Good news, then. Read the rest of the survey, though, and you find that most teachers don't know what their school changed to get there, and they can't agree on who's in charge. Anyone running a Windows estate, a Microsoft 365 tenant or a stack of shared student laptops will recognise that problem.
What Ofqual actually measured
This is a poll, not a forensic audit. Ofqual's notes to editors say percentages referring to teachers are based on a sample of 3,775 secondary teachers in England. Where percentages refer to schools, responses were limited to one per school, selecting the most senior teacher. This resulted in a sample representing up to 2,162 schools. Teacher Tapp ran the poll, on behalf of Ofqual, on 13 July 2026. It is its third annual survey covering the 2025 to 2026 academic year, and it was released for Cyber Security Awareness Month.
The Register's report adds the incident details:
- Phishing was the most common incident type, followed by data protection breaches, hacking and ransomware.
- Ransomware affected 2% of respondents.
- Staff data was the information most often compromised. Student data was affected in 13% of incidents and student work in 1%.
- Recovery: besides the 66% who recovered "immediately", 12% recovered within half a term (roughly six or seven weeks), 1% took longer than half a term and another 1% needed at least a full term.
- "Critical damage" fell from 10% to 7% of reported incidents.
That last figure needs care. The Register says Ofqual did not define "critical damage" and told the publication that respondents could interpret it however they liked. Ofqual also couldn't say what caused the improvement. So the regulator has a better scoreboard but no explanation for it.
Section summary: Fewer reported incidents and faster recovery are real survey results. They are self-reported, the key terms are loosely defined, and nobody has explained why things improved.
Three years of data, read properly
The trend looks more interesting next to last year's release. In September 2025, Ofqual's headline was that recovery was getting worse: only 55% of schools which experienced a cyber incident were able to recover immediately, compared to 63% the previous year. The same release said the severity of the impact was greater with 10% of schools reporting critical damage from attacks, up from 6% the year before.
| Academic year | Schools reporting an incident | Immediate recovery (of affected) | "Critical damage" |
|---|---|---|---|
| 2023/24 | 34% | 63% | 6% (per Ofqual's 2025 release) |
| 2024/25 | 29% | 55% | 10% |
| 2025/26 | 27% | 66% | 7% |
So this year's 66% isn't a breakthrough. It's a rebound, and only slightly above where schools were two years ago. The severity figure isn't consistent across reports either. Schools Week's coverage of the new data says critical damage from the attacks fell to 7 per cent, down from nine per cent two years ago. That matches 2024 reporting that nine per cent of heads said the attacks were "critically damaging", but not the 6% in Ofqual's own 2025 release. When the baseline changes depending on which document you read, any year-on-year severity trend should be treated with suspicion.
Section summary: The incident rate has fallen steadily for three years. Recovery dipped in 2024/25 and has now bounced back slightly past its 2023/24 level. The severity numbers are too loosely defined and too inconsistent to support firm conclusions.
The "I don't know" problem
The most telling figure for IT staff is that 54% of teachers answered "I don't know" when asked what cybersecurity improvements their school had made in the past year, according to The Register. Among the 46% who named at least one change:
- half said their school had introduced a cybersecurity policy
- 22% cited new or tested backup procedures
- 20% said an incident response plan had been completed or updated.
Ofqual's own framing is more upbeat: more than half of the secondary schools surveyed (55%) have already taken action to protect against cyber attacks. Measures include implementing a cyber security policy, carrying out risk assessments, and setting up backup and recovery procedures. The two readings fit together. The work may well be happening, but it isn't reaching the classroom. Policies and backup routines exist on a server somewhere, and many of the people most likely to click a phishing link haven't heard of them.
Responsibility is just as unclear. 46 percent say the IT team bears primary responsibility, 40 percent say it's shared among all staff, and only 9 percent point to senior leadership. Ofqual's position is direct: "Cyber security isn't just an IT problem; it's a leadership responsibility. Regular backups and a clear response plan can make a huge difference when things go wrong."
Mat Pullen, director of education at device-management vendor Jamf, told The Register the frequency and recovery figures were promising but called the confusion over responsibility a concern. He noted that attacks have closed schools for a week or longer in the past, and argued that security is shared between IT, teachers and senior leadership. Jamf sells to schools, so read that with its commercial interest in mind. The point itself is hard to argue with.
