Six out of 10 secondary schools in the UK have suffered a cyber-attack or security breach over the past 12 months, according to a government survey. The figure rises to eight out of 10 for further education colleges and nine out of 10 for higher education institutions, making the education sector more likely to face attacks than private businesses, where four out of 10 reported breaches.
Phishing emails were the most common form of attack, and ransomware incidents have become well known. Attackers typically encrypt systems and steal data, demanding payment in bitcoin. Recent examples include a ransomware attack on West Lothian council's education network and attacks on Newcastle University, the University of Manchester and the University of Wolverhampton.
Toby Lewis, global head of threat analysis at Darktrace, said the education sector is not necessarily being targeted deliberately but is caught in a dragnet of cybercrime. He noted that state schools may be more vulnerable due to funding pressures and lack of specialist expertise, while universities have many young students who may not be cyber security literate.
Pepe Di'lasio, general secretary of the Association of School and College Leaders, called ransomware a 'major risk' and said substantial work is ongoing to protect systems. James Bowen of the National Association of Head Teachers said additional government funding to help spot and respond to threats would be welcome.
The Department for Education said it takes cybersecurity seriously and has a dedicated team for responding to incidents, working with the National Cyber Security Centre to offer free training. Meanwhile, ministers are preparing to ban schools, the NHS and local councils from making ransomware payments under new proposals to tackle hackers.



