Penetration Testing for Schools: What It Is and When to Do It

by Rebecca Sutton

Penetration testing for schools means paying a qualified tester to attack your network the way a real intruder would, then reporting what they got into and how to fix it. The Department for Education does not require it. Even so, it is the quickest way to find out whether your own controls hold up, and the odds are that your most capable adversary is already inside the building: a student with a laptop and some curiosity.

Students with laptops in a classroom, the kind of network penetration testing for schools examines

What does the DfE actually require?

The DfE cyber security standards for schools and colleges list seven expectations. They cover risk assessment, staff and pupil awareness, firewalls and anti-malware, account controls, patching, backups and incident reporting. Penetration testing for schools is not on the list.

The DfE cyber security hub says schools should be working towards meeting these expectations by 2030, so they are a target rather than an overnight mandate. They are also a floor. They tell you which controls to have, yet they do not prove those controls work.

That gap is where a penetration test fits. The standards ask, for example, that multi-factor authentication is enabled for staff accounts with access to cloud services, and that critical fixes land within 14 days. A tester can check whether that is true in practice, not just on paper.

What is penetration testing for schools?

A penetration test is a controlled, authorised attack. The tester agrees a scope with you first, then looks for weaknesses in the systems inside it. They try to exploit what they find, so you see real impact instead of a list of theoretical flaws.

For a school, the scope usually includes some mix of the following:

  • The internal network that staff and pupils use, including Wi-Fi.
  • Internet-facing systems such as the website, remote access and email.
  • Cloud services like Microsoft 365 or Google Workspace.
  • The management information system that holds pupil records.

The output is a written report. A good one explains each finding in plain English, rates its risk and says how to fix it.

Why are schools a realistic target?

Schools hold sensitive data about children and families, and they often run lean IT teams. That is a tough mix, but the threat is also not only external.

The Information Commissioner’s Office reviewed 215 insider data breach reports from the education sector between January 2022 and August 2024. It found students were behind 57% of them, and 97% of the breaches linked to stolen login details. Nearly a third of insider attacks involved students guessing weak passwords or finding them written down, according to coverage of the ICO report.

The same review blamed other causes too. Weak data protection, such as devices left logged in, accounted for over 23% of breaches. Staff sending data to personal devices made up 20%, and misconfigured systems, such as wrong permissions on shared folders, caused 17%.

These are exactly the weaknesses a tester looks for. So weak passwords, over-generous permissions and poorly segmented networks show up in school tests again and again, so it makes sense to find them before a Year 11 does.

What is the difference between a penetration test and a risk assessment?

The DfE standards ask schools to complete a cyber risk assessment every year and review it each term. The assessment is a structured look at assets, threats and gaps. Our guide on what a cyber security risk assessment involves covers how that works.

Penetration testing for schools is the practical follow-up. The risk assessment tells you where you think the danger lies, while the test tells you whether an attacker can really get through. Used together, they give governors and trustees evidence rather than assurance by opinion.

What can penetration testing for schools find?

Every school differs, but typical findings include:

  • Weak or reused passwords on staff, pupil or service accounts.
  • Flat networks where a pupil device can reach servers it should never see.
  • Missing patches on servers, firewalls and older classroom equipment.
  • Excess access, such as shared drives open to every user.
  • Insecure IoT and legacy devices, from printers to door systems.

The DfE standards say all network-connected devices, including internet of things devices, should be securely configured, kept up to date and protected by firewalls. If any of that has slipped, a test will show where.

How does it fit with Cyber Essentials?

Many schools work towards Cyber Essentials, the government-backed certification that the NCSC lists among its school resources. It checks that basic controls exist, whereas a penetration test goes deeper by attacking those controls. If you want the detail, we explain how Cyber Essentials and penetration testing differ and how they complement each other.

How should a school prepare for a test?

Because preparation keeps the test safe and the results useful, start with these steps:

  1. Decide what matters most, such as pupil records or the finance system.
  2. Agree the scope and timing in writing, and avoid exam periods.
  3. Tell the people who need to know, including your DPO and senior leaders.
  4. Check who holds permission for any third-party hosted systems.
  5. Plan who will fix findings, and by when.

After that, ask for a retest once fixes are in. A retest confirms that the issue is closed, which is the evidence trustees and insurers want to see.

How can penetration testing for schools fit a tight budget?

Start small, and test the highest-risk area first, usually the internal network or the systems that hold pupil data. But do the basics too. The NCSC offers free school resources, including Exercise in a Box for rehearsing an incident, a cyber governance toolkit for boards and a free online check of public-facing IT. Those free tools are a sound foundation before you commission anything.

When you are ready for a proper test, our team can scope one around a school’s size and budget. You can read about our penetration testing services or get in touch for a conversation about what would suit your site.

What should you look for in a tester?

Choose a provider that explains its approach before you sign. Ask who will do the work and what experience they have with education networks. Ask how they handle pupil data they come across, and how they will report a serious finding mid-test rather than at the end.

Look at a sample report too. If you cannot follow it, your governors will not either. Also check that the quote covers a retest, because fixing issues is the point of the exercise.

Finally, be wary of anyone who promises that a test makes you unhackable. It does not. A test gives you a snapshot, so the real value comes from acting on it.

Frequently asked questions

Is penetration testing for schools mandatory?

No. The DfE standards do not require one. It is a way to check the standards are working.

How often should penetration testing for schools happen?

A common approach is annually, or after a major change such as a new network or cloud migration. Match the cycle to your yearly risk assessment.

Will a test disrupt lessons?

It should not. Testers agree timing and safe limits up front, and they can work outside teaching hours.

Who should read the report?

Your IT lead, the senior leadership team and the trustee or governor responsible for risk. Plain language findings help non-technical readers act on them.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like