3 min read

Cyber Security Awareness Month: five questions every school and MAT should ask

Cyber Security Awareness Month: five questions every school and MAT should ask

October’s Cyber Security Awareness Month is a useful opportunity to pause and ask a practical question: how confident are we that our school could keep operating through a cyber incident?

For school and multi-academy trust leaders, cyber safety reaches into everyday decisions about people, systems and budgets. An unavailable account or inaccessible system can interrupt lessons, delay administration and make essential information harder to access.

Awareness activities are a valuable starting point. The next step is to turn that attention into a clear understanding of your ICT arrangements, the gaps that need addressing and who will take action.

These five questions can help shape that conversation.

 

1. Do staff know what to do when something looks wrong?

 

A convincing email can arrive during a busy lesson changeover or just before a payment deadline. Staff need practical guidance that reflects those pressures.

Use short, relevant examples: an unexpected password reset, a supplier requesting new bank details or a message asking for sensitive pupil information. Explain how to check an unusual request through a trusted contact route and where to report concerns.

Make reporting straightforward and supportive. Someone who has clicked a suspicious link should feel able to raise it immediately.

The National Cyber Security Centre’s free training for school staff provides a useful starting point for raising awareness of the threats schools face.

 

2. Are important accounts protected appropriately?

 

Ask your ICT support team to explain where multi-factor authentication, or MFA, is enabled and where gaps remain. MFA adds another verification step when someone signs in, helping protect accounts if a password is stolen.

The Department for Education’s MFA guidance highlights privileged accounts, internet-accessible systems and cloud services handling sensitive information. It also identifies senior leaders and staff working with confidential or financial data as important users of MFA.

For a MAT, a useful review question is whether protection is consistent across every academy. Ask for a clear account of any exceptions, the reasons behind them and the plan to resolve them.

 

3. Have we tested that our backups can be restored?

 

A successful backup notification does not answer every recovery question. Leaders also need to understand which information is covered, how it is protected and whether it can be restored when needed.

The DfE’s backup guidance recommends multiple, separated copies, protection for backups and regular restoration tests. It also makes clear that cloud-based systems still need appropriate backup arrangements.

Ask your team to talk through the latest recovery test. What was restored? How long did it take? Were any gaps identified?

Connect those answers to school operations. Prioritise the information and services needed to support pupils, communicate with families and keep essential processes running.

 

4. Could we put our response plan into practice?

 

A cyber response plan becomes more useful when people have rehearsed it.

Try a short discussion exercise with senior leaders, technical colleagues and relevant operational staff. Imagine that email and shared files are unavailable at the start of the school day.

Who coordinates the response? How will colleagues contact each other? Which activities need an alternative process? What information will leaders need before making decisions?

The DfE Cyber Security Hub offers guidance and a template to help schools develop their response plans.

Use the exercise to identify specific improvements, then assign an owner and completion date to each one.

 

5. Does our digital strategy reflect what we have learnt?

 

Cyber awareness should inform the decisions schools make throughout the year.

Your review may reveal a need for clearer responsibilities, additional staff training, improvements to infrastructure or better oversight of suppliers. Bring those findings into your school digital strategy so that priorities, budgets and timescales are considered together.

An IT audit can provide a useful foundation for that work. Novatia’s  ICT Audit & Digital Strategy service independently reviews technical, operational and educational ICT, including network resilience, support arrangements and how technology serves teaching and learning. Its findings inform practical improvement recommendations and a digital strategy.

For leaders, that wider view helps connect the reliability of school IT with the needs of staff, pupils and the organisation.

 

Turn October’s awareness into a practical plan

 

Use this month to bring the right people together, ask for evidence and agree a manageable set of actions. Review progress regularly so that cyber resilience remains part of how your school supports safe, reliable digital learning.

Get in touch with Novatia to discuss how our ICT audits, consultancy and digital strategy services can help you understand your current provision, prioritise improvements and plan the next steps for your school or trust.