More UK Schools Are Recovering Faster from Cyber Incidents
The government’s Office of Qualifications and Examinations Regulation (Ofqual) released new figures on October 1 to coincide with Cyber Security Awareness Month.

The government’s Office of Qualifications and Examinations Regulation (Ofqual) released new figures on October 1 to coincide with Cyber Security Awareness Month.
It revealed that the share of schools experiencing a cyber incident has fallen consistently over recent years: from 34% in 2023-24 to 29% in 2024-25 and 27% for 2025-26.
When incidents take place, two-thirds (66%) of schools are now able to recover immediately, up from 55% in the prior academic year.
Cybersecurity should be a responsibility shared between IT, teachers and senior leadership, he added, claiming: Some 2162 schools and 3775 teachers were surveyed for the Ofqual study.
A notification from the firm published by a customer on Reddit on October 2 revealed that the breach itself was discovered almost two months ago.
Together, the details could be used to craft more convincing phishing attacks, and provide a solid foundation for attempting various types of identity fraud including tax scams and new account fraud.
Read more on education sector cyber risk: Cyber-Attacks Surge 63% Annually in Education Sector said Ofqual executive director of delivery, Amanda Swann.
Mat Pullen, director for education at Jamf and a former secondary school teacher and university lecturer, said it’s encouraging that the sector is improving cyber resilience.
Critical damage from attacks has also fallen, down to 7%.
Regular backups and a clear response plan can make a huge difference when things go wrong.” However, the data revealed that, for a plurality of schools, cybersecurity is in fact still treated as a problem solely for the tech team.
Frontline Education provides administration software for thousands of K-12 school districts, enabling teams to better manage human capital, business operations and special education.
“The important security question is what that vulnerable application could reach.
Frontline says it remediated the vulnerability, but affected districts also need to understand which records were accessible through it and what controls limited that access,” he argued.
Frontline Education said it would be sending notices out to all individuals affected via email and post, as well as publishing a notification on its website and via a press release.
What happened
The government’s Office of Qualifications and Examinations Regulation (Ofqual) released new figures on October 1 to coincide with Cyber Security Awareness Month.
It revealed that the share of schools experiencing a cyber incident has fallen consistently over recent years: from 34% in 2023-24 to 29% in 2024-25 and 27% for 2025-26.
When incidents take place, two-thirds (66%) of schools are now able to recover immediately, up from 55% in the prior academic year.
What changed
Cybersecurity should be a responsibility shared between IT, teachers and senior leadership, he added, claiming: Some 2162 schools and 3775 teachers were surveyed for the Ofqual study.
A notification from the firm published by a customer on Reddit on October 2 revealed that the breach itself was discovered almost two months ago.
Together, the details could be used to craft more convincing phishing attacks, and provide a solid foundation for attempting various types of identity fraud including tax scams and new account fraud.
Who is affected
Read more on education sector cyber risk: Cyber-Attacks Surge 63% Annually in Education Sector said Ofqual executive director of delivery, Amanda Swann.
Mat Pullen, director for education at Jamf and a former secondary school teacher and university lecturer, said it’s encouraging that the sector is improving cyber resilience.
Why it matters
Critical damage from attacks has also fallen, down to 7%.
Regular backups and a clear response plan can make a huge difference when things go wrong.” However, the data revealed that, for a plurality of schools, cybersecurity is in fact still treated as a problem solely for the tech team.
Technical details
Frontline Education provides administration software for thousands of K-12 school districts, enabling teams to better manage human capital, business operations and special education.
“The important security question is what that vulnerable application could reach.
Frontline says it remediated the vulnerability, but affected districts also need to understand which records were accessible through it and what controls limited that access,” he argued.
Response
Frontline Education said it would be sending notices out to all individuals affected via email and post, as well as publishing a notification on its website and via a press release.
AI tools are also frequently deployed to generate custom malware for attacks.
What security teams should do
Asked who is primarily responsible for cybersecurity, nearly half (46%) of responding teachers said their IT team, 40% said all staff, and only 9% claimed senior leadership played a role.
This might explain why many schools are still failing to prioritize cyber initiatives.
What remains unknown
Districts need to understand why access through that application exposed sensitive employee records and whether similar access paths remain elsewhere in the environment.” Thus far, it’s unclear how many districts and staff members are impacted by the breach.
Attribution
Infosecurity Magazine: The government’s Office of Qualifications and Examinations Regulation (Ofqual) released new figures on October 1 to coincide with Cyber Security Awareness Month.
Infosecurity Magazine: Frontline Education provides administration software for thousands of K-12 school districts, enabling teams to better manage human capital, business operations and special education.
Infosecurity Magazine: The tech giant said that attackers are getting to the advantages of AI first, and the pressure is now on defenders to adapt quickly to close the gap.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.