A fantastic Cyber Security Breaches Survey 2025: What Schools Need To Know event from Secure Schools this morning! Some real food for thought! 𝐈'𝐥𝐥 𝐥𝐞𝐚𝐯𝐞 𝐬𝐨𝐦𝐞 𝐥𝐢𝐧𝐤𝐬 𝐢𝐧 𝐭𝐡𝐞 𝐜𝐨𝐦𝐦𝐞𝐧𝐭𝐬 The Cyber Security Breaches Survey 2025 has once again made it clear UK schools and colleges are in the firing line. But what’s changing is how we're talking about it. Cyber risks are growing, and yet budget, licensing, and policy decisions are holding back progress, especially when it comes to Multi-Factor Authentication (MFA). No phones, no MFA? Many schools banning phones are finding themselves stuck, especially for student accounts. Alternatives like YubiKeys, QR badges, and Conditional Access exist, but they cost. And even those aren’t bulletproof. Conditional Access ≠ compliance – It’s becoming clear that relying on location-based MFA exemptions won’t cut it for Cyber Essentials for much longer. Attackers don’t wait until you’re offsite. Licences matter Microsoft A3/A5 unlock essential security features like Conditional Access and TAPs. But most schools are stuck on A1, and funding remains a barrier. Not all schools/colleges use the Microsoft platform No silver bullet, YubiKeys can be lost, cloned, or underutilised. SMS isn’t ideal. Training, planning, and layered defences still matter most. The real problem? A lack of central support. There's a strong appetite for DfE or local authority-negotiated tools, bundled at reduced cost. This could lift the burden and improve adoption Free resources do exist, including NCSC's Active Cyber Defence tools and LGfL’s Elevate Toolkit but many schools aren’t aware or supported enough to use them effectively. This conversation shows just how complex cyber security is becoming in education. What’s needed isn’t just awareness, but leadership, funding, and practical support at every level from classrooms to governors. Full survey: https://lnkd.in/eYTB-Gvt Tools mentioned: https://lnkd.in/ekVa89R3 | https://lnkd.in/esjJ_Wdf #CyberSecurity #EdTech #CyberEssentials #Microsoft365 #EducationSecurity #MFA #UKSchools #DigitalStrategy
Cyber Security Breaches Survey 2025 (Full) https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025 Cyber Security Breaches Survey 2025: Education Institutions Findings https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025-education-institutions-findings NCSC Active Cyber Defence (ACD) Tools & Services https://www.ncsc.gov.uk/section/active-cyber-defence/services IASME Cyber Essentials Readiness Tool https://iasme.co.uk/cyber-essentials/cesp-readiness-tool/ LGfL Elevate Cyber Security Toolkit https://lgfl.net/services/security/elevate Cyber Essentials Misconceptions for Schools (Secure Schools blog) https://www.secureschools.com/en-gb/blog/five-common-cyber-essentials-misconceptions-for-schools
I think your point about licenses is really important - a lot of schools I speak to simply don't have the licenses they need to implement the appropriate security and access. Going for what they think they can afford rather than what they need perhaps, or not understanding the black art of Microsoft licensing? Why do you think this is?
Thanks, Mark! We're glad you enjoyed the session.
IT Manager | Microsoft 365 & Entra ID | 20 + Years in IT Operations, Identity & Access | Project Delivery & PM | Networking & Switch Management | Author | Content Creator | Freelance
5moCyber Score Tool (Secure Schools) https://www.secureschools.com/en-gb/blog/introducing-cyber-score NCSC School Governor Cyber Questions https://www.ncsc.gov.uk/information/school-governor-questions Digital and Technology Standards for Schools – Cyber Security https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/cyber-security-standards-for-schools-and-colleges Email Security Check – IASME (NCSC tool example) https://checkcybersecurity.service.ncsc.gov.uk/email-security-check/results?domain=iasme.co.uk 2FA/MFA in Schools – CyberTec Security https://kb.cybertecsecurity.com/books/2famfa-in-school YubiKey Cloning Vulnerability (Ars Technica) https://arstechnica.com/security/2023/10/yubikeys-are-vulnerable-to-cloning-attacks-thanks-to-newly-discovered-side-channel/