Penetration Testing for Schools: What UK Trusts Actually Need

by Rebecca Sutton

Penetration testing for schools is a scoped, authorised attempt to break into a school or academy trust’s IT systems. A real attacker would try the same routes in. The tester then reports exactly what worked, so it can be fixed. This is not the same as the Cyber Essentials questionnaire. It is not the same as the annual risk assessment your business manager already files. Whether your school needs one depends less on a single rule. It depends more on what you actually run: a management information system holding safeguarding data, a finance platform, and a growing list of cloud services.

Most schools assume compliance covers this ground already. It mostly does not. The Department for Education’s digital and technology standards set a baseline for accounts, patching and backups. They stop short of requiring anyone to actually try to break in.

Hands typing on a laptop keyboard while running penetration testing for schools checks

What does penetration testing for schools actually cover?

A typical scope for penetration testing for schools splits into a handful of areas. These matter to a school specifically, not to a generic office network:

  • The pupil-facing network, and whether a device on it can reach staff systems, the MIS, or finance software.
  • Remote access used by staff and IT support providers, including VPNs and remote desktop tools.
  • Cloud platforms such as Microsoft 365 or Google Workspace for Education, where most staff email and shared data now lives.
  • The management information system itself (SIMS, Arbor, Bromcom and similar), since it holds safeguarding records alongside attendance and grades.
  • Guest and BYOD wifi, which is often set up quickly and reviewed rarely.
  • Any internet-facing services the school or trust runs directly, such as a parent portal or booking system.

A good tester maps this against what would actually hurt if it failed. That matters more than what is easiest to scan. A weak guest wifi password matters far less than a guest network that can reach the server holding pupil records.

Do the DfE cyber security standards require penetration testing?

Not explicitly. The DfE’s cyber security core standard is part of the wider digital and technology standards. Schools and colleges are expected to meet these by 2030. The standard covers specific controls. Staff need multi-factor authentication for cloud or remote access. Admin accounts must stay separate from day-to-day email. Critical and high-severity flaws need a patch within 14 days. Backups must follow a 3-2-1 pattern: three copies, on two devices, with one kept off-site. Penetration testing and vulnerability scanning are not named as distinct rules.

Funding rules pull in a different direction. An ESFA update told colleges they must achieve Cyber Essentials during the 2024 to 2025 funding year. At the same time, the old rule for an annual IT health check was dropped. For colleges, then, formal testing went from a funding rule to no rule at all. Schools proper are not bound by the same wording. Cyber Essentials sits more as an expectation than a rule. Even so, many trusts pursue Cyber Essentials Plus anyway, to satisfy governors, insurers or a local authority.

The practical result is a gap. A school can meet every DfE standard and hold Cyber Essentials without anyone ever having tried to get into its network. Compliance proves the controls exist on paper. Only penetration testing proves whether they hold up against someone trying to get past them.

Why schools keep getting hit anyway

The government’s Cyber security breaches survey for 2025/2026 puts the scale of this in context. Across the past year, 49% of primary schools and 73% of secondary schools identified a breach or attack. That figure rises to 88% among FE colleges and 98% among universities. Take-up of penetration testing for schools tracks the same curve, but in reverse. Only 23% of primary schools and 38% of secondary schools had commissioned one. For FE colleges the figure was 52%. For universities it was 84%. Smaller schools are being hit just as often, proportionally. They are simply being tested the least.

Real incidents show why that gap is expensive. In September 2024, the Rhysida ransomware group breached Fylde Coast Academy Trust in Blackpool. Systems were encrypted across all ten of its schools, and the gang demanded £1.2 million while threatening to leak stolen data. Full restoration took weeks, so staff fell back on paper registers and mobile data to keep classrooms running. More recently, threat intelligence trackers recorded LockBit 5.0 listing Shottermill Junior School in Haslemere, Surrey as a victim in June 2026. Initial access appears to date back roughly three weeks before that listing appeared. That kind of dwell time gives an attacker plenty of chance to map exactly which systems matter, well before anyone notices.

Academy trusts now carry an added incentive to prevent this rather than manage it afterwards. Under the Academy Trust Handbook 2025, which took effect in September 2025, trusts must not pay cyber ransom demands at all. That tightens the previous rule, which only required ESFA’s consent before paying. If negotiation is off the table, prevention and a tested recovery plan are what is left.

What a decent school pentest report should tell you

Good penetration testing for schools produces findings that map to what the DfE standards, and your safeguarding duties, actually depend on. Look for a report ranked by real impact, not a raw vulnerability count:

  • Whether the pupil network can reach the MIS, finance system or staff shares, and by what route.
  • Whether stale or shared admin accounts exist outside the dedicated accounts the DfE standard calls for.
  • How exposed remote access and any VPN really are to credential guessing or known flaws.
  • Whether cloud email and file storage enforce MFA consistently, not just for a subset of accounts.
  • Clear, prioritised remediation steps a small IT team can actually action, not a 200-page dump of raw scanner output.

Ask any penetration testing for schools provider how findings map to the DfE standards before you commission the work. A trust with limited IT capacity gets far more value from three fixed high-risk issues. A long list of low-priority noise just wastes time nobody has.

How often should a school or trust run penetration testing for schools?

Annually is a sensible baseline. Time it to sit alongside the DfE-recommended termly review of your risk assessment. Retest sooner after any major change: a new MIS migration, a switch in remote access provider, or a new site joining a growing trust. A trust absorbing several schools at once faces a particular risk. Sites often get merged onto a shared network faster than the segmentation between them gets checked. That “enforced integration” pattern, though, has been linked to recent multi-school incidents.

Frequently asked questions

Do primary schools need penetration testing, or is this only for large trusts?

Size matters less than what you hold. A single-form-entry primary with an MIS full of safeguarding data, and a finance system processing parent payments, has plenty worth protecting. That holds even if its IT budget is tiny compared with a ten-school trust.

If we already have Cyber Essentials, do we still need penetration testing?

Cyber Essentials checks a fixed set of baseline controls through a self-assessment or, for Plus, an external verification. Penetration testing goes further. It actively tries to chain weaknesses together the way a real attacker would, rather than just confirming boxes are ticked.

What’s the difference between this and the old IT health check?

An IT health check was typically a narrower, compliance-driven scan, sometimes automated, run to satisfy a specific requirement. That’s quite different from a genuine manual penetration test. A manual test is scoped to your actual systems, and aims to show real-world impact rather than list generic findings.

Who should commission it: the school, the trust, or the local authority?

Whoever owns the risk should own the decision. Most academy trusts commission penetration testing for schools centrally, across every site, for consistency and cost. Maintained schools more often work through their local authority’s IT support arrangement, or commission directly.

How much should we budget?

Cost depends on the number of sites, systems in scope and network complexity. It is worth getting quotes scoped against your actual estate, rather than a generic price list. Our guide on how to choose a penetration testing company covers the red flags worth checking before you sign anything. A trust running several schools on a shared network typically pays more than a single site. It also gets more value, though, from testing the segmentation between them.

Penetration testing for schools won’t stop every attack on its own, and no honest provider will claim otherwise. It shows you, before an attacker does, whether your network segmentation, admin access and cloud accounts actually hold up. For a school weighing up whether to commission one, that is the real question. It is not whether you are compliant, but whether you have actually checked.

Aardwolf Security runs penetration tests scoped to education-sector networks, including MIS, cloud platforms and multi-site trust segmentation. If you’re weighing up a first test, or a retest after a network change, get in touch for a scope built around what your school or trust actually runs.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like