School IT Security: 10 Summer Checks Before September
The classrooms may be empty, but your school’s IT certainly isn’t.

The classrooms may be empty, but your school’s IT certainly isn’t.
While staff and pupils enjoy the summer break, your school’s servers, Microsoft 365 environment, backups, firewalls, wireless network and cloud systems continue working around the clock.
Unfortunately, cyber criminals do too.
The summer holidays provide schools with something that can be difficult to find during term time: an opportunity to stop, review the IT environment and fix weaknesses before the new academic year begins.
And this year, there is an additional reason for schools to take a closer look.
The Department for Education has recently updated its cyber security guidance, with schools expected to work towards meeting its cyber security standards by 2030. The standards cover areas including annual cyber risk assessments, cyber awareness, malware protection, firewalls, account security, keeping technology up to date, backups and cyber incident reporting.
Meanwhile, Keeping Children Safe in Education 2026 comes into force on 1 September 2026, reinforcing the importance of protecting children's personal information and having appropriate cyber security systems in place as part of a school's wider safeguarding responsibilities.
So, before everyone returns in September, here are 10 areas every school should consider checking.
1. Have you tested your backups?
One of the biggest mistakes a school can make is assuming that because a backup says "successful", the data can actually be recovered.
Backups should be regularly tested by carrying out an actual restoration.
The DfE is now actively promoting the 3-2-1 backup strategy:
- 3 copies of your data
- 2 different forms of storage
- 1 copy kept off-site
The DfE also recommends that schools regularly test their ability to restore backups and maintain an offline or otherwise isolated copy that cannot simply be encrypted by a ransomware attack.
The summer holidays are an ideal time to perform a proper restore test.
Ask yourself: If your main server disappeared tomorrow, how quickly could you recover?
2. Remove accounts belonging to staff who have left
The end of the academic year usually means staff changes.
Teachers retire. Staff move schools. Temporary workers finish. Governors change. Contractors come and go.
But what happens to their IT accounts?
Before September, schools should review:
- Microsoft 365 accounts
- Email accounts
- Remote access
- VPN access
- Admin accounts
- Third-party education applications
- Shared accounts
- Access to sensitive files and folders
An account belonging to someone who left months ago should not still provide access to your school's systems.
The DfE specifically highlights the importance of controlling and securing user accounts and access privileges.
3. Check Multi-Factor Authentication
A stolen password should not automatically mean an attacker can access your school's systems.
Multi-Factor Authentication (MFA) provides an additional layer of protection by requiring users to prove their identity using another factor.
The DfE recommends MFA particularly for senior leaders and staff handling confidential, financial or sensitive information, as well as privileged accounts, internet-facing systems, cloud services and remote access technologies.
The summer holidays are an excellent opportunity to review exactly where MFA is enabled — and, just as importantly, where it isn't.
4. Review your Microsoft 365 security
For many schools, Microsoft 365 is now at the centre of day-to-day operations.
Email, Teams, OneDrive, SharePoint and other Microsoft services may contain an enormous amount of sensitive information.
But having Microsoft 365 does not automatically mean that your school's Microsoft 365 environment is securely configured.
A summer security review should consider areas such as:
- Global administrator accounts
- Conditional Access
- MFA
- External forwarding
- Suspicious mailbox rules
- Guest access
- Privileged accounts
- Legacy authentication
- Device compliance
- Sign-in activity
- Unused accounts
This is particularly important because attackers increasingly target user identities rather than simply trying to break through a school's firewall.
5. Update old servers, PCs and network equipment
The summer holidays are often the best time to replace ageing IT equipment.
An old server that is still functioning may appear to be saving the school money — until it fails during term time.
The same applies to:
- Wireless access points
- Network switches
- Firewalls
- Teacher PCs
- Laptops
- Interactive displays
- Storage devices
Old equipment can introduce security, reliability and compatibility risks, particularly when manufacturers stop providing firmware or security updates.
The DfE cyber security standards specifically expect schools to keep their technology up to date.
Replacing equipment during the summer can also mean significantly less disruption to teaching.
6. Give your staff a phishing test
A large proportion of school cyber incidents start with people.
That doesn't mean staff are the problem. It means attackers know that a convincing email can sometimes be more effective than trying to break through sophisticated technical security.
The DfE's current Cyber Security Hub highlights phishing as one of the major threats facing education. It reports that phishing was involved in 92% of reported incidents in primary schools and 89% in secondary schools among the incidents referenced in its current threat information.
Before staff return, consider running a phishing simulation.
This can establish a baseline and identify where additional security awareness training is required.
At Soltech IT, we can help schools conduct phishing simulation testing in a controlled environment, allowing schools to understand their risk without putting real data at risk.
7. Review your cyber incident response plan
magine this:
It's 10:30pm on a Saturday during half term.
A member of staff calls to say they can't access their files.
Then another.
Then the school office.
Your systems appear to be encrypted.
Who do you call?
Who has authority to make decisions?
Who contacts the IT provider?
Who informs the Headteacher?
Who contacts the DPO?
Who communicates with staff and parents?
And how quickly can the school begin recovering?
The DfE's current cyber resilience checklist specifically highlights the need for schools to create a cyber response plan and be clear about who is responsible for what.
A plan that sits in a folder and has never been discussed is not much of a plan.
8. Review your Cyber Essentials position
The summer is also an ideal time to review your school's Cyber Essentials position.
Cyber Essentials provides a useful framework for identifying and addressing fundamental cyber security weaknesses.
For schools that already hold certification, the summer provides an opportunity to check that the controls are still operating correctly.
For schools that haven't yet started, September can be an excellent target for beginning the process.
Certification can also help demonstrate to parents, governors, trusts, insurers and other stakeholders that cyber security is being taken seriously.
9. Check your devices before pupils return
The start of a new academic year is not the time to discover that 30 laptops are too old for the latest operating system.
Before September, schools should review the age, condition and compatibility of their technology estate.
Look at:
- Windows compatibility
- Security updates
- Antivirus/EDR protection
- Encryption
- TPM and Secure Boot
- Battery health
- Warranty status
- Manufacturer support
- Age of equipment
A simple summer hardware audit can help schools create a realistic replacement programme rather than replacing equipment reactively when it fails.
10. Don't wait until September to find the problems
Perhaps the biggest advantage of the summer holidays is simply the time available.
During term time, an IT problem can quickly become a teaching problem.
A failed server can affect lessons.
A broken wireless network can affect an entire building.
A compromised Microsoft 365 account can expose sensitive information.
A ransomware attack can potentially bring school operations to a standstill.
The summer provides a window to identify those weaknesses while there is still time to do something about them.
Is Your School Ready for September?
The question isn't whether your school will experience an IT problem.
It's whether you have identified the risks before they become problems.
With the DfE continuing to strengthen its expectations around cyber security, and the new Keeping Children Safe in Education guidance coming into force from September 2026, there has never been a better time for schools to review their IT and cyber security arrangements.
At Soltech IT, we work with schools and education organisations to help keep their technology secure, reliable and ready for the new academic year.
From IT support and infrastructure upgrades to Microsoft 365 security, Cyber Essentials, phishing simulation testing, EDR, MDR and backup and security, we can help identify the areas that need attention.
Don't wait for the first IT problem of the new school year. Use the summer to fix it before September.
Talk to Soltech IT about a Summer IT & Cyber Security Health Check.
Get in touch



























