School Connection / Feature
Six standards, one trust-wide view: digital readiness can now be planned across more than one school
DfE has added its Cyber Security Hub to the cyber standard and updated Plan Technology so multi-academy trusts can submit self-assessments for more than one school at a time. The opportunity is a common readiness view; the risk is mistaking a completed assessment for tested control.
The answer in brief
A common assessment creates visibility; assurance still depends on owned, tested evidence at each school.
Two DfE changes on 8 September are operationally useful but should be described precisely. The standards change log says a link to the Department's Cyber Security Hub was added to the cyber core standard. Separately, Plan Technology was updated so multi-academy trusts can complete and submit self-assessments for more than one school at a time. The official pages do not say the Hub launched on 8 September, and they do not present a submitted assessment as certification.2357
The wider framework is six core standards: broadband internet, wireless network, network switching, digital leadership and governance, filtering and monitoring, and cyber security. DfE says schools and colleges should work towards all six by 2030. That creates a shared planning spine, but the evidence must still show whether controls work under the conditions of each site.1
- Use the MAT-wide assessment to expose variation and dependencies, not to replace school-level evidence with a trust average.
- Keep DfE guidance, current statutory safeguarding responsibility and optional assurance routes clearly separated.
- Convert every recommendation into an owner, deadline, dependency, budget decision and test of completion.
01 / What changed
The 8 September update joins planning and practical support; it does not create a new compliance badge.
The standards manual now directs users of the cyber core standard to the DfE Cyber Security Hub. The Hub groups resources under four practical routes: strengthening cyber security, creating a response plan, following processes for specific incidents, and finding awareness resources and support. The change is easier access to operational material, not evidence that a school has implemented it.257
Plan Technology already allowed schools and trusts to complete self-assessments, receive recommendations and track progress. Its 8 September update adds that MATs can complete and submit assessments for more than one school at a time. Anyone with a DfE Sign-in account for the school or trust can use the service without adding it or obtaining access approval, and DfE says information from the service is not shared with Ofsted.3
02 / Trust-wide, not uniform
A portfolio view is valuable because schools differ, not because they can be treated as one site.
A multi-school submission can give trust leaders a consistent baseline, make common gaps visible and support sequencing across budgets and contracts. It can also reveal where one supplier, administrator account, internet route or recovery dependency creates concentration risk across several schools. DfE's cyber standard expressly warns that an incident may affect other schools on a broader organisational network.35
The control remains local as well as central. A trust-wide firewall contract does not prove the filtering profile suits each pupil cohort; a common backup product does not prove every school can restore; and a shared wireless design does not prove coverage in a particular building. Record one answer per school where site conditions matter, then aggregate the evidence without erasing exceptions.
03 / Six connected controls
The six standards are a dependency system, and they do not all share the same urgency.
Broadband, wireless and switching form the service path. Leadership and governance establishes accountability, current information, continuity and a strategy led by educational and organisational needs. Filtering and monitoring connects the technical estate to safeguarding. Cyber security covers risk assessment, awareness, protective controls, accounts, updates, backup and incident reporting. Weakness in one layer can undermine apparently strong performance in another.1456
The 2030 phrase must not be read as permission to defer everything. DfE's filtering and monitoring page says schools and colleges should already meet that core standard because they have a statutory responsibility to keep children safe online as well as offline. By contrast, the cyber page describes standards for all settings and distinguishes Cyber Essentials certification: it is required for colleges under their funding agreements, while some schools may choose it.56
Within the cyber standard, DfE says a cyber risk assessment should be conducted annually and reviewed every term. It places accountability and coordination with the SLT digital lead while IT support actions the technical work. That allocation prevents cyber resilience being treated as either an IT-only task or a board-only declaration.5
04 / From assessment to assurance
Turn recommendations into a controlled programme and test the claims that matter most.
A completed self-assessment is a baseline. Assurance begins when the trust can connect each material answer to current evidence, an accountable owner and a test result. Use the Hub's response-plan route to structure preparation, but do not stop at a completed template: exercise decision-making, communications, safeguarding continuity, restoration and supplier escalation under realistic loss-of-service conditions.378
- Complete the six-standard baseline for every school and timestamp the evidence behind each answer.
