Cyber Rebels

Why School Staff Are Central to School Cyber Security

School staff member working at a desk with a laptop and paperwork.

A teacher is preparing for a lesson when the resource they need refuses to open. The class is due in a few minutes. Another member of staff sends a link to the document and says they may need to sign in again. Nothing about the situation feels particularly unusual. The colleague is familiar, the resource […]

A teacher is preparing for a lesson when the resource they need refuses to open. The class is due in a few minutes. Another member of staff sends a link to the document and says they may need to sign in again.

Nothing about the situation feels particularly unusual. The colleague is familiar, the resource is expected and the request solves a problem that genuinely needs solving. Following the link feels less like taking a security decision and more like getting the lesson ready.

That is one of the reasons school staff are so important to cyber security.

Cyber risk does not sit neatly in the IT office waiting to be dealt with as a technical problem. It appears while people are teaching, supporting pupils, communicating with parents and carers, handling safeguarding information, approving access, paying suppliers and trying to keep a busy school running. A request can be malicious while still making complete sense in the work around it.

Schools already recognise much of this risk. The latest Cyber Security Breaches Survey 2025/2026 found that 49% of primary schools and 73% of secondary schools surveyed had identified a cyber security breach or attack during the previous 12 months. Among the schools that had identified an incident, phishing was overwhelmingly the most common type, reported by 90% of affected primary schools and 96% of affected secondary schools.

Those figures matter, but not because they show that school staff are doing something wrong. In fact, the same survey paints a much more interesting picture. Schools already report high levels of technical controls, formal cyber policies, senior leadership engagement and staff awareness activity. The difficult part of school cyber security is not choosing between technology and people. It is making sure all of those layers still work together when somebody has to make a decision in the middle of an ordinary school day.

Why cyber security cannot stop with the IT team

Good technical security is fundamental. Schools need properly configured systems, appropriate access controls, secure accounts, malware protection, firewalls, patching, backups and effective technical support. Asking staff to be more vigilant cannot compensate for weak technology, and awareness training should never be presented as a substitute for those controls.

The 2025/2026 survey suggests that schools have made substantial progress in many of these areas. At least nine in ten of every type of educational institution surveyed had relevant controls covering firewalls and internet gateways, secure configurations, user access and malware protection. The survey’s mapping against the NCSC’s 10 Steps to Cyber Security also found that 99% of primary schools and 98% of secondary schools met its mapped measure for architecture and configuration, while 89% and 86% respectively met the identity and access management measure.

Technology can prevent or limit a great many actions. What it cannot do is remove every judgement that happens around it.

A school can control who has access to a shared platform, but somebody may still need to decide whether a new request for access is appropriate. An email system can filter enormous amounts of malicious traffic, but it cannot guarantee that a convincing message from a compromised genuine account will be recognised. A school can establish rules for handling information, but a member of staff may still have to decide what should be shared when a safeguarding concern is moving quickly and another professional appears to need the details.

Those decisions are not edge cases. They are woven through the way modern schools operate.

Teaching staff move between learning platforms, email, shared resources and pupil information. Reception teams deal with parents, visitors and requests that often need an immediate answer. Safeguarding staff work with information where both confidentiality and timely action matter. Finance teams handle invoices and supplier changes. Senior leaders approve access and respond to issues across several areas at once. In a multi-academy trust, central teams may also be supporting staff they do not know personally across several schools and shared systems.

The systems matter. The policies matter. The people making decisions inside them matter too.

That is why describing staff as the “weakest link” gets the problem badly wrong. People are not an inconvenient vulnerability bolted onto an otherwise perfect technical system. They are part of how the school functions. The real challenge is helping them make good decisions when security is only one of several legitimate things competing for their attention.

The difficult decisions often look like normal school work

Phishing remains important because modern phishing is not limited to badly written messages from obviously suspicious senders. The Cyber Security Breaches Survey found that phishing dominated the incidents identified by schools, while impersonation was also reported by 31% of affected primary schools and 44% of affected secondary schools.

Both work particularly well when the request fits its surroundings.

Imagine an email that appears to come from a senior leader asking for a document before a meeting. The meeting exists. The document exists. The sender’s name is familiar and getting the information across quickly appears helpful.

Or a message from a parent that refers to a real pupil and asks for something to be sent to a different address.

Or a shared-document notification that appears while a teacher is already waiting for somebody to grant access to teaching material.

Or a supplier asking for payment information to be updated during a conversation about a genuine invoice.

