Who Is Responsible for Cyber Security Within Your School? A Guide for MATs & School Leaders
Schools house vast amounts of sensitive information, making them attractive targets for a cyber attack. In the UK Government’s 2025 Cyber Security Breaches Survey, it was reported that 44% of primary schools and 60% of secondary schools experienced a cyber security breach or attack. A successful attack can result in a data breach, financial loss, and disruption to teaching and learning, causing safeguarding concerns and reputational damage.
The Department for Education (DfE) has set clear expectations for cyber security in educational settings as part of its Digital and Technology Standards. Meeting this standard will help build cyber resilience and allow schools to react more effectively to cyber attacks and reduce operational downtime.
But within such a large setting, who is actually responsible for cyber security within your school? In short, it’s a shared responsibility, and different people have varying levels of accountability. Cyber security isn’t simply an IT issue; it’s something that senior leadership teams (SLT) and multi-academy trusts (MAT) must also take ownership of.
In this blog, our experts will guide you through why cyber security is critical for schools, the levels of responsibility, and how a cyber security partner can help meet the DfE’s standards.
Why Is Cyber Security Critical for Schools?
The DfE states that everyone in a school, including leaders, governors and trustees, has a responsibility to protect the school’s data in compliance with the standard and data protection law.
With schools holding so much sensitive data, they must treat cyber security as a leadership and governance priority, not just an issue for the IT department. Without the correct level of protection, cyber criminals could get access to:
- Pupil, Parent & Staff Information: Personal details such as their full names, addresses, emails and telephone numbers can make them targets for scams.
- Payroll & Financial Data: Financial information could be used by scammers for fraud or targeted phishing attacks.
- Safeguarding Records: A breach could expose already highly sensitive information about vulnerable individuals, putting them at further risk.
A cyber attack can take many forms; ransomware, compromised accounts, or network outages can disrupt education and affect:
- Teaching
- Access to systems
- Administration
- Payroll
- Communication with parents
- Safeguarding processes
As a result, schools can face significant financial and reputational consequences, such as:
- Recovery costs
- Potential regulatory consequences
- Lost staff time
- Reputational damage
- Loss of trust among parents and pupils
Cyber security protects much more than just a school’s computers; it protects operations and the school’s image, making it a critical part of its policies.

The True Cost of Maintaining Legacy Systems Goes Beyond IT Budgets
The cost of maintaining legacy systems extends beyond software licences or hardware repairs. It’s the hidden costs that tend to have the biggest impact on the bottom line:
- Employee inefficiency and lost productivity: Staff working with outdated interfaces spend more time on manual workarounds and duplicate data entry than on tasks that advance the business.
- Downtime: Legacy infrastructure is more prone to unplanned outages; when something fails, specialist knowledge is often scarce, and repairs take longer.
- Missed business opportunities: Hard-to-integrate systems make it difficult to launch new products or respond to competitors who are moving faster on newer platforms.
- Delayed innovation: IT teams stretched thin on maintenance have less time and budget left for strategic projects, such as AI adoption, automation, and better analytics.
Who Is Responsible for Cyber Security Within Your School?
Cyber security is a shared responsibility between everyone at the school. In short, school leaders, governors and trustees are responsible for governance and oversight, while SLT and IT manage and implement the practical measures. Here’s a breakdown of responsibilities for each role:
Headteacher / Principal
- Overall accountability for meeting the school’s cyber security requirements
- Ensuring cyber security receives appropriate leadership attention
- Making sure appropriate people and resources are available
- Ensuring there is an effective incident response process
- Coordinating with governors and trustees and relevant specialists during an incident
- Preparing statements or letters for the media, parents and pupils in the event of an attack
Governors & Trustees
- Understand the school’s cyber risk
- Challenge and scrutinise leadership
- Ensure appropriate policies and processes exist
- Make sure cyber security is incorporated into business continuity planning
- Ensure appropriate resources are available
Designated Safeguarding Lead
- Identifying if there is a safeguarding issue due to the incident
- Considering referrals to relevant safeguarding services e.g. social services
Data Protection Officer (DPO)
- Liaising with the headteacher and governors to determine if the incident needs to be reported to the ICO
SLT Digital Lead
- Coordinating cyber security activity
- Maintaining policies
- Working with IT support
- Coordinating cyber awareness training
- Overseeing risk assessments
- Leading or coordinating incident response
IT Team / External IT Provider
- Verifying successful system backups
- Restoring backups and advising on data loss
- Discussing potential costs of repairing, patching or buying hardware
- Advising on downtime and affected systems
- Protecting unaffected records
If your school is currently without an IT expert, get in touch with the team to find out how we can support you.

Who Is Responsible for Cyber Security in MATs?
For MATs, cyber security can become more complex due to the responsibility being shared between trust-level and academy-level teams. This affects those in roles such as:
- Trust leadership
- Trustee
- Central IT/digital teams
- Individual school leadership
- Academy-level digital leads
- External IT providers
The key differences lie with the trust and academy-level responsibilities. Let’s break these down for MATs.
Trust-Level Responsibilities
Those who have trust-level responsibilities, such as trustees and trust leadership, will need to take ownership of the following:
- Setting organisation-wide cyber security policies
- Establishing minimum security standards
- Coordinating risk management
- Ensuring consistent security across academies
- Centralising expertise where appropriate
- Managing trust-wide incident response
- Understanding interconnected risks
Academy-Level Responsibilities
Although the tasks vary, academy-level teams still need to understand cyber security and ensure policies are being implemented by carrying out the following actions:
- Follow trust policies
- Understand their local risks
- Ensure staff know reporting procedures
- Maintain appropriate awareness and training
- Escalate incidents
- Work with central IT/trust teams
Centralising technical services can provide greater consistency and make it simpler to ensure security. However, this doesn’t mean that academy-level staff no longer hold accountability for ensuring school records and information are safe and secure.
What Happens If Your IT Is Outsourced?
It’s a common assumption that if schools outsource their IT, their responsibility is covered; however, it doesn’t transfer the school’s overall accountability. To make the most of your outsourced IT, schools should establish:
- Who owns cyber security governance
- What the IT provider is responsible for
- Who responds to incidents
- Who handles safeguarding implications
- Who communicates with parents and staff
- Who reports to governors and trustees
- What happens outside normal IT support hours
- How often incident response plans are tested

Knowing Your Cyber Security Responsibilities
So, how can schools ensure each staff member, no matter their department or level of responsibility, knows exactly what their role is to help prevent and minimise the damage of a cyber attack?
Here’s our checklist with the steps you can take to ensure your staff are aware of and trained in their responsibilities:
- Assign clear ownership
- Document roles and responsibilities
- Carry out an annual cyber risk assessment
- Review cyber risks every term
- Create a cyber incident response plan
- Train staff regularly
- Test your response plan
- Review your IT provider’s responsibilities
- Keep governors/trustees informed
- Review and update policies regularly
How Net Consulting Can Support Your School’s Cyber Security
Partnering with an external IT cyber security provider allows them to become an extension of your school’s existing team, rather than transferring responsibility.
At Net Consulting, our team has supported several organisations in the education sector in improving their cyber security; read about our work with Sheffield Hallam University.
If you want to feel more confident in your school’s cyber security, get in touch with us today to start implementing advanced security measures that actually protect your data.