- Separate trust-wide controls from site-specific conditions, recording shared dependencies and local exceptions.
- Prioritise current safeguarding gaps and high-consequence cyber or continuity failures before cosmetic standardisation.
- Give every recommendation an owner, due date, cost, prerequisite, acceptance test and review cycle.
- Run a trust-level cyber exercise that tests school escalation, unavailable systems, backup restoration and cross-site containment.
Leadership questions
Questions that turn the development into a governing conversation.
Board test
Which answers in our MAT-wide assessment are supported by current test evidence, and which are self-reported assumptions?
Board test
Where would one supplier, identity platform, administrator account, network route or backup failure affect more than one school?
Board test
Which filtering and monitoring gaps require action now rather than being placed on a general 2030 roadmap?
Board test
Can every school operate safeguarding, communications, teaching and essential administration while priority systems are unavailable?
School Connection intelligence lens
What the national Observatory can add, and where it must stop.
School Connection can connect dated changes in DfE standards, published trust and school characteristics, connectivity context and recurring public incident evidence. That can show where leaders need to investigate a dependency; it cannot see private configurations, test backups or certify control effectiveness.123
A useful trust view should retain school-level provenance, assessment date, control owner, evidence state and last test. School Connection will distinguish DfE wording from its own prioritisation and will not turn a self-assessment into a public cyber rating.
Only human-approved, public-safe intelligence can appear here. Private candidates, commercial signals, contacts, opportunity values and internal scores are never exposed through School Connection.
Evidence boundary
What this analysis does not prove.
- The six core standards and 2030 direction are DfE guidance, not a general certification or proof that every related legal and contractual duty has been met.
- Plan Technology is a self-assessment and recommendation service; the public guidance does not say DfE independently verifies answers, technical configuration or operational effectiveness.
- The 8 September change log records that a Hub link was added. It does not establish the Hub's launch date or demonstrate that using its resources improves outcomes without implementation and testing.
What we are monitoring next
Publication is the beginning of the watch.
- Further DfE changes to the six core standards, Plan Technology's multi-school workflow and Cyber Security Hub resources.
- Evidence that MAT-wide assessments are producing funded action, closed gaps and tested recovery rather than higher completion counts alone.
- Changes in Cyber Essentials, safeguarding, filtering and incident-reporting requirements that alter the boundary between guidance, funding conditions and statutory duty.
Approved public intelligence
What the live evidence is showing now.
Gigabit is coming to more schools. The connection is only the beginning.
The DfE's new gigabit programme is an opportunity to close a stubborn infrastructure gap and strengthen the digital foundations schools increasingly depend on. Our analysis shows where the opportunity is greatest, what changes operationally when connectivity improves, and what school and trust leaders should be thinking about now.
A stronger connection is valuable because it changes what a school can reliably depend on. The opportunity is not simply faster internet. It is the chance to strengthen the whole chain that sits behind teaching, administration, safeguarding and day-to-day operations. 1. SERVICE AND CONTRACT POSITION The DfE-funded connection and the broadband service are separate decisions. Schools contacted through the programme will still need to understand what service sits on the new connection, how that fits with the current contract, what notice or renewal dates apply and whether support arrangements remain appropriate. The positive opportunity is to avoid carrying an old commercial arrangement into a new infrastructure environment simply because it is familiar. Leaders should know what they are paying for, what level of service is actually being delivered, what happens when performance drops and whether the contract gives enough flexibility for future change. 2. INTERNAL NETWORK READINESS A better external connection can expose weaknesses inside the school that were previously hidden by limited bandwidth. Cabling, switches, routers, wireless access points and network configuration determine what staff and pupils actually experience. This is an opportunity to identify the genuine bottleneck rather than assume everything needs replacing. In many schools, targeted improvements to Wi-Fi coverage, switching capacity or network management may unlock much more value from the connection than a wholesale infrastructure refresh. 3. RESILIENCE AND CONTINUITY Connectivity now supports essential school operations. Cloud systems, MIS access, telephony, communications, remote support and safeguarding tools can all depend on it. That makes continuity part of the operational conversation. A good outcome is not simply one fast connection. It is a school that can continue operating when the primary service fails. Leaders should understand whether backup is genuinely independent, whether failover is automatic, whether core network equipment has appropriate power resilience and whether the recovery plan has actually been tested. 4. SAFEGUARDING AND CYBER Any significant connectivity change is also a useful point to review filtering, firewalling, monitoring, remote access and support responsibilities. The aim is not to make the transition feel risky. It is to use planned change as a positive opportunity to strengthen controls at the same time as capability improves. A stronger network should support stronger governance. Schools should know who owns the security configuration, how changes are tested, what happens during cutover and how safeguarding controls are verified afterwards. 5. TEACHING, ADMINISTRATION AND USER EXPERIENCE The practical test of the programme is what improves for people. Staff should spend less time working around unreliable systems. Pupils should experience more consistent access to digital resources. Remote support should become easier. Cloud applications should perform more predictably. Telephony and communications can become more dependable. This is where the value becomes visible. A connectivity project should ultimately be judged by the improvement it creates in the operation of the school, not by the specification on the circuit alone. 6. TRUST-WIDE OPERATIONAL CONSISTENCY For trusts and responsible bodies, several different school starting points can become one strategic opportunity. One school may enter the DfE programme, another may already have strong fibre, another may be approaching renewal and another may have internal network limitations. The opportunity is to define a common minimum outcome across the group: suitable capacity, resilience, filtering and firewall standards, clear support ownership, visibility of contract dates and a consistent route for escalation. The solution does not need to be identical at every site, but the standard should be clear. KEY OPERATIONAL MESSAGE The connection is the foundation. The lasting value comes from what the school builds around it: the right service, a capable internal network, tested resilience, strong safeguarding and cyber controls, and a digital environment that works reliably for staff and pupils.
This panel reads only the editor-approved School Connection public feed. It never exposes raw Observatory records, private candidates, contacts, commercial opportunities or internal scores.
Sources and methodology
Evidence used in this analysis
School Connection links to the primary source behind each material claim. Source status, period and limitations are stated so readers can reproduce the evidence trail.
- 01
Department for Education · Published 23 March 2022; updated 8 September 2026
Meeting digital and technology standards in schools and colleges
The current manual and list of six core standards that schools and colleges should work towards meeting by 2030. - 02
Department for Education · Updated 8 September 2026
Updates: Meeting digital and technology standards in schools and colleges
The change log. For 8 September it records a link to the DfE Cyber Security Hub being added to the cyber core standard; it does not describe that date as the Hub's launch. - 03
Department for Education · Published 11 September 2024; updated 8 September 2026
Plan technology for your school
The service description, including self-assessments, recommendations, progress tracking and the new ability for MATs to complete and submit assessments for more than one school at a time. - 04
Department for Education · Manual published 23 March 2022; updated 8 September 2026
Digital leadership and governance: core standard
Current guidance on accountable leadership, roles, registers, continuity and a strategy led by teaching, learning and organisational needs. - 05
Department for Education · Manual published 23 March 2022; updated 8 September 2026
Cyber security: core standard
Current school and college cyber guidance, including annual risk assessment with termly review, response planning, account security, patching, backup, reporting and the link to the DfE Hub. - 06
Department for Education · Manual published 23 March 2022; updated 8 September 2026
Filtering and monitoring: core standard
The important timetable exception: schools and colleges should already meet this standard because of current statutory online-safeguarding responsibility. - 07
Department for Education · Live service retrieved 9 September 2026
Cyber Security Hub
DfE's operational resource hub covering protective measures, cyber response planning, incident processes and awareness resources. - 08
Department for Education · Live resource retrieved 9 September 2026
Create your cyber response plan
The Hub's response-planning guidance and template route; using a template does not demonstrate that the plan has been exercised successfully.