In each case there may be something that needs checking, but the surrounding context gives the request credibility before the person has consciously assessed it. The task is real, the timing makes sense and acting keeps the work moving.

That is very different from someone seeing a clear cyber threat and deciding to ignore it.

Schools can make this even more difficult because responsiveness often has a legitimate purpose. A teacher is expected to be ready for the lesson. A receptionist is trying to help a family. A safeguarding lead may be dealing with something that should not be delayed unnecessarily. A school business manager has deadlines. A member of a trust team may be trying to resolve an issue before it affects several schools.

Speed is not simply carelessness in those situations. Sometimes it is what responsible work looks like.

The cyber security challenge is therefore not to teach staff that every unusual request should be treated as dangerous. A school where nobody trusts anybody and routine work constantly grinds to a halt would not be more secure in any useful sense.

The more practical skill is learning to separate the genuine situation from the action being requested.

The pupil can be real while the route used to ask for their information still needs checking. The colleague can genuinely need the document while the particular access request is wrong. The supplier can be genuine while the bank-details change has come from somebody else. A familiar account can belong to the right person while the message sent from it was not written by them.

That distinction creates room for a proportionate check without turning ordinary school work into constant suspicion.

Most schools already provide cyber awareness. The harder question is what happens afterwards

If the latest breach figures were the only evidence available, it would be easy to reach for the familiar answer: schools need more cyber security awareness training.

The same survey makes that conclusion much harder to justify.

Cyber security training or awareness activity for staff or volunteers not directly involved in cyber security had already been delivered by 72% of primary schools and 77% of secondary schools surveyed. The report says this continues a longer-term increase in activity within schools.

Schools are not simply ignoring awareness.

Many are also testing it. Some 51% of primary schools and 61% of secondary schools reported testing staff awareness and response, including through activities such as mock phishing exercises.

That moves the conversation somewhere more useful.

A member of staff can know what phishing is. They can understand why passwords matter. They can know that unexpected attachments should be treated carefully and that sensitive information should not be shared without thought.

The hard part arrives when none of those ideas presents itself in textbook form.

During training, the example is normally visible because everyone knows they are there to talk about cyber security. The phishing email is being examined as a phishing email. The suspicious request is already framed as something worth questioning. Participants have time to discuss it because discussion is the task.

Real work removes that framing.

Weeks later, the same person is not thinking, “I am now completing a cyber security exercise.” They are trying to get into a system before pupils arrive, respond to a colleague, deal with an urgent message or find the document somebody needs.

The question therefore changes from “Does this person know what phishing is?” to “What helps them recognise when this particular request deserves another look?”

That does not make basic awareness unimportant. Staff still need the underlying knowledge. But awareness becomes much more useful when it also gives people somewhere to practise applying that knowledge in situations where the answer is not already obvious.

A school-specific discussion can explore why a request feels credible before examining what should be checked. Staff can work through the difference between questioning the situation and questioning the route. They can consider what independent verification actually looks like in their environment, when something should be escalated, and how to deal with uncertainty when the immediate task still needs completing.

That moves training away from trying to make people remember more warnings and towards helping them make better use of what they already know.

Cyber security now sits explicitly within the wider safeguarding picture

For schools in England, there is another reason this matters.

Keeping Children Safe in Education 2026, which comes into force on 1 September 2026, makes an explicit connection between cyber security and safeguarding. It says governing bodies and proprietors should protect children by protecting personal information and ensuring appropriate cyber security systems are in place, and that this should be approached as part of the school’s or college’s wider safeguarding responsibilities. It points schools towards the Department for Education’s cyber security standards as part of that work.

That does not mean every phishing email becomes a safeguarding incident, nor does KCSIE turn its safeguarding training requirements into a general statutory requirement for cyber awareness training.

What it does is make the significance of school cyber security harder to reduce to “keeping the computers safe”.

Schools hold information because they need it to educate and protect children. Pupil records, contact information, SEND information, behaviour records, safeguarding material and communications with families all exist for legitimate reasons. The systems holding that information also support teaching, communication and day-to-day school operations.

A cyber security decision can therefore sit surprisingly close to a safeguarding one.

A request to share information may be motivated by the need to support a child quickly. A member of staff may feel uncomfortable delaying something because they believe another professional needs it. A message that appears to come from a parent or safeguarding colleague carries a different kind of pressure from a generic business email because the consequences of not responding can feel personal and immediate.

