Schools and colleges in England reported fewer cyber incidents during the 2025–26 academic year, while those affected said they were better able to restore systems quickly. The new findings show progress in resilience, but they also expose a basic weakness: staff do not share a clear view of who owns cyber security.
Fewer incidents, faster recovery
The third annual survey found that 27% of schools had experienced a cyber incident in 2025–26. That compares with 29% in the previous academic year and 34% in 2023–24. The figures are reported experience, rather than a complete count of attacks, but they offer a useful indication of how frequently secondary schools are encountering disruption.
Recovery appears to have improved more sharply. Among schools that had an incident, 66% said they could recover immediately, up from 55% a year earlier. The proportion reporting critical damage from an attack was 7%. It suggests that the ability to restore services promptly may be improving even when an incident cannot be prevented. Lost access to a network, email or school systems can interrupt teaching and administration even where there is no lasting loss of data.
Students can still feel the effects
A quicker technical response does not remove the educational consequences of a breach. Coursework, marks and other records can create uncertainty when systems are unavailable or data is affected. Staff may also be left managing lessons, communications and safeguarding processes with reduced access to routine tools. The survey therefore points to resilience as more than an IT issue: it is part of keeping a school functioning during disruption.
The results should not be read as evidence that every school is equally protected, or that the decline in reported incidents has a single cause. The poll was conducted on 13 July and drew on 3,775 secondary teachers in England. For questions answered at school level, one senior teacher responded for each establishment, producing a sample of up to 2,162 schools. It is a substantial snapshot, but it measures respondents’ reported experience and preparedness.
Responsibility remains split
For the first time, teachers were asked who was primarily responsible for cyber security at their school. Forty-six per cent named the IT team, 40% said responsibility lay with all staff and only 9% selected senior leadership. That division matters because attacks often begin with everyday decisions: recognising a suspicious message, securing access, reporting an error and following a prepared procedure.
Specialist staff remain central to maintaining systems and responding to incidents. Yet the figures suggest that technical ownership alone cannot provide a complete answer. Leaders decide how risks are governed, whether resources are available and whether recovery arrangements are tested. A policy that depends on staff improvising when a system fails is unlikely to give pupils or parents much certainty. Teachers and support staff also need to know what to do when normal systems fail.
Preparation is the practical test
Fifty-five per cent of the secondary schools surveyed had already taken protective action, including cyber-security policies, risk assessments and backup and recovery procedures. Those measures are most useful when they are current, understood beyond the IT team and rehearsed before an incident occurs.
The next step for schools is not simply to buy more technology. It is to assign clear leadership, maintain reliable backups, agree a response plan and make sure staff know how to use it. The latest results show that recovery can improve. They also show why schools cannot treat cyber security as someone else’s problem.