Independent UK education editorial Evidence · leadership · action

AboutMethodologyContact
SCHOOL CONNECTIONEDITORIAL NETWORK

See the change. Examine the evidence.
Understand what it means for schools.

Editorial intelligenceAcademic year 2026/27
Menu

School Connection / Feature

Primary: DigitalConnected: FundingConnected: EstatesConnected: Workforce
School Connection Digital Resilience ProgrammeLive

Third-party access is part of the school attack surface

Outsourced IT and cloud support can improve capability, but it also extends the identity, network and recovery boundary. Leaders need evidence about how external access is granted, monitored, limited and removed.

An external support relationship still needs an internal owner and an evidence trail.

DfE's cyber standard says schools should understand risk across their technology and the services they rely on. That includes outsourced IT, because provider accounts, remote support tools, cloud consoles and third-party integrations can carry privileged access into the school environment.1

The response is not to avoid external support. It is to make access proportionate, attributable and reviewable, with clear incident, data, continuity and exit duties. Procurement and cyber assurance are therefore connected decisions.23

  • Know which people, tools and organisations can reach critical systems.
  • Require named accountability, strong authentication, least privilege and useful logs.
  • Test how access is suspended during an incident and removed at the end of a relationship.

The school attack surface includes the route taken to support it.

Create an access map for remote support, identity administration, backup consoles, network management, filtering, device management and data integrations. Record what the access can do, where it is used, who approves it and how activity is attributed.14

A service description is not the same as an assurance position.

Due diligence should cover security responsibilities, personnel and subcontractor access, data location, incident notification, logging, backup, recovery, vulnerability handling, service continuity and evidence supplied at review. The level of detail should reflect the access and consequence, not the size of the invoice.23

  • Name the school's accountable owner and the provider's accountable role.
  • Set review points for privileged accounts, subprocessors, major changes and material incidents.
  • Keep a workable route to suspend access, preserve evidence and communicate during an incident.

The real test is what happens when trust has to become verification.

During an incident, the school needs to know who can isolate a service, revoke credentials, preserve logs, restore from a clean copy and contact the right people. At exit, it needs evidence that accounts, tokens, devices, data and remote tools have been removed or transferred as agreed.14

Questions that turn the development into a governing conversation.

01

Board test

Which external accounts and tools can change the school's most important systems?

02

Board test

Can every privileged action be attributed, reviewed and stopped quickly?

03

Board test

What evidence do we receive after access, incidents, major changes and recovery tests?

04

Board test

How would we operate safely if this relationship or remote-support route stopped tomorrow?

What the national Observatory can add, and where it must stop.

School Connection treats third-party access as a connected condition of resilience, not an accusation about any individual provider. The evidence question is whether responsibility, access, logging, recovery and exit are visible enough for leadership to govern.12

Publication boundary

Only human-approved, public-safe intelligence can appear here. Private candidates, commercial signals, contacts, opportunity values and internal scores are never exposed through School Connection.

What this analysis does not prove.

  • Public guidance does not assess an individual provider's controls or a school's contract.
  • Certification or policy documents do not replace local configuration, access review or incident testing.
  • The existence of external access does not by itself prove unacceptable risk; access purpose and control matter.

Publication is the beginning of the watch.

  • DfE cyber-standard and procurement-risk updates.
  • Material managed-service, identity, backup or remote-support changes.
  • Evidence from access reviews, exercises, incidents and contract exits.

What the live evidence is showing now.

Live feed · approved view
Primary signalVerifiedHigh confidence

Gigabit is coming to more schools. The connection is only the beginning.

The DfE's new gigabit programme is an opportunity to close a stubborn infrastructure gap and strengthen the digital foundations schools increasingly depend on. Our analysis shows where the opportunity is greatest, what changes operationally when connectivity improves, and what school and trust leaders should be thinking about now.

Why it matters

A stronger connection is valuable because it changes what a school can reliably depend on. The opportunity is not simply faster internet.

1,656 schools in the contextual evidence cohortVerified 4 Sept 2026

This panel reads only the editor-approved School Connection public feed. It never exposes raw Observatory records, private candidates, contacts, commercial opportunities or internal scores.

Evidence used in this analysis

School Connection links to the primary source behind each material claim. Source status, period and limitations are stated so readers can reproduce the evidence trail.

  1. 01

    Department for Education · Updated 8 September 2026

    Cyber security: core standard

    Guidance on cyber risk assessment, training, identity, patching, backups, incident response and continuity.
  2. 02

    Department for Education · Published 15 July 2026

    How to reduce procurement risk: good practice for academy trusts

    Good practice on governance, due diligence, competition, records, conflicts and contract management for academy trusts.
  3. 03

    Department for Education · Updated 8 September 2026

    Digital leadership and governance: core standard

    Guidance on ownership, strategy, reporting, roles and the governance evidence needed to manage digital change.
  4. 04

    National Cyber Security Centre · Published 20 August 2026

    Managing the cyber risk of agentic AI

    Interim cross-sector guidance on threat modelling, restricted authority, human oversight, logs, monitoring and emergency shutdown.

A living editorial

Published once.
Monitored continuously.

How School Connection develops and updates its coverage