School Connection / Explainer
Backups are not recovery: the restoration test for critical school services
A backup report can show that data was copied. It cannot show that the school can restore the right service, within the right time, with the right permissions and enough evidence to know the result is safe.
The answer in brief
Recovery is a school operating capability, not a storage feature.
DfE's cyber, cloud and storage standards place backup and recovery inside a wider control system: critical data must be protected, access must be controlled, services must be supported and the organisation must understand how it will restore after disruption.123
The proof is a restoration exercise that reflects the service the school needs. A successful file restore is not the same as a working MIS, identity directory, telephony service, safeguarding record or teaching workflow.12
- Define recovery by service and function, not only by dataset.
- Keep offline or separately protected copies where the risk model requires them.
- Record restoration evidence, integrity checks, permissions and the person who accepts the result.
01 / Backup evidence
A green backup dashboard answers only one part of the question.
Leaders should know what is covered, how often it is copied, where copies are held, how long they are retained, who can alter or delete them and how alerts are reviewed. Critical data may sit across cloud services, local systems, devices, integrations and exports; one report rarely covers the whole estate.23
02 / Restore the service
The exercise should recreate the decisions a real incident would force.
A restoration test should use a defined scenario, recovery objective, clean environment, named roles and a verification checklist. It should test dependencies such as identity, network access, permissions, integrations, safeguarding workflows and communication, then record what could not be restored and why.123
- Choose one critical service and trace it from data recovery to a usable school workflow.
- Verify that restored accounts, permissions, logs and safeguarding controls are correct.
- Capture elapsed time, manual workarounds, unresolved gaps and a dated improvement owner.
03 / Recovery governance
The board conversation is about acceptable interruption and evidence of improvement.
Every critical service needs a proportionate recovery objective, an accountable owner and an escalation route. The residual risk should be visible when the cost of recovery, the age of the system or a provider dependency makes full restoration difficult.12
Leadership questions
Questions that turn the development into a governing conversation.
Board test
Which services must be restored first for the school to remain safe and operational?
Board test
When did we last restore them end to end, and what evidence did the exercise produce?
Board test
Can an attacker or administrator delete, alter or encrypt every copy we rely on?
Board test
Who accepts the gap between the desired and demonstrated recovery position?
School Connection intelligence lens
What the national Observatory can add, and where it must stop.
The programme distinguishes backup presence from recovery evidence. Public standards can set the questions; only a school or trust exercise can show whether a particular service, identity path and safeguarding workflow can be restored in practice.123
Only human-approved, public-safe intelligence can appear here. Private candidates, commercial signals, contacts, opportunity values and internal scores are never exposed through School Connection.
Evidence boundary
What this analysis does not prove.
- A published standard does not establish a school's backup coverage, retention or recovery time.
- One successful restoration does not prove every service or dependency will recover under a different incident.
- Recovery objectives are local leadership decisions and should reflect safeguarding and operational consequence.
What we are monitoring next
Publication is the beginning of the watch.
- Changes to DfE cyber, cloud and storage standards.
- Restoration evidence for MIS, identity, safeguarding, telephony and critical teaching services.
- Material provider, architecture, ransomware or incident-response changes.
Approved public intelligence
What the live evidence is showing now.
Gigabit is coming to more schools. The connection is only the beginning.
The DfE's new gigabit programme is an opportunity to close a stubborn infrastructure gap and strengthen the digital foundations schools increasingly depend on. Our analysis shows where the opportunity is greatest, what changes operationally when connectivity improves, and what school and trust leaders should be thinking about now.
A stronger connection is valuable because it changes what a school can reliably depend on. The opportunity is not simply faster internet.
This panel reads only the editor-approved School Connection public feed. It never exposes raw Observatory records, private candidates, contacts, commercial opportunities or internal scores.
Sources and methodology
Evidence used in this analysis
School Connection links to the primary source behind each material claim. Source status, period and limitations are stated so readers can reproduce the evidence trail.
- 01
Department for Education · Updated 8 September 2026
Cyber security: core standard
Guidance on cyber risk assessment, training, identity, patching, backups, incident response and continuity. - 02
Department for Education · Updated 8 September 2026
Servers and storage: core standard
Guidance on supported storage, resilience, backup, recovery and the risks of relying on one service or location. - 03
Department for Education · Updated 8 September 2026
Cloud solutions: core standard
Guidance on cloud assurance, portability, availability, access control, data protection and external backup.