top of page
Search

DfE Cyber Security Standards: A School Business Manager's Checklist

  • Jun 30
  • 4 min read

If you're a school business manager, bursar, or office manager who's just been told "cyber security is now part of your job," you're not alone. The Department for Education's digital and technology standards make cyber security a shared responsibility across the senior leadership team — not something that sits quietly with whoever does IT on a Tuesday afternoon.


The trouble is that the official guidance is thorough, but it's written for people who already know what a firewall does. This post strips it back into a working checklist you can actually take to a leadership meeting or governors' update.



Why this has landed on your desk

Cyber security standards are one of six core digital and technology standards the DfE expects every school and college to be working towards by 2030. They sit alongside standards for broadband, wireless networks, network switches, filtering and monitoring, and digital leadership — and like the others, they're not just an IT problem. The DfE is explicit that meeting the standard depends on the senior leadership team, business professionals, the designated safeguarding lead, the data protection officer and IT support all playing a part, not IT working in isolation.

That's why, increasingly, it's the SBM who ends up coordinating the paper trail: pulling together evidence for governors, briefing auditors, and chasing IT support (internal or outsourced) to confirm what's actually in place.

The checklist

Use this as a working document rather than a one-off tick-list — most of these need revisiting annually, and some termly.

1. Risk assessment Has a cyber risk assessment been carried out in the last 12 months? It should be repeated annually as a minimum, and sooner if there's a significant change to your systems, a near miss, or a confirmed incident. Findings need to be reported to governors or trustees as part of normal risk management, not filed and forgotten.

2. Multi-factor authentication (MFA) Is MFA switched on for every account with access to personal, financial or sensitive data — including senior leaders, finance staff, and anyone in IT support, internal or external? This now extends to cloud services such as your MIS, email platform and safeguarding tools, not just on-site logins.

3. Password policy Where MFA genuinely can't be used, is there a documented policy requiring stronger passwords in its place? Has this been communicated to staff, not just written down somewhere?

4. Firewalls and device security Is every device on the network — including staff laptops used at home and any BYOD devices in scope — sitting behind a properly configured firewall? Are firewall logs actually being checked, not just collected?

5. Patching and updates Is there a defined process (and timescale) for applying security updates, and is it being followed in practice? The expectation has tightened recently: delays in applying critical or high-risk patches are no longer treated as acceptable, so "we'll get to it" isn't a process.

6. Backups Do you have a documented, reviewed backup plan covering all your data — including anything held in cloud services? You need to know what's backed up, how often, how it would be restored, and how long you could realistically operate without each system in a worst-case scenario. This should sit in your information asset register, alongside what data you hold and why.

7. User account management Is there a clear process — agreed between HR/business professionals and IT — for creating and removing accounts as staff join, leave, or change role? Stale accounts belonging to people who left two terms ago are a common and entirely avoidable weakness.

8. Staff training Has everyone with network access completed basic cyber security training in the last year, including new starters as part of induction? It should cover phishing, password habits, social engineering and the risks of removable media — and it needs repeating, not done once and ticked off forever.

9. Cyber response plan Is there a written response plan for a cyber incident, sitting within your business continuity and disaster recovery plan? If you hold Risk Protection Arrangement (RPA) cover, this isn't optional — it's a condition of cover.

10. Reporting routes Does everyone involved know who to contact if something goes wrong? Incidents and near misses should be logged internally, and confirmed breaches reported to Action Fraud, the DfE's sector cyber team, and — where there's a high-risk data breach — the ICO within 72 hours.

11. Cyber Essentials Cyber Essentials certification is a condition of funding for colleges and special post-16 institutions. It's not currently mandatory for schools, but it maps closely onto several of the standards above and is increasingly treated as a baseline expectation by trustees, auditors and insurers alike.

What "good" looks like at governor level

Governors and trustees don't need the technical detail — they need assurance. In practice, that means being able to answer three questions confidently at any point in the year: when was risk last assessed, what would happen if a key system went down tomorrow, and who is responsible for each item on the list above. If those answers take more than a phone call to find, that's usually the first thing worth fixing.

Where this gets difficult without dedicated IT support

Most of this checklist is straightforward to state and genuinely hard to maintain without someone keeping it current — patch levels change weekly, staff turnover affects account management constantly, and backup configurations drift if nobody's watching them. For schools without an in-house IT team, this is exactly the gap a managed IT support partner is meant to fill: not just fixing things when they break, but keeping the evidence trail current so you're never scrambling before an audit or governors' meeting.

DCAD works with nurseries, primary and secondary schools, academies and trusts across Hertfordshire and Essex, helping business managers meet the DfE standards without needing to become cyber security experts themselves. If you'd like a straightforward review of where your school currently stands against this checklist,

get in touch for a free consultation.

 
 

Recent Posts

See All
bottom of page