Select Your Cookie Preferences

We use cookies and similar tools that are necessary to enable you to use our website, to enhance your experience, and provide our services, as detailed in our Cookie Notice. We also use these cookies to understand how customers use our services (for example, by measuring site visits) so we can make improvements.

With your consent, we and our partners may use personal data (like browsing behaviour or unique IDs) for ads personalisation, content measurement, and audience insights. Click "Customise Cookies" if you'd prefer to decline these cookies, make more detailed choices, or learn more. Learn how Google uses your data

Customise Cookies

Computeam Secure

Cyber Essentials for Schools and MATs

Cyber Essentials is the UK government's baseline cybersecurity certification, backed by the National Cyber Security Centre (NCSC).

Book a Cyber Security Audit

Alongside the critical task of protecting school and MAT networks against ransomware, malware, and data breaches, Cyber Essentials increasingly appears in tenders and insurance requirements.

It also complements the DfE cyber security standard that every school and college is expected to meet by 2030; and gives leadership a clear, structured starting point for a subject that can otherwise feel overwhelming.

Computeam supports schools and trusts through the entire journey – a Cyber Security Audit to establish your baseline, a prioritised plan to close the gaps and hands-on support towards certification, delivered by a dedicated, education-only cyber security team.

Find out where your school stands

Our Cyber Security Audit measures your current position against the DfE cyber security standard and Cyber Essentials, then gives you a clear, prioritised plan.

Book a Cyber Security Audit

Hear from the cyber security expert

Brad Biddle, our Head of Cyber Security, answers the questions school leaders ask most.

Cyber Essentials FAQs

What is Cyber Essentials?

Cyber Essentials is an entry-level cybersecurity standard backed by the NCSC. The standard itself is free to read and follow; certification, which involves an annual assessment, carries a cost. There are two levels:

Level one

Cyber Essentials

Cyber Essentials is a verified self-assessment. Your school answers a question set covering the five controls, signed off at board or trust level, and an assessor reviews the responses.

Level two

Cyber Essentials Plus

Cyber Essentials Plus covers the same requirements but adds an independent technical audit, including device testing and a vulnerability scan, to prove the controls are working in practice.

The scheme itself was written for organisations of all kinds, not schools specifically, so the language and scope can often feel broad. Here is a key reason why schools benefit from working with an education specialist who can translate the requirements into a school context.

Start with the DfE digital and technology standards, then Cyber Essentials

The DfE's cybersecurity standard is written specifically for schools and colleges, and the DfE expects every institution to meet its six core digital and technology standards by 2030.

The digital standard is the right baseline to establish first. Cyber Essentials then builds on it, with more structure around technical controls and networks, and a certificate you can show to insurers, tender panels and your governing body. The two frameworks overlap and work in tandem; succeeding in one accelerates compliance with the other.

Computeam Compass

If you are working towards the DfE standards, Compass helps schools and trusts track, manage and evidence their progress, while our audit services benchmark where you are today.

Start a free 30-day trial

The five controls, and where schools typically meet challenges

Control What it covers

Where schools commonly struggle

Firewalls

The boundary between your network and the internet, blocking malicious connections.

Confusing firewalls with filtering. Filtering protects users from harmful content; the firewall protects the network itself.
Secure
Configuration

Removing default passwords, unnecessary software and insecure settings.

Shared and year-group logins with weak passwords. These make it impossible to trace filtering incidents and pose a safeguarding and security risk.

Security update management

Applying security updates promptly across devices and software.

End-of-life devices and old operating systems are kept in service to stretch budgets, leaving known vulnerabilities unpatched.
User access
control
Giving staff and pupils only the access they need, with MFA on accounts.

Patchy MFA rollout and too many accounts with admin rights. Least privilege should be the default.

Malware
protection

Protecting devices from malicious software.

Relying on traditional, signature-based antivirus. Modern attacks use genuine software such as Word or Microsoft 365 tools, so behaviour-based protection is needed.

Why schools need Cyber Essentials

Schools are an attractive target for cyber criminals. They hold large volumes of sensitive, regulated data about pupils, families and staff, and they typically run the user numbers of a large organisation on the budget of a much smaller one. Staff are stretched, training time is scarce, and attackers know it.

The threats themselves are getting harder to spot

Phishing remains the number one attack route into schools, and AI has made phishing emails look and read more convincingly than ever. Criminal groups now buy and sell services to one another, and social engineering has moved beyond email to phone- and voice-based attacks. The 2025 attacks on M&S, Harrods and Jaguar Land Rover all began with phone-based social engineering. Anyone can be targeted, from a teaching assistant to a headteacher.

The consequences of getting caught out are severe 

A successful ransomware attack can take a school completely offline: digital registers, cashless catering, email, teaching resources and finance systems all stop working, while pupil and staff data is held to ransom or sold. Recovery without reliable backups can mean rebuilding accounts, systems and data from scratch.

In practice, most schools come to Cyber Essentials through one of four routes: a governor or trustee raising the question, an incident or near miss, an insurance requirement, or a tender that requires certification as standard. Whatever the prompt, the scheme gives you a recognised framework for getting the basics right and proving it.

Cyber Essentials or Cyber Essentials Plus?

For most schools, the sensible pathway is: DfE cyber security standard first, then Cyber Essentials, then Cyber Essentials Plus. MATs should note that certification sits at trust level; the trust is the member, and that is what insurers look at.

Cyber Essentials

Cyber Essentials Plus

Assessment

Verified self-assessment question set, signed off at board or trust level.

The same requirements, plus an independent technical audit.

Evidence

Your answers describe what is in place.

An auditor checks it is working in practice: screen-shared walkthroughs, a sample of devices tested, and a vulnerability scan with 14 days to fix any findings.

Disruption

Minimal; mainly the time of the person completing it.

Manageable. It is demanding for the person running the process, but not disruptive for the wider school.

Best suited to Establishing and evidencing the baseline.

Schools and trusts that need a higher level of assurance, often for insurance, tenders or trust-wide governance.

Cyber Essentials focuses on networks and devices. It does not cover everything, cloud security in depth or physical security, for example, which is where a broader audit and individual recommendations add real value.

Scheme update

How did Cyber Essentials change in April 2026?

The scheme was updated on 27 April 2026, with a new question set (Danzell) and revised requirements (v3.3). The headline changes for schools:

1

MFA is now mandatory for all cloud services where it is available. Previously advisory; now an automatic fail if missing.

2

Critical and high-risk security updates must be applied within 14 days of release, including router and firewall firmware, again with automatic failure for non-compliance.

3

Cloud services cannot be excluded from scope, and scoping questions are more detailed, so schools need a clear picture of every cloud service that stores or processes their data.

4

A board-level declaration now confirms responsibility for maintaining the controls throughout the certification period.

5

Cyber Essentials Plus testing is stricter, with re-testing across new device samples to prevent fixes being applied only to the machines being checked.

There is also a growing emphasis on passwordless authentication, including passkeys, as the direction of travel. Certification increasingly rewards security that is inherently embedded in day-to-day operations, not applied temporarily for an assessment.

For schools renewing or certifying for the first time, MFA coverage and patching discipline are the two areas to check now.

How Computeam supports your school

Computeam is an education-only technology partner with a dedicated cybersecurity team, supporting schools and trusts at every stage of the Cyber Essentials journey.

Cyber Security Audit

A two-stage process: an on-site survey with your leadership team covering physical, network, user and device security, followed by a written report benchmarking you against the DfE cyber security standard and Cyber Essentials, with prioritised recommendations.

Vulnerability scanning

IASME-compliant scanning using the same technology Cyber Essentials Plus auditors use, so you know how you would fare before the real assessment.

Remediation and strategy

A plan to fix the issues, with ongoing support to put it into practice, and help with the certification process itself.

Beyond the certificate

Cyber Essentials guards against the most common attacks, not all of them. Advanced email security, modern anti-malware, user awareness training and phishing simulations close the gaps it does not cover, all delivered under Computeam Secure. 

Staff training

CPD-certified cyber security training for school staff, delivered through Learning Locker, supporting the annual all-staff training the RPA expects. 

Talk to our cybersecurity team

Whether you are starting from scratch or preparing for Cyber Essentials Plus, we will help you find your baseline and build from there.

Get in touch

Cyber Essentials, answered:

Q&A with Brad Biddle, Head of Cyber Security at Computeam

Brad Biddle, who leads Computeam's cyber security team, provides answers to the questions most frequently asked by school leadership teams.

How would you explain Cyber Essentials to a headteacher or school business manager who is unsure it is relevant to them?

“Cyber Essentials is an entry-level standard from the NCSC. It provides organisations with guidance and objectives to meet the fundamentals of cybersecurity, backed by certification. The standard itself is free of charge; certification has a cost. It is the gateway to cybersecurity for schools and small businesses.

The standards are not written specifically for schools, so they are broad, which can be an issue for schools. That is why I would say the DfE digital standard for cybersecurity is the place to start. It is school-specific, and the DfE expects every school to be meeting it by 2030. Get that in order first, then Cyber Essentials.”

What is the single biggest misconception schools have about Cyber Essentials?

“That is the first thing they should do. Schools should comply with the DfE cyber standard first.

The other one is thinking it can all be outsourced. Cyber Essentials is all about policies and processes, so the school needs to have them in place and measure and monitor them. Computeam can help, but the school or trust needs to take responsibility. It is more about best practice and less about tech.”

Why are schools such an attractive target compared with other organisations?

“Schools have tight budgets, not the best tech, not the best training plans, and real-time pressures. There is pressure from the government to keep data secure, so attackers see them as willing to pay to get data back in a ransomware attack. The data is very valuable because the sector is so regulated.

Schools have the budgets of a small or medium business, but the number of staff of a big business.”

What is the realistic worst case for a school without the basics in place?

“This is a real example. A school is running a server on their network. An attacker deploys ransomware on that server, locking everyone out of everything and causing the school to go completely offline. No backups. They have to start completely fresh with accounts, systems, data, everything. Literally nothing works: digital registers, cashless lunch purchasing, all of it. Networks are down, systems are offline, and all the data about students and finances can be extorted for money or sold to third parties.

If the intention is to do maximum damage, the hacker will look to corrupt the backups,, too. Sped up with the use of AI, it can be a matter of minutes between the start of the hack and major chaos.”

Do MATs need certification at trust level, or school by school?

“Always at trust level, especially for insurance and the RPA, but every school in the Trust is within scope of the assessment. The trust is the member. It does depend on what schools have in place, as some schools may be further ahead than the trust as a whole, but the overall responsibility lands with the trust.”

What does the independent testing in Cyber Essentials Plus involve, and is it disruptive?

“Essentials and Essentials Plus have the same requirements; the difference is the level of proof required for Plus, to show it is working and in place. The auditor will run checks on a Teams call and ask you to share your screen to show that procedures and systems are in place in practice. They will test a sample of devices, and a vulnerability scan will take place. You get a list of vulnerabilities and 14 days to fix them before being tested again.

It is not overly disruptive for the whole team. It can be for the person within the process, but not the whole school or network.”

What changed with the scheme in April 2026, and what does it mean for schools?

“The main changes are focused on the assessment itself. In the past, the checks were more basic; auditors now have additional controls to make sure the security is genuine and in place. More thorough checks and more cloud checks that were not previously covered as standard.

The big one is that MFA must now be enabled for all cloud services. It used to be advisory, but it is now mandatory, and missing it is an automatic fail. There is also a greater focus on passwordless verification and other authentication methods to move away from passwords. It is a shift towards security that is embedded in day-to-day operations, rather than applied temporarily for an assessment.”

For a school that feels completely behind on cyber, where should they start?

“The most effective controls can be free: MFA, password management, basic and logical management of passwords and internet usage. Most schools are in the same boat. None are perfect, and all are vulnerable.

Speak to a professional and get your baseline to start with. You are probably doing more than you think.”

Get in touch

Get your baseline

You are probably doing more than you think. Book a Cyber Security Audit and get a clear picture of where your school or trust stands, and what to do next.

Book a Cyber Security Audit

Loading... Updating page...