That is exactly where blanket advice such as “never click links” or “always slow down” becomes less useful. Staff need a way to protect the child and check the request, not a security rule that assumes the underlying responsibility can simply wait.

KCSIE’s wider approach to online safety points in a similar direction. It describes effective online safety as a whole-school and college approach that protects and educates pupils, students and staff while establishing mechanisms to identify, intervene in and escalate concerns where appropriate. It also requires safeguarding and child-protection training, including online safety, to be regularly updated, with updates provided at least annually.

That emphasis on usable routes matters beyond safeguarding. Recognition is only one part of a good response. Staff also need to know what to do next and to have confidence that the organisation will support them when they do it.

Staff are central. They are not the whole of school cyber security

Putting staff at the centre of the conversation creates a danger of putting all of the responsibility there too.

Those are not the same thing.

If a member of staff is expected to verify an unusual request but there is no simple way to do it, repeating the instruction to “verify first” will not fix the process. If people are told to raise concerns but doing so consistently creates criticism or unnecessary difficulty, the organisation is teaching them something very different from the awareness session. If permissions are poorly configured, training cannot turn excessive access into good access control. If systems are not patched or accounts are badly protected, staff cannot compensate by becoming permanently alert.

The Cyber Security Breaches Survey reflects that broader picture. Schools reported high levels of senior-management engagement, technical controls, formal policies, business-continuity planning and risk-identification activity alongside staff training. Cyber security is already being treated by many schools as a combination of governance, technology, process and people rather than a single intervention.

That is the right direction.

Awareness training has a specific job within it.

It can help people recognise when an apparently normal situation deserves a check. It can let them practise verification and escalation before the pressure is real. It can expose situations where different roles interpret the same process differently. And it can reveal points where staff know what they should do but the systems or processes around them make that response harder than it needs to be.

What it cannot do is carry the entire school’s cyber security responsibility.

School staff are central to school cyber security. They are not the whole of school cyber security.

The distinction matters because it changes what good training looks like. The aim is not to make staff individually responsible for preventing every attack. It is to make their judgement a stronger part of a wider system that also includes secure technology, clear responsibilities, usable processes, appropriate governance and leadership support.

Cyber awareness has to work while the school is working

The teacher from the beginning still needs the lesson resource.

The answer cannot be to treat every link from a colleague as hostile. Nor is the answer to follow every request simply because it appears at a convenient moment.

What matters is being able to recognise the small change in the situation: an unexpected sign-in, a different sharing route, a request for more access than expected, a detail that does not quite fit. Then there needs to be a proportionate way to check it without turning a routine task into an investigation.

The same principle holds across the school.

The receptionist still needs to help the parent. The safeguarding lead still needs the information. The finance team still needs to pay genuine suppliers. Staff still need access to the systems and documents that allow them to do their jobs. The trust still needs schools to cooperate and share information.

Cyber security has to function inside that reality.

That is why useful awareness training should do more than explain cyber threats. It should help people recognise how those threats can borrow the appearance of real work, understand why acting can feel completely reasonable, and practise the checks that still make sense when the school day is already moving.

The goal is not a workforce that distrusts everything.

It is a school where people are better able to tell the difference between trusting the situation and confirming the request — and where the systems, processes and leadership around them make that distinction practical.

For schools and multi-academy trusts that want to explore that approach, Cyber Rebels provides live cyber security awareness training built around the roles, systems and working situations staff actually encounter, rather than treating education as a generic cyber awareness audience.

Explore cyber security training for schools and MATs

Director of Training and Development, Cyber Rebels. Andy Longhurst is the founder of Cyber Rebels and a cybersecurity practitioner and educator focused on how risk actually shows up in real organisations. His work sits at the intersection of digital safety, education, and practical risk management — helping teams understand not just what policies say, but what happens in the moments where decisions are made under pressure. With a background spanning adult education, web development, and technical consultancy, Andy specialises in translating complex security concepts into clear, usable understanding. Rather than focusing solely on tools or compliance frameworks, his approach centres on human behaviour, judgement, and the systems that shape everyday choices. He delivers live, interactive cyber awareness training for organisations of all sizes, from small businesses and education providers to public-sector teams and larger organisations operating in complex risk environments. Outside of delivery, Andy spends his time analysing emerging attack patterns, refining training design, and exploring how organisations can build resilience that holds up in the real world — usually with a strategically sized cup of tea close to hand.

Shopping cart close