"Reducing incidents matters, but so does recovering faster," said Mat Pullen, director of education at Jamf — a concise summation of the picture that emerges from a new Ofqual survey of England's secondary schools.
Ofqual's headline findings: fewer incidents, clearer sample
Ofqual, the exams regulator, surveyed 3,775 secondary teachers in England in July and, for whole-school questions, counted one response from the most senior participating teacher at each institution, producing a sample of up to 2,162 schools. The proportion of schools reporting a cybersecurity incident fell to 27 percent in the 2025/26 academic year, down from 29 percent the year before and 34 percent in 2023/24.
Phishing was the most commonly reported incident type, followed by data protection breaches, hacking, and ransomware. Ransomware affected 2 percent of respondents. Staff data was the information most commonly compromised; student data was affected in 13 percent of incidents and student work in 1 percent.
Recovery times improved, measured damage fell
Recovery figures showed the clearest improvement. Among schools reporting an incident, 66 percent said they recovered "immediately," up from 55 percent in the previous academic year. A further 12 percent recovered within half a school term — roughly six or seven weeks — while 1 percent took longer than half a term and another 1 percent required at least a full term.
The share of incidents that respondents considered to have caused "critical damage" fell from 10 percent to 7 percent. Ofqual told The Register that "critical damage" was not defined and that respondents were free to interpret the question as they saw fit.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadDefensive measures taken — and the gaps teachers report
When asked what cybersecurity improvements their school had made during the past year, 54 percent of teachers selected "I don't know." Among the 46 percent who identified at least one change, half said their school had introduced a cybersecurity policy, 22 percent cited new or tested backup procedures, and 20 percent said they had completed or updated an incident response plan.
Training figures were mixed. Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had, up from 28 percent a year earlier; a similar proportion said the training they received was not useful. Of those who received training, 65 percent said they made no changes as a result.
Responsibility for cybersecurity: IT, everyone, or leaders?
Teachers were divided over primary responsibility for cybersecurity: 46 percent pointed to the IT team, 40 percent said responsibility was shared among all staff, and just 9 percent identified senior leadership. Ofqual argued that cybersecurity is a leadership responsibility rather than solely an IT problem.
Mat Pullen echoed that concern, calling the frequency and recovery figures "promising" but warning that the understanding of security responsibility remained a worry. He noted that cyberattacks have previously closed schools for a week or longer, disrupting education and affecting the wider economy as parents take time off work. "Ultimately, cybersecurity is a shared responsibility of IT, teachers and senior leadership, and breaking down these silos keeps technology secure and lessons running," he said.
What this means for IT teams, senior leadership, and teachers
- IT teams: Faster recoveries suggest operational improvements or better tooling in some schools, but low recognition of who owns security and limited changes after training (65 percent said they made no changes) point to gaps in translating learning into practice.
- Senior leadership: With only 9 percent of teachers naming senior leadership as primarily responsible, leaders face a credibility and accountability gap even as Ofqual frames cybersecurity as a leadership duty.
- Teachers: A third report no or uncertain training and similar numbers find training not useful; that combination helps explain why 54 percent cannot say what their school improved in cybersecurity over the past year.
How this sits alongside broader UK data
Ofqual's findings are measurably more optimistic than the government's Cyber Security Breaches Survey published in April. That government research found 73 percent of secondary schools across the UK had identified a breach or attempted attack during the previous 12 months (49 percent for primary schools, 88 percent for further education colleges, and 98 percent for higher education). The government survey counted identified attacks and breaches regardless of whether they succeeded, and it covered the full education sector across the UK rather than secondary schools in England alone; Ofqual used teacher-reported "incidents" in a narrower population.
The government survey also showed more frequent targeting in further and higher education — 27 percent of those institutions identified attacks at least weekly — and that almost half of those reporting a breach suffered an adverse impact on their systems. In June, several schools across England and Wales temporarily shut while technicians investigated a malware scare. The ICO said last year that students were responsible for more than half of cyberattacks attributed to a known actor in the UK education sector.
Ofqual cannot yet explain what drove the apparent improvements in incident numbers and recovery times, and more than half of teachers cannot identify what changes their schools made over the past year. The data shows progress on response, but also persistent uncertainty about who should lead on school cybersecurity and how training turns into better practice — questions that will determine whether the recent gains hold.