Section summary: Most teachers don't know what changed, and fewer than one in ten think leadership owns the problem. Ofqual is pushing hard against that view.
Training: more of it, not much effect
The training figures are the least encouraging part of the release. According to The Register, about a third of teachers said they had received no cybersecurity training in the past year or weren't sure whether they had, up from 28% the year before. A similar share said the training they did get wasn't useful. Of those who were trained, 65% said they changed nothing as a result.
Last year's release had been celebrating the opposite trend. The share of trained teachers had risen from 61% in 2023/24 to 72% in 2024/25, according to Ofqual's September 2025 release. So training coverage seems to have slipped back. Of all the numbers here, "65% changed nothing" deserves the most attention from whoever buys the training. A completed course that changes nobody's behaviour doesn't protect much.
Squaring this with the government's much scarier numbers
If 27% sounds low, it is, next to the UK government's Cyber Security Breaches Survey 2025/26, published in April. That survey found 73% of secondary schools, 88% of further education colleges and 98% of higher education institutions had identified breaches or attacks in the previous 12 months, along with 49% of primary schools. It also found the secondary school figure had risen significantly, from 60% in 2024/25.
These numbers don't contradict Ofqual's. The government survey counts any breach or attack that was identified, whether or not it succeeded. It covers the whole of the UK and every level of education. Ofqual asks teachers in England about "incidents", which is a narrower idea. Put together, the two surveys say schools are attacked constantly and most attempts don't turn into an incident teachers would notice. The government survey also found that 20% of secondary schools that identified a breach or attack reported negative effects on their systems.
The government data also gives some context on readiness, though none of it explains Ofqual's improvement. The share of secondary schools with a policy to apply security updates within 14 days rose from 56% to 62%. That was still the weakest of the Cyber Essentials technical controls across education. About 77% of secondary schools had run cybersecurity training or awareness sessions for staff outside security roles. Treat these as separate measures from separate samples, not as the reason for Ofqual's figures.
Section summary: The two surveys measure different things. Attacks are common, successful incidents are rarer, and patching is still the weakest of the basic controls.
Why "recovered immediately" isn't the whole story
Ofqual itself warns against reading recovery too optimistically. Executive director Amanda Swann said: "It's encouraging to see schools recovering faster, but a cyber breach can still cause real uncertainty for students if coursework or marks are lost, and staff confidence can be affected long after systems are back online." Last year she put it more bluntly, saying that schools and colleges experiencing cyber security incidents reported losing entire classes' coursework and facing weeks of disruption to teaching and learning.
Incidents still close schools. The Register points to June, when several schools in England and Wales shut temporarily while technicians investigated a malware scare. It also cites the Information Commissioner's Office's finding last year that students were behind more than half of the UK education sector cyberattacks attributed to a known actor. In other words, the attacker may be sitting in the classroom.
What school IT teams should take from this
The following is general good practice, not something Ofqual prescribes in detail, but it maps directly onto the survey's weak spots:
- Tell staff what you've done. If most teachers can't name a single improvement, a short termly note covering the policy, the backups and the response plan costs almost nothing.
- Test restores, not just backups. Swann said last year that schools that maintain current, accessible back-ups can restore systems more quickly and avoid ransomware demands. Coursework is the data people miss first, so include it in restore tests.
- Get the incident plan signed off by leadership. That puts on record who owns the problem, which only 9% of teachers currently believe is leadership.
- Close the patching gap. The government survey shows the 14-day patching policy is still the control schools most often lack.
- Measure training by what changes. If two-thirds of trained staff change nothing, judge the course by click rates on simulated phishing, not by how many people finished it.
- Plan for an insider. Given the ICO's finding about students, least-privilege access and separating student accounts from admin accounts are basic requirements.
The bottom line
England's secondary schools report fewer incidents and faster recovery, which is real progress worth acknowledging. But the improvement is self-reported, "critical damage" is undefined, and Ofqual can't say what caused it. Most teachers don't know what their school changed, and almost none think senior leadership owns the problem. Recovery has improved; making sure staff know the plan, and that leaders own it, is the next job.
References
- England's schools are getting better at mopping up cyber incidents The Register · 2026-10-01T11:40:13+00:00
- England's schools are getting better at mopping up cyber incidents daily.dev
- Schools show improved cyber training rates but recovery times slow - GOV.UK gov.uk