Why Phishing, Not Firewalls, Is Your School's Biggest Cyber Risk

Most school breaches don’t start with someone breaking through a firewall. They start with a member of staff signing in on a page that looked real.
By
Matthew Holt
September 4, 2026

The number that matters more than your firewall

Ask most school leaders what a cyber attack looks like, and they’ll picture someone breaking through a firewall. In practice, that’s rarely how it happens.

According to the government’s own Cyber Security Breaches Survey, phishing was identified as the cause in 90% of primary school breaches and 96% of secondary school breaches, consistent across the last two years of the survey. Not malware. Not a hacked firewall. Phishing.

Here’s why that distinction matters. A firewall is good at blocking unauthorised connections. It can’t tell the difference between an attacker and a genuine member of staff who’s signed in with a valid password and passed multi-factor authentication, because to the system, that’s exactly what’s happened.

A typical example: a member of your finance team receives an email that looks like a normal Microsoft 365 document share. They click through, sign in on a page that looks identical to the real one, and approve the MFA prompt without a second thought. From that point, the attacker isn’t breaking in. They’re logging in, using a genuine identity, doing things that look like normal use of the system, at least until something looks wrong.

That’s why the standard your school is working towards puts as much weight on people and identity as it does on technical defences.

What the DfE actually asks of your school

The cyber security core standard is one of six standards schools and colleges are expected to meet by 2030. Some parts of it, like having anti-malware and a firewall in place, you’re expected to already be meeting. Others, like the annual risk assessment, are things to build towards.

In plain terms, it asks your school to:

  • Carry out a cyber risk assessment every year, and revisit it every term, led by your SLT digital lead working with IT support and your data protection officer.
  • Train staff and students on cyber awareness at least annually, covering things like phishing, password security and multi-factor authentication, not just a slide deck once a year.
  • Secure your network with a properly configured firewall and centrally managed anti-malware software.
  • Control who has access to what, with multi-factor authentication required on all staff accounts that reach cloud services or remote access.
  • Back up your data properly, with at least three copies, on two different types of storage, one of them off-site.
  • Have a clear process for reporting a cyber incident, both internally and to the right external bodies.

None of this needs to happen overnight. But it does need a named person accountable for it, which the standard also asks for: your SLT digital lead.

Where we’d suggest starting

If you’re looking at that list wondering where to begin, start with the way your staff sign in.

Make sure multi-factor authentication (MFA) is protecting every staff account that accesses cloud services, with stronger protection such as security keys or passkeys for anyone with administrator access.

Then ask your IT support to check that older, less secure ways of signing in have been disabled, access from unfamiliar devices or locations is being challenged, and your email protection is configured to spot common phishing attempts.

Finally, make cyber awareness practical for staff. A fake invoice or an email appearing to come from the Headteacher is much more useful to practise spotting than another generic security presentation.

Why we’re leading with this, not with fear

We could have opened this article with worst-case scenarios. We haven’t, because that’s not how we work, and it’s not particularly useful either. The DfE’s standard exists so you have a clear, structured way to check where you stand, not so you spend the next year worrying about it.

If your school already has good MFA coverage and a firewall in place, that’s genuinely worth knowing, and we’ll tell you so. If there are gaps, we’d rather point them out plainly and help you close them in an order that makes sense for your budget, rather than recommending everything at once.

That’s the same approach we bring to every part of IT support: work out what’s actually protecting you, be honest about what isn’t, and fix things in the order that matters most.

Guidance referenced is current as of August 2026. DfE standards are updated periodically – always check GOV.UK for the latest version.

TL;DR: Phishing, not firewalls, causes most school cyber breaches (90% of primary, 96% of secondary, per the government’s own survey). The DfE’s cyber security standard expects an annual risk assessment, staff training, secure accounts with MFA, proper backups and a clear reporting process, working towards full compliance by 2030. We’d start with phishing-resistant MFA before anything else.

Get in Touch with ekte

We're here to support your broadband needs—reach out for expert advice and assistance today.