The SLT digital lead will need to work with:

If you do not have the technical expertise in-house, you will need to get advice from an external support provider or consider training for your internal IT staff to make sure they have the skills needed.

How to meet this standard

The SLT digital lead will work with IT support to make sure:

You should also consider how to raise the level of cyber awareness within families if digital technology is taken home or student work is completed online at home.

Create an acceptable use policy

An acceptable use policy describes what a person on the network can or cannot do when using digital technology.

Anyone who has access to the school or college network or data will need to be made aware of, and sign up to, the acceptable use policy. This will include guests and supply teachers who want to use the school or college network and wifi.

The SLT digital lead will work with IT support, the designated safeguarding lead and the DPO to create and update the acceptable use policy.

If you use a student contract, then this should include relevant sections of the acceptable use policy to make it clear how digital technology should be used within your educational setting. This will need to be carried out at the beginning of every academic year.

You can find examples of acceptable use policies on the Education Data Hub website:

Train students and staff

Training students and staff in cyber security is a vital step in maintaining safety and security. Cyber training should be given at least annually, or more regularly if there is a known cyber risk to those who use school or college digital technology.

The SLT digital lead will need to coordinate training with IT support, the DPO and the designated safeguarding lead. This training is for:

Training should be age-appropriate and suited to your school or college’s risks, but should generally include training on:

If you have risk protection arrangement, you must evidence that the relevant users have undertaken the free National Cyber Security Centre (NCSC) training. This needs to be taken annually.

If you are looking for further support, the NCSC have downloadable copies of cyber security information cards for schools.

When to meet this standard

You should already have an acceptable use policy in place. If not, it should be updated towards the end of the academic year and shared with students, staff, and any cover or temporary staff at the beginning of the new academic year.

If you have not carried out cyber training in your school or college within the last 12 months, then you should plan to implement this as soon as possible.

The following digital standards should also be considered when completing this standard.

Digital leadership and governance:

Laptops, desktops and tablets:

Secure digital technology and data with anti-malware and a firewall

Creating and maintaining the security around your digital technology and data is a critical line of defence against a cyber incident or attack. Once a virus or hacker is in your system, they will look for a way to exploit other vulnerabilities.

All network-connected devices, including internet of things (IoT), need to be:

To complete this standard, the senior leadership team (SLT) digital lead and IT support will first need to read and action the standard on how devices should be safe and secure.

Why this standard is important

Following this standard will help to make sure that:

Not meeting this standard could lead to:

Who needs to be involved

The SLT digital lead will be accountable for this standard but IT support will be responsible for actioning it.

IT support will need to work with:

If you do not have the technical expertise in-house, you will need to get advice from an external support provider or consider training for your internal IT staff to make sure they have the skills needed.

How to meet this standard

The SLT digital lead will need to plan how the technical requirements section within this standard will be met with IT support.

IT support will need to:

If you are unsure about any data or applications, contact your IT support and they will be able to check the security of them.

Technical requirements

This section is for your IT support who may be an internal support team or an external provider. They will set up your network and digital technology to meet these minimum requirements.

Firewall

Many schools and colleges will be provided with a firewall as part of their broadband connection. If this applies to you, then you will need to discuss these technical requirements with your broadband provider.

If your broadband provider does not include a firewall, then IT support will need to source one and set it up securely.

To meet this standard, IT support must:

Anti-malware software

Anti-malware software needs to be kept up to date with the latest updates. This should be reviewed termly to check that it is meeting your school or college’s needs. This software must:

The NCSC provide further guidance on how to select, configure and use anti-virus and other security software.

To help prevent malware infecting digital technology from an external device, IT support should prohibit the use of USB storage devices by default, unless for a specific need – for example, if the examination board require this.

If USB storage devices are permitted in specific use cases, the anti-malware software should scan the USB drive before it is made available to the student or staff member.

Security checks

IT support should:

The NCSC has a tool that can assist you with email security configuration and reporting.

When to meet the standard

This standard should already be in place for the security of your network.

Completing the standard in this topic titled ‘Conduct a cyber risk assessment annually and revisit every term to review if anything has changed’ will help to inform this process.

The following digital standards should also be considered when completing this standard.

Servers and storage:

Cloud solution:

Wireless network:

Network switching:

Digital leadership and governance:

Laptops, desktops and tablets:

Broadband:

Control and secure user accounts and access privileges

Why this standard is important

Protecting user accounts and related data is a critical line of defence against cyber incidents and attacks.

Following this standard will make sure that:

Not meeting this standard could lead to:

Who needs to be involved

The senior leadership team (SLT) digital lead will be accountable for this standard but IT support will be responsible for actioning it.

IT support will work with:

If you do not have the technical expertise in-house, you will need to get advice from an external support provider or consider training for your internal IT staff to make sure they have the skills needed.

