Leadership1 publisher3 min readPublished
Ofqual survey finds 9% of teachers in England see cyber security as a leadership job
Ofqual found that 9% of teachers in England see senior leadership as primarily responsible for cyber security, while 46% name the IT team. The regulator says backups and response plans belong to leaders, a duty most staff assign elsewhere.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Ofqual's data shows 27% of schools had a cyber incident in the 2025 to 2026 academic year, down from 29% a year earlier and 34% in 2023 to 2024.
- Among schools that were hit, 66% recovered immediately, up from 55% in the previous year.
- Earlier this year an attack on Northern Ireland's C2K system left staff and pupils at more than 30 schools unable to reach coursework and teaching services.
- The Information Commissioner's Office says pupils themselves are often behind school cyber incidents, with motives that include boredom and financial gain.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision Heads now have to choose whether backups and the response plan sit with a named senior leader or stay with the IT teams that most teachers already treat as the owners.
- exposure Lost coursework or marks harm students and staff confidence long after systems return, and a school's leadership answers for that harm whoever runs the servers.
- constraint On tight school budgets, a leader who takes ownership also takes on the fight to fund backups and replace legacy systems that attackers still probe.
Teachers were asked who is primarily responsible for cyber security. The IT team, all staff and senior leadership took 95% of the answers between them [1], and the 40% who said all staff [5] gave a defensible reply. Ofqual itself wants measures in place so that staff know what to do when systems come under attack, and it points schools to the Department for Education's Cyber Security Hub [14].
Amanda Swann, Ofqual's executive director of delivery, was plain about where she thinks ownership belongs. "Cybersecurity isn't just an IT problem; it's a leadership responsibility. Regular backups and a clear response plan can make a huge difference when things go wrong," she said [6]. An IT team can specify a backup regime. ITPro notes that low budgets mean school cyber security is often underfunded [8]. The National Cyber Security Centre already publishes advice written for governing boards and senior leaders [15].
A skeptical head would say the current arrangement is working. Immediate recovery rose 11 points in a year [2], and critical damage from attacks fell to 7% [3]. The survey, as reported, does not tie those gains to who owns the work. And 34% of schools that were hit still could not recover straight away [3]. Swann's other warning is about those schools. "It's encouraging to see schools recovering faster, but a cyber breach can still cause real uncertainty for students if coursework or marks are lost, and staff confidence can be affected long after systems are back online," she said [4].
Much of the exposure is old. SonicWall found that the Apache Log4j2 remote code execution flaw was the leading signature targeting UK primary and secondary schools last year, at around 660,000 hits [9]. The same data showed 71,000 attempts against TFTP server directory traversal signatures, aimed at network boot systems common in school IT [10]. Patching those flaws falls to IT teams, but retiring the systems that carry them is a spending decision. Last year a ransomware attack on West Lothian council's education network lost data from a dozen schools [12].
The ICO's finding that pupils are often the culprits [13] matters for ownership. I think it moves part of the problem into the head's office, since pupil conduct is already a leadership matter.
Some of the groundwork Swann describes exists. Of the secondary schools surveyed, 55% have taken protective action, including cyber security policies, risk assessments and backup and recovery procedures [7]. That figure covers secondary schools only, while the incident and recovery rates describe schools and colleges more broadly [1]. I'd expect each of those documents to need a head's or a governing board's sign-off before it means much.
The incident rate has fallen 7 points in two years [4], and that pace leaves room for ordinary planning. The decision a head makes now is whose name sits on the response plan and the backup budget. That decision fixes who answers next year when a school loses marks or coursework, and Swann has already called it a leadership responsibility [6].
What to watch
- Whether Ofqual's next survey shows the share of teachers naming senior leadership rising from 9%, and whether recovery keeps improving alongside it.
- Whether DfE or NCSC guidance for governing boards becomes a formal expectation that governors sign off backup and response plans.
- Whether the share of secondary schools reporting protective action moves past 55%, and whether later data links those measures to recovery.