Schools & MATs

Digital graphic displaying a cyber security alert, warning schools about sophisticated payroll fraud and online threats.

Schools across the Thames Valley area are being targeted by criminals attempting to access staff payroll accounts, according to a warning issued by the South East Cyber Crime Unit's Cyber Protect team. In several confirmed cases, the attacks have succeeded, leaving affected staff without their pay after criminals diverted their salaries elsewhere.

Digital graphic symbolizing a cyber attack and data breach at the Department for Education (DfE).

The Department for Education confirmed that hackers have accessed its internal helpdesk and the Turing Scheme portal, taking more than 600,000 records. Contact details belonging to headteachers, senior school leaders, government officials and university staff were among the data taken, and some of it has since appeared on the dark web.

Understandably, this has caused a lot of anxiety across the sector and, predictably, a lot of speculation. Was this preventable? Should the DfE have done more? Who's to blame?

Digital screen interface representing a school Management Information System (MIS) handling pupil records and DfE

A Management Information System (MIS) is the single most important data processing system a school operates. It holds pupil records, including special category data, safeguarding information, and family contact details. So when the Department for Education publishes guidance on choosing one, DPOs and data protection leads should pay attention, even when, as here, the guidance is framed in commercial rather than data protection terms.

Graphic representing new DfE guidance on EdTech procurement for schools, focusing on data protection.

On 9 July 2026, the DfE added a new section to its Data Protection in Schools guidance: Procuring educational technology (EdTech). It sets out what schools should consider before, during and after procuring EdTech tools, and the questions to put to prospective suppliers. Significantly, it is the first DfE guidance to directly reference the ICO's EdTech Examined audit report, telling schools to take the ICO's findings into consideration when procuring EdTech tools.

ICO EdTech Examined report graphic, highlighting data protection audit findings for UK schools and children'

The ICO's edtech audit programme, covering 28 providers used across UK primary and secondary schools, has resulted in one of the most significant data protection reports to affect the education sector in years. Published in June 2025, the ICO's EdTech Examined report made 596 recommendations and found widespread compliance failures in how edtech providers handle children's personal data. This article sets out what was found and what schools and DPOs need to do about it.

Graphic representing the Department for Education (DfE) Data Protection in Schools guidance update from June

The Department for Education (DfE) updated its Data protection in schools guidance on 17 June 2026, this refresh aligns the guidance with the wider expected KCSIE 2026 guidance and reinforces existing obligations that schools should already be acting on.

This article sets out what has changed, what it means for your school in practice, and the actions your data protection lead should be taking now.

 