How to meet this standard

The SLT digital lead will need to plan how the technical requirements section within this standard will be met with IT support and how they will:

IT support should make sure that users only have the network and data access they need, and that their account is secure.

To help action this standard, you can also also refer to:

Technical requirements

This section is for your IT support who may be an internal support team or an external provider. They will set up users so that they only have the access they need by following these minimum requirements.

If you have external IT support that will carry out the activities within this standard, make sure that your contract with them is compliant with General Data Protection Regulation (GDPR).

Passwords

Users must be authenticated with unique credentials before they access:

This can include using passwords.

Passwords must be:

If staff access a number of systems, you should consider using a single sign-on solution that allows you to sign on once and access all applications.

IT support will need to:

On networking devices and servers, IT support should:

For younger children, users with special educational needs or disabilities, or for those with English as an additional language, consider using:

Visit the NCSC website to learn more about setting up password policies.

Multi-factor authentication (MFA)

MFA secures your account by asking the user to provide 2 or more pieces of evidence to verify their identity. This could include a password and a login through another device.

MFA must be enabled for all:

Passkeys may provide an alternative solution, if staff use a dedicated device.

You may need to consider alternatives or extra support for anyone with accessibility needs or disabilities.

MFA should include at least 2 of the following:

Where MFA is not available, a more complex password should be used, following the recommended guidance around password security in this standard.

The DfE cyber security hub has guidance about using MFA.

Account management

IT support need to control user accounts and access privileges by:

IT support should consider using tools that link to the management information system (MIS) to automatically create or delete user accounts which will make this process easier to manage.

IT support will also:

The NCSC has detailed guidance on privileged access management.

When to meet this standard

You should already be meeting this standard. This will make sure that your data and digital technology is best protected against cyber threats.

If you are not already meeting this standard, then you should implement this as soon as possible through a structured, well managed rollout plan.

The following digital standards should also be considered when completing this standard.

Cloud solutions:

Servers and storage:

Laptops, desktops and tablets:

Network switching:

Wireless network:

Broadband:

License digital technology and keep it up to date

Why this standard is important

All digital technology must be licensed. Digital technology includes software programmes, operating systems and applications running on devices and servers, or online cloud services.

These must be licensed so you can:

Not licensing or updating digital technology could lead to:

Who needs to be involved

The senior leadership team (SLT) digital lead will be accountable for this standard, with IT support responsible for actioning it.

The governing body or board of trustees should check that the digital technology is fully licensed as part of their normal compliance review.

Your internal or external IT support will work with:

If you do not have the technical expertise in-house, you will need to get advice from an external support provider or consider training for your internal IT staff to make sure they have the skills needed.

How to meet this standard

The SLT digital lead will plan how the technical requirements section within this standard will be met with IT support.

IT support will need to check all digital technology is licensed, supported and set up to meet the technical requirements in the next section. The end of support dates for each device’s operating system should be recorded in the asset register and your mobile device management system, if you have one.

At the end of every term, IT support and the business professionals or the finance team should review the contracts register and inform the SLT when digital technology:

You can find out more about the contract and asset registers by visiting our standards on digital leadership and governance.

An alternative to licensing software is to use a cloud service. These are usually subscription based, and the responsibility is on the supplier to license and update the software. You should ask your DPO to undertake a DPIA if you choose to do this where it is storing or processing personal or sensitive personal data. Visit the Department for Education (DfE) website for more information on data protection policies and procedures.

If you are using open-source software or operating systems, you must abide by their licensing terms.

Occasionally, DfE may issue instructions on security updates. The SLT digital lead will need to inform IT support. IT support should then apply these updates within 5 working days of notification.

Technical requirements

This section is for your IT support who may be an internal support team or an external provider. They will set up your digital technology to meet these requirements.

Licensing

All software needs to be licensed and eligible for security updates. You should remove unlicensed software or take steps to license it.

IT support will need to check that:

Security updates

IT support must complete vulnerability fixes for operating systems, applications and firmware within 14 days of the fix being released.

Vulnerability fixes include:

Apply the 14-day requirement when:

The CVSSv3 is the security industry standard for measuring the danger of a vulnerability. The score is a number from 1 to 10 where 10 means it is the most easily exploitable. There is a more detailed explanation of CVSSv3 on the National Vulnerability Database website.

IT support will also need to:

The NCSC has further guidance on the problems with patching.

When to meet this standard

You should already be meeting this standard with existing digital technology within the school or college. When buying new digital technology (including cloud-based services), you will need to check that it meets this standard.

The following digital standards should also be considered when completing this standard.

Digital leadership and governance:

Laptops, desktops and tablets:

Cloud solution:

Servers and storage:

Broadband:

Network switching:

Wireless network:

Develop and implement a plan to back up your data and review this every year

A backup is an additional copy of data, held in a different physical location (which could include being on the cloud), in case the original data is lost or damaged. If all copies were held in the same physical location, they would all be at risk from natural disasters, criminal damage or a malware attack.

The physical location for your backup will need careful consideration to make sure that, in the event of a disaster situation, it is not impacted by the same incident or attack.

Follow the National Cyber Security Centre (NCSC) advice on backing up 3 copies of your data, 2 of which are on separate devices and one of which is offsite which could include a cloud backup service. Members of the risk protection arrangement (RPA) should refer to their terms for making a claim, as backing up to this level is currently a condition of cover.

The Education Data Hub has further guidance on backing up your data.

Why this standard is important

Schools and colleges are now more reliant on digital technology and data being stored in different locations (such as cloud services). Not all of these will be backed up to meet the needs of the school or college (for example, cloud services will only backup your data for a limited time period), so you need to have a backup plan to meet your diverse needs.

This standard will help your school or college to:

Not meeting this standard could lead to:

Who needs to be involved

The senior leadership team (SLT) digital lead will own the backup plan and work with IT support to make sure backups are being done correctly.

IT support will action the backup plan and will communicate this with any IT leads in your broader organisation (if applicable), such as a multi-academy trust or a local authority school, to find out if anything needs to be actioned or approved by them.

The SLT need to prioritise which data areas would need to be recovered first in the event of a cyber incident or attack.

The SLT digital lead and IT support will identify risks and priorities by speaking to:

If you do not have the technical expertise in-house, you will need to get advice from an external support provider or consider training for your internal IT staff to make sure they have the skills needed.

How to meet this standard

Your backup plan should feed into your business continuity plan and disaster recovery plan. The backup plan should be:

Read our standards on digital leadership and governance for more details on business continuity plans.

Analyse where you are now

It is useful to understand what your current backup plan looks like so that you can assess if it needs improvement.

The SLT digital lead should ask IT support:

If you do not have internal IT support, ask your service provider to explain what they are doing to help you achieve this standard.

Plan and action how to backup and restore data in the future

The SLT digital lead will work with your business professionals or the finance team, designated safeguarding lead, data protection officer and IT support to identify:

IT support should:

You should not take any physical backups offsite unless they are encrypted and stored in a secure location. Regardless of whether they are encrypted, backups should never be taken to anyone’s home.

When to meet this standard

You must backup your data now. If you have not yet done so, you should develop a backup plan as soon as possible to allow you to respond quicker in a disaster situation.

The following digital standards should also be considered when completing this standard.

Digital leadership and governance:

Cloud solution:

Servers and storage:

Report cyber attacks

Why this standard is important

A cyber incident or attack will often be an intentional and unauthorised attempt to access, change or damage data and digital technology. They could be made by a person, group, or organisation outside or inside the school or college.

Everyone is responsible for and should report a cyber incident or attack to their IT support and senior leadership (SLT) digital lead.

Following this standard means that:

Failure to report and act quickly could lead to:

Who needs to be involved

Cyber incidents or attacks can be reported by anyone to their IT support and SLT digital lead who will work closely with the data protection officer (DPO) to identify any data protection issues.

Any formal reporting to external bodies (such as Report Fraud) will need to be done by someone appointed by the SLT digital lead and involve the:

If you do not have the technical expertise in-house, you will need to get advice from an external support provider or consider training for your internal IT staff to make sure they have the skills needed.

How to meet this standard

All students and staff have a responsibility to report cyber risk or a potential incident or attack to IT support and the SLT digital lead.

The SLT digital lead will need to make sure that all students and staff understand how to report a potential incident or attack and that they feel safe and comfortable to do so.

To help action this standard, you can also refer to:

Report a cyber incident or attack internally

As soon as IT support and the SLT digital lead have been alerted by a student or member of staff to a potential incident or attack they will need to:

Any incidents, attacks or near misses should be recorded in an internal incident report or system.

Report a cyber incident or attack to external bodies

Incidents or attacks where any security breaches may have taken place, or other damage was caused, should be reported to an external body.

The SLT digital lead will be responsible for assigning someone to report any suspicious cyber incidents or attacks. This person will need to report this to:

You may also need to report it to:

You must act in accordance with:

Police investigations may find out if any compromised data has been published or sold and identify the perpetrator.

When to meet this standard

You should already be meeting this standard. If you do not have these procedures in place, then you should implement them as soon as possible.

The following digital standards should also be considered when completing this standard.

Digital leadership and governance:

Cloud solution:

Servers and storage:

Meta

Guidance text is reproduced verbatim from the gov.uk guidance page by tools/gov-uk/build_dfe_standards.py; the page's "Updated" date is pinned, so verify fails as soon as the DfE revises the standard.