School Connection / Feature
Third-party access is part of the school attack surface
Outsourced IT and cloud support can improve capability, but it also extends the identity, network and recovery boundary. Leaders need evidence about how external access is granted, monitored, limited and removed.
The answer in brief
An external support relationship still needs an internal owner and an evidence trail.
DfE's cyber standard says schools should understand risk across their technology and the services they rely on. That includes outsourced IT, because provider accounts, remote support tools, cloud consoles and third-party integrations can carry privileged access into the school environment.1
The response is not to avoid external support. It is to make access proportionate, attributable and reviewable, with clear incident, data, continuity and exit duties. Procurement and cyber assurance are therefore connected decisions.23
- Know which people, tools and organisations can reach critical systems.
- Require named accountability, strong authentication, least privilege and useful logs.
- Test how access is suspended during an incident and removed at the end of a relationship.
01 / Draw the boundary
The school attack surface includes the route taken to support it.
Create an access map for remote support, identity administration, backup consoles, network management, filtering, device management and data integrations. Record what the access can do, where it is used, who approves it and how activity is attributed.14
02 / Assurance in the contract
A service description is not the same as an assurance position.
Due diligence should cover security responsibilities, personnel and subcontractor access, data location, incident notification, logging, backup, recovery, vulnerability handling, service continuity and evidence supplied at review. The level of detail should reflect the access and consequence, not the size of the invoice.23
- Name the school's accountable owner and the provider's accountable role.
- Set review points for privileged accounts, subprocessors, major changes and material incidents.
- Keep a workable route to suspend access, preserve evidence and communicate during an incident.
03 / Incident and exit
The real test is what happens when trust has to become verification.
During an incident, the school needs to know who can isolate a service, revoke credentials, preserve logs, restore from a clean copy and contact the right people. At exit, it needs evidence that accounts, tokens, devices, data and remote tools have been removed or transferred as agreed.14
Leadership questions
Questions that turn the development into a governing conversation.
Board test
Which external accounts and tools can change the school's most important systems?
Board test
Can every privileged action be attributed, reviewed and stopped quickly?
Board test
What evidence do we receive after access, incidents, major changes and recovery tests?
Board test
How would we operate safely if this relationship or remote-support route stopped tomorrow?
School Connection intelligence lens
What the national Observatory can add, and where it must stop.
School Connection treats third-party access as a connected condition of resilience, not an accusation about any individual provider. The evidence question is whether responsibility, access, logging, recovery and exit are visible enough for leadership to govern.12
Only human-approved, public-safe intelligence can appear here. Private candidates, commercial signals, contacts, opportunity values and internal scores are never exposed through School Connection.
Evidence boundary
What this analysis does not prove.
- Public guidance does not assess an individual provider's controls or a school's contract.
- Certification or policy documents do not replace local configuration, access review or incident testing.
- The existence of external access does not by itself prove unacceptable risk; access purpose and control matter.
What we are monitoring next
Publication is the beginning of the watch.
- DfE cyber-standard and procurement-risk updates.
- Material managed-service, identity, backup or remote-support changes.
- Evidence from access reviews, exercises, incidents and contract exits.
Approved public intelligence
What the live evidence is showing now.
Gigabit is coming to more schools. The connection is only the beginning.
The DfE's new gigabit programme is an opportunity to close a stubborn infrastructure gap and strengthen the digital foundations schools increasingly depend on. Our analysis shows where the opportunity is greatest, what changes operationally when connectivity improves, and what school and trust leaders should be thinking about now.
A stronger connection is valuable because it changes what a school can reliably depend on. The opportunity is not simply faster internet.
This panel reads only the editor-approved School Connection public feed. It never exposes raw Observatory records, private candidates, contacts, commercial opportunities or internal scores.
Sources and methodology
Evidence used in this analysis
School Connection links to the primary source behind each material claim. Source status, period and limitations are stated so readers can reproduce the evidence trail.
- 01
Department for Education · Updated 8 September 2026
Cyber security: core standard
Guidance on cyber risk assessment, training, identity, patching, backups, incident response and continuity. - 02
Department for Education · Published 15 July 2026
How to reduce procurement risk: good practice for academy trusts
Good practice on governance, due diligence, competition, records, conflicts and contract management for academy trusts. - 03
Department for Education · Updated 8 September 2026
Digital leadership and governance: core standard
Guidance on ownership, strategy, reporting, roles and the governance evidence needed to manage digital change. - 04
National Cyber Security Centre · Published 20 August 2026
Managing the cyber risk of agentic AI
Interim cross-sector guidance on threat modelling, restricted authority, human oversight, logs, monitoring and emergency shutdown.