  1. The DSL’s Guide to Filtering and Monitoring
  2. Cyber Attack : LockBit 5.0 Targets a Primary School
  3. Human Error and High Stakes: What the Horizon Academy Trust Incident Teaches Us About School Data Breaches
  4. We’re Bringing It Back: Our Data Protection Conference Returns
  5. When Cyber Risk Becomes Reality: Lessons from the Powys School Attack
  6. What the Data (Use and Access) Act Means for Schools
  7. Can you use AI safely in schools?
  8. Guardians of Privacy: Social Media, Privacy, Children and the AI Threat
  9. What School Leaders Need to Know About the DfE's New Cyber Security Hub
  10. The Cyber Security Breaches Survey 2025/2026 - Key Advice for Schools
  11. The 2026 Mandate: Navigating the Children’s Wellbeing and Schools Act.
  12. Visitor Management: A Guide for Schools
  13. Update to the DfE Digital Cyber Security Standards for Schools and Colleges
  14. Wireless Network Standards for Schools & Colleges: What's New?
  15. How were schools and pupils affected by the C2K cyber attack?
  16. School Cyber Attack: St Anne's Catholic School
  17. Volunteer Acceptable Use Policy & Agreement
  18. Handling Subject Access Requests (SARs) - at the end of term
  19. Holiday Cheer or Cyber Fear? : Essential Pre-holiday Checks
  20. How should schools manage paper archives?
  21. Navigating the Redaction Divide: SAR or PEX?
  22. What type of request have you received? SAR? Educational Record? Or FOI?
  23. Leavers' Memorabilia
  24. Sharing photos on World Book Day: Privacy considerations
  25. The Danger of the 'Data Dump': Why more information isn't always better!
  26. Cyber Alert: Surrey and Sussex Schools Targeted by Phishing and Ransomware Attacks
  27. Parents and students covertly recording conversations
  28. New DfE AI Standards
  29. Is your IT Support Provider Compliant?
  30. The Government Cyber Action Plan
  31. School Cyber Attack: Higham Lane School Hit by Major Cyber Attack: Campus Remains Closed
  32. What does the technology in schools survey tell us?
  33. IT Support Standards for Schools and Colleges Guidance (DfE Digital Standards)
  34. Sharing information to safeguard children and young people in the education sector in the UK
  35. October 31. On the road to improving cyber resilience
  36. October 30. Cyber Support
  37. October 29. Admin Controls & Accounts
  38. October 28. Phishing: Don't Take the Bait!
  39. October 27. Passwords
  40. October 26. Physical Security of Digital Assets
  41. October 25. Server Security: Protecting Your Digital Core
  42. October 24. Backups: Your Recovery Safety Net
  43. October 23. Filtering and Monitoring
  44. October 22. Hardware: Printers
  45. October 21. Hardware: Asset Management
  46. October 20. Hardware: Safe disposal
  47. October 19. Anti-virus/anti-malware
  48. October 18. Regular Updates: Patching Against Threats
  49. October 17. Access Control: Managing User Privileges
  50. October 16. Access Control: Securing Your Digital Gateways (Wi-Fi & Networks)
  51. October 15. Access Control: Securing Your Home Office (Working From Home)
  52. October 14. Access Control : (Multi-factor authentication)
  53. We've teamed up on a podcast with the Small Business Cyber Security Guy
  54. October 13. Cyber Security Awareness
  55. October 12. Training: Empowering your human firewall
  56. October 11. Policies and Procedures: Cyber Blueprint
  57. October 10. Understanding Your Cyber Posture
  58. Time's Ticking: Windows 10 support ends in October 2025!
  59. October 9. A Guide for Education Providers
  60. October 8. How Can Your Organisation Prevent Ransomware Attacks?
  61. October 7: Under Attack: The Reality of Ransomware
  62. October 6: Cyber Action Plan and A Roadmap to Resilience
  63. October 5: Cyber Responsibilities - We're All in This Together
  64. October 4: When a Cyber Attack Hits
  65. October 3: Data Security, the Core of Protection
  66. October 2: Privacy Protection & Safeguarding Personal Data
  67. October 1: Welcome to Cyber Security Awareness Month!
  68. Nursery Cyber attack
  69. Fraud awareness from the DfE
  70. The Classroom's Dark Side: Cyber crime from the Classroom
  71. Data Breach: School sends out names and contact details in a spreadsheet.
  72. KCSIE 2025: Data Protection, AI, and Cyber Security
  73. The Online SCR Data Breach: What You Need to Know
  74. Back to School Basics for Data Protection and Cyber Security Compliance
  75. The Latest Cyber Threat: The "Murky Panda"
  76. Building a Secure School: Using the ICO Accountability Framework to Meet DfE Digital Standards
  77. Why Physical and Data Security Must Go Hand-In-Hand
  78. Digital Safeguarding: DfE announces statutory DfE Digital Standards
  79. The Data Protection Lead/Champion Role
  80. Changes to the Academy Trust Handbook 2025
  81. School closes for two days after cyber incident
  82. Social Media Day 2025
  83. How Ofsted looks at AI during inspection and regulation
  84. Data Breaches 2025 Report Highlights
  85. Not everyone needs access: The Key to Protecting Sensitive Data
  86. School cyber attack: Outwood Academy, Middlesbrough
  87. Alert: Schools receiving Microsoft File Sharing Phishing Emails
  88. School cyber attack: Framlingham College, Suffolk
  89. West Lothian Schools in Cyber Attack
  90. A Wake-Up Call for Cyber Vigilance - Danger in the Threat Landscape for Everyone
  91. New Governor Resources
  92. Are teachers using AI? 83% say its a time-saver
  93. DfE Digital Standards - narrowing the digital divide
  94. Arbor AI - On By Default
  95. DfE Guidance: Choosing a new MIS
  96. Short Guide to AI Video
  97. Safer Internet Day, Cyber Security & Data Protection
  98. The Cyber Resilience Championship
  99. The Multiple Dimensions of Supplier Due Diligence
  100. School shares sensitive pupil information as part of an FOI response
  101. Blacon High School Cyber Attack
  102. WhatsApp and FOI's: ICO Warnings
  103. New AI Guidance from the DfE
  104. What the proposed Government legislative proposal around cyber crime means
  105. DfE update to record keeping and management
  106. Update to data sharing for school immunisation programmes
  107. SLT Digital Lead Profile
  108. The role of governors in cyber security and data protection
  109. Navigating Privacy at the End of Term , Special Occasions and End of Year
  110. South East Technological University has experienced a cyber incident
  111. Safeguarding Identity in Microsoft 365: Protecting the UK Education Sector Against Cyber Threats
  112. Cyber Attack on a Special School
  113. Stealing children's data
  114. Ofqual highlights the value of cyber security training in schools
  115. Fylde Coast Academy Trust Cyber Attack This Week
  116. Calling all IT leads in schools and mult academy trusts!
  117. Ransomware cyber attack on a school in Bromley
  118. School hit by Cyber Attack
  119. DfE Digital Standards for Schools and Colleges Tracker
  120. Schools and Trusts Best Practice Area
  121. ESFA Cyber Essentials Requirement for Colleges from 2024/2025
  122. ICO Reprimands a School
  123. Out of date technology
  124. Data Retention and the Pupil File
  125. Have you assigned your SLT Digital Lead yet?
  126. What's a Cyber Incident and what should we do?
  127. Getting Started with AI (Artificial Intelligence)
  128. Cyber attack on a school during half term
  129. The rise of cyber attacks in schools are causing pupils to miss classes
  130. Cyber attack on a Trust; the aftermath
  131. School Focus: The Vale Federation | Aylesbury
  132. DfE Dealing with Subject Access Requests (SARs) Guidance
  133. Update to the Guidance on Information Sharing from the DfE
  134. Product Focus on Checklists : Initial Trust Plan
  135. Product Focus on Checklists : End of Term Checklist
  136. Product Focus on Checklists : Social Media
  137. Product Focus on Checklists : Lettings
  138. Milk Island: The secret location that allows children to view restricted content on Google Maps
  139. Free Cyber help, advice and training with the Cyber Resilience Centres
  140. The Perils of Paper: The Printing Vulnerability
  141. Product Focus on Checklists : Governors and Data
  142. Product Focus on Checklists : Site Moves
  143. Cyber attack on a University
  144. Product Focus on Checklists : Bring your own device
  145. Product Focus on Checklists : Working out of school/offsite
  146. Cyber Attack on a School
  147. Major cyber-criminal gang Lockbit brought down by UK Law Enforcement
  148. Product Focus on Checklists : Photos and video
  149. Safer Internet Day 2024
  150. Kent Councils Data Breach
  151. Free cyber training for staff
  152. DfE Digital Standards Update
  153. ClassCharts Possible Data Breach
  154. School Focus: St Bernadette's Catholic Primary School | Brighton
  155. Guardians of Privacy: 16. Social Media Checklist
  156. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  157. Guardians of Privacy: 14. Social Media and Cyber Bullying
  158. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  159. Guardians of Privacy: 12. Social Media and Going Viral
  160. Guardians of Privacy: 11. Staff Social Media Accounts
  161. Guardians of Privacy: 10. Social Media and Cookies
  162. Guardians of Privacy: 9. Social Media and Morality
  163. New Resources for Schools from the ICO
  164. Guardians of Privacy: 8. Social Media Policies
  165. Guardians of Privacy: 7. Social Media Data Retention
  166. Guardians of Privacy: 6. Posting Safely
  167. Guardians of Privacy: 5. Social Media and Consent
  168. Guardians of Privacy: 4. Social Media Access Control
  169. Guardians of Privacy: 3. Social Media Channels
  170. Guardians of Privacy: 2. Law and Regulations
  171. Phishing attacks targeting schools - alert from City of London Police
  172. The ICO reprimands a Multi Academy Trust
  173. Guidance for the use of school email and applying email retention in schools
  174. Data Protection Tips for Early Years Settings
  175. Trust Initial Plan Checklist Update
  176. Update on Advisory for Rhysida Ransomware
  177. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  178. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  179. Lettings Best Practice and Guidance
  180. The UK Online Safety Bill becomes an Act (Law)
  181. Considerations when migrating to a new MIS
  182. The importance of software updates (PaperCut vulnerability and Rhysida ransomware)
  183. Public bodies and sensitive data
  184. ICO: 10 Step guide to sharing information to safeguard children
  185. Email and Security: ICO recent guidance
  186. Social Media Policy
  187. Data Protection and Cyber Security (Inset Day) Training Ideas
  188. Changes to Microsoft Free Licensing for Schools
  189. What to do in the event of a Cyber Attack
  190. How KCSIE is linked to Cyber Strategy
  191. VICE SOCIETY - Ransomware attacks on schools
  192. Using Tags if you are a group of organisations in the DPE Knowledge Bank
  193. Cyber Insurance in the Public Sector
  194. Cyber Attack: Leytonstone School
  195. The ICO Reprimands a school
  196. Cyber Attack: Dorchester School
  197. Knowledge Bank Role Types: Admin, Staff and Trustee
  198. Cyber Attack: Wiltshire School
  199. Types of Cyber Attacks: The Insider Threat
  200. Why your data is profitable to cyber criminals
  201. Striking Data Breach
  202. January Cyber update - How Can Schools Help Prevent Cyber Attacks?
  203. FOI: Vaccination Justifications
  204. The Education sector now at highest risk of cyber attacks
  205. Schools Blocked from Using Facial Recognition Systems
  206. The Children's Code
  207. Cyber Attacks
  208. Protocol for Setting Up and Delivery of Online Teaching and Learning
  209. Class Dojo International Data Sharing
  210. Secure file transfer of files using Royal Mail
  211. Emergency contacts and consent
  212. Best Practice for Managing Photos and Video
  213. Headteacher fined for breach of data protection legislation

Search