...

School cyber security has formally become a safeguarding issue, not just an IT one, under the 2026 edition of Keeping Children Safe in Education, which comes into force on 1 September 2026. The change follows a run of ransomware attacks on English primary and secondary schools, including Shottermill Junior School in Haslemere, Surrey, which the LockBit 5.0 ransomware group listed as a victim on 9 June 2026 after threat-intelligence monitors traced the initial network intrusion back to 20 May – roughly three weeks of undetected access before the attack became public.

The updated guidance requires schools to treat cyber incidents through the same lens as other safeguarding risks: a governance responsibility, not a task delegated entirely to an IT contractor. On 24 June 2026 the Department for Education also updated its Cyber Security Core Standard for schools and colleges, reflecting new technical requirements from the National Cyber Security Centre.

Why a data breach is also a physical safeguarding risk

The reclassification is not bureaucratic tidying. A ransomware attack on a school typically exposes safeguarding files, pupil premise data, medical information and, in some cases, access-control and CCTV system credentials – records that matter as much to physical safety as to data protection. Three weeks of undetected access inside a school network, as reportedly happened at Shottermill, is enough time for an attacker to map exactly which systems control site entry, visitor logging and alarm response before the school even knows it has been compromised.

This is the same convergence pattern we described when covering the NCSC’s warning that the UK faces four major cyber incidents a week: attackers who gain a foothold in a network do not stop at data. Where a school’s door-entry system, visitor sign-in, or CCTV platform is networked, a cyber incident and a physical security incident are no longer separate categories of risk.

What schools should check before 1 September

Ahead of the new academic year, school leaders and business managers should confirm three things sit within the same review, not separate ones. First, whether physical access-control and CCTV systems are on the same network as general school IT, and if so, whether they are properly segmented. Second, whether the school’s incident response plan for a cyber breach includes a step for reviewing whether physical security credentials were exposed. Third, whether school security staff and site managers are briefed to treat unusual access-control behaviour – doors unlocking unexpectedly, visitor logs behaving oddly – as a possible indicator of a wider network compromise, not just a maintenance fault.

Guidance from the Department for Education on Keeping Children Safe in Education and the NCSC’s schools cyber security guidance both set out the baseline expectations schools now need to meet before term starts.

Governors and multi-academy trust boards also have a role that is easy to overlook in the rush to patch systems. Keeping Children Safe in Education places the safeguarding duty on named individuals, and the 2026 edition expects those individuals to be able to describe, in plain terms, how a cyber incident would be detected, reported and escalated – not simply to confirm that an IT support contract exists. Schools that can give a short, current answer to “who would know, and how quickly” if door-entry or CCTV credentials were exposed are in a materially stronger position than those relying on the assumption that their IT provider already has it covered.

Need a security review?

Our team supports schools with site-security assessments that account for how physical and networked systems interact. Call us on 020 3700 0967, email info@secureonsitesecurity.co.uk, or visit our contact page. Related services:

Whatever a school’s IT budget covers, school cyber security now sits inside the same safeguarding conversation as the lock on the front gate – and from 1 September, the guidance says so explicitly.

Loading...
Share This