IT support for schools is not a smaller version of business IT. A secondary school runs a network with more connected devices than most mid-sized companies, hands accounts to a thousand children, publishes filtering evidence to a safeguarding regulator, and does the whole of its change work in six weeks of August. A multi-academy trust does that in twelve buildings at once, across three local authorities, on twelve inherited networks nobody designed together. IT support for schools is the discipline of running that estate to a statutory standard on a funding-agreement budget.

This guide is written for trust chief operating officers, school business managers, headteachers and trustees who own the technology decision. It covers what good IT support for schools actually delivers: the DfE digital and technology standards and the 2030 deadline attached to them, the cyber security standards read as a contract, filtering and monitoring, safeguarding retention clocks that run to forty years, Microsoft 365 licensing and the storage cliff behind it, and the cost of each shape written out in pounds.

Two datasets underpin the numbers below and both are re-countable. The first is the Department for Education’s Get Information About Schools full establishment extract dated 22 August 2026, which we downloaded and counted ourselves — 27,221 open establishments, of which 22,986 are state-funded schools in England.

The second is the DSIT and Home Office Cyber Security Breaches Survey 2025/2026 education institutions findings, published 30 April 2026, which interviewed 273 primary schools, 222 secondary schools, 33 further education colleges and 49 higher education institutions. Everything read off a source was read on 22 August 2026. Where a figure is modelled rather than published it is labelled modelled and the arithmetic is shown.

The worked example throughout is a modelled twelve-school multi-academy trust: nine primaries and three secondaries, spread across three local authorities, 5,160 pupils on roll and 717 adult accounts. Sector guides for neighbouring estates answer the same questions differently — IT support for charities covers the volunteer identity problem and IT support for dental practices covers clinical systems. What we deliver day to day sits on our managed IT services page, and the estate-wide side of it on device management.

Why IT Support for Schools Is Its Own Discipline

it support for schools b desk globe sphere curved stand

A commercial provider looks at a school and sees a small business with a big network. IT support for an office of that headcount is a solved problem; a school is not an office. That reading is wrong in six specific ways, and every one of them changes the design. IT support for schools that starts from the small-business template gets the identity model wrong, the change calendar wrong and the evidence trail wrong, in that order.

IT support for schools serves a user population that is mostly children

A business gives accounts to employees who signed a contract and sat through an induction. A school gives accounts to four-year-olds. In our modelled trust, 5,160 of the 5,877 accounts belong to pupils — 87.80% of the identity estate is held by people who cannot be disciplined, cannot be trained in the ordinary sense, and turn over completely every seven years. IT support for schools has to make the controls survive that population rather than assume it away.

The change window is six weeks long and it is not negotiable

Every other sector schedules migrations around quiet periods it chooses. Schools have exactly one: the summer holiday. Cabling, switch replacement, server decommissioning, tenant migration and device refresh all compete for the same six weeks of IT support for schools capacity, and anything unfinished on the first day of term is visible to nine hundred people at once. IT support for schools is planned backwards from that date or it is not planned at all.

IT support for schools has to produce evidence, not assurances

Ofsted, the Department for Education, the Information Commissioner’s Office and — for a trust — the accounting officer all want to see the same thing: written proof that a control existed on a date. Filtering checks, cyber training completion, patch timeliness and account reviews all have to be producible on demand. IT support for schools is largely the work of making those trails fall out of normal operations instead of being assembled in a panic.

For IT support for schools, safeguarding sits inside the network

In most organisations the security team and the welfare team never meet. In a school the filtering system is a safeguarding control, the monitoring report is a safeguarding artefact, and the designated safeguarding lead has a named role in reviewing both. A provider delivering IT support for schools who treats web filtering as a firewall feature has misunderstood what it is for.

IT support for schools is bought with public money and a handbook attached

An academy trust spends under the Academy Trust Handbook, with delegated authority limits, a mandatory risk register and a duty to report irregularity above £5,000. A maintained school spends under its local authority’s scheme. Neither can sign a three-year contract the way a private firm can. IT support for schools has to be procured in a shape the accounting officer can defend.

Nobody in the building has technology in their job title

Decisions are distributed across a headteacher, a school business manager, a trust chief operating officer and a board of volunteer trustees. Very few have a technical background, and the person who understands the network is often a single site technician with no budget authority. IT support for schools that does not supply a clear recommendation and a written rationale simply watches the decision fail to happen.

What the Register Says About the Schools Buying IT Support

it support for schools c jigsaw piece square tab socket

Before designing anything it is worth knowing who the buyer actually is. We downloaded the DfE’s Get Information About Schools full extract on 22 August 2026 and counted it. There are 27,221 open establishments on the register; 22,986 of them are state-funded schools in England, holding 8,343,250 pupils on roll across the 22,740 schools that carry a pupil figure. The distribution is more lopsided than the sector’s own language suggests, and it explains most of what IT support for schools has to be.

Just over half the market for IT support for schools is academies

Of the 22,986 open state-funded schools, 12,025 — 52.31% — are academies or free schools, and 10,961 remain local authority maintained. Measured by pupils rather than buildings the picture is far more decisive: 5,383,414 of the 8,343,250 pupils on roll, or 64.52%, are in an academy. The market for IT support for schools is therefore majority-academy by pupil, and majority-trust by contract value, even though the raw school count is close to even.

IT support for schools is really two markets, secondary and primary

The split is not uniform. Of 3,171 open secondary schools, 2,665 — 84.04% — are academies, holding 83.64% of secondary pupils. Of 16,700 primaries, 8,311 — 49.77% — are academies, holding 50.39% of primary pupils. All-through schools run at 88.68% and 16-plus institutions at 98.78%. Nursery schools are at 0.00%: not one of the 376 maintained nursery schools has converted. IT support for schools sold as a single sector proposition is really two markets.

PhaseOpen schoolsAcademiesAcademy sharePupilsPupils in academies
Primary16,7008,31149.77%4,427,90450.39%
Secondary3,1712,66584.04%3,369,85683.64%
All-through15914188.68%211,02786.18%
Middle, deemed secondary896471.91%44,25078.35%
16 plus828198.78%22,45896.39%
Nursery37600.00%35,7080.00%
All state-funded22,98612,02552.31%8,343,25064.52%

The median school buying IT support for schools has 234 pupils

Across the 22,740 state-funded schools carrying a pupil figure, the mean roll is 366.9 and the median is 234. A quarter of schools have 143 pupils or fewer, and 16.72% have under 100 — between them those 3,802 schools hold 2.59% of the pupils. At the other end, the 479 schools with 1,500 or more pupils hold 10.01%. Those two ends need different IT support for schools entirely. The median primary has 225 pupils and the median secondary has 1,045, a 4.64x difference in one sentence. IT support for schools priced per site is pricing two completely different jobs the same.

Small schools are the structural problem for IT support for schools

Nearly two in five state-funded schools — 8,642 of the 22,740 carrying a pupil figure, or 38.00% — have fewer than 200 pupils, and on the national workforce ratio that means fewer than twenty-four adults. A school that size cannot fund a technician, cannot fund a firewall renewal cycle and cannot fund a project manager for a summer migration. Every serious model for IT support for schools at this end of the distribution is a shared-service model, whether that sharing happens through a trust, a local authority or a managed provider.

Campus-scale sites change what IT support for schools has to be

The 2,627 schools with 800 or more pupils are 11.55% of the counted estate but hold 38.45% of pupils. These are the sites where IT support for schools means genuine campus networks: multiple buildings, hundreds of access points, a data centre cupboard that grew organically, a cashless catering system, an access-control system, CCTV and a bring-your-own-device sixth form. IT support for schools at this scale is closer to a small university than to a small business.

Free school meals eligibility averages 26.87% and shapes IT support for schools

Across the 21,849 schools publishing a figure, the mean proportion of pupils eligible for free school meals is 26.87% and the median is 23.0%. In a school where a quarter of families are on benefits-related eligibility, a bring-your-own-device policy is not a cost saving — it is a mechanism for excluding a quarter of the class from homework. That single number is why IT support for schools in England is overwhelmingly a school-owned-device conversation, and it shows up directly in the breach survey: 82% of primary schools allow only organisation-owned devices on the network.

Where the academies actually sit: share of the 12,025 open academies by trust size band
Large MAT, 11 to 20 schools 29.09%
Very large MAT, 21 to 50 schools 24.71%
Mid MAT, 6 to 10 schools 22.51%
Small MAT, 2 to 5 schools 12.14%
Single-academy trust 7.74%
Mega MAT, 51 or more schools 3.81%

The Trust Structure IT Support for Schools Has to Serve

it support for schools d chess pawn round head tapered body

The register names a trust for every one of the 12,025 open academies and free schools, and there are 2,069 distinct trusts among them. That is the number that decides how IT support for schools is actually bought in England today: not 12,025 school-level decisions, but roughly two thousand organisational ones, half of them covering a single school and a tenth of them covering more than twenty.

Single-academy trusts are the worst-served buyers of IT support for schools

Of the 2,069 trusts, 931 — 45.00% — hold exactly one school. Between them those single-academy trusts account for 931 schools, 7.74% of the academy estate, and 713,810 pupils. They are structurally identical to a standalone school for IT support for schools purposes but carry a full trust’s governance overhead, which is why they are the most consistently under-supported buyers of IT support for schools in the country.

The 1,138 real multi-academy trusts hold 11,094 schools between them

Strip out the single-academy trusts and 1,138 genuine MATs remain, running 11,094 schools and 4,669,604 pupils. The mean MAT holds 9.75 schools, the median 7, the ninetieth percentile 20 and the largest 96. Mean pupils per MAT is 4,103 and the median is 2,885. Our modelled twelve-school, 5,160-pupil trust sits just above both medians, which is deliberate: it is the shape most trust-level IT support for schools conversations actually start from.

Trust size bandTrusts% of trustsSchools% of academiesPupils% of pupils
Single-academy trust93145.00%9317.74%713,81013.26%
Small MAT, 2 to 544021.27%1,46012.14%713,24913.25%
Mid MAT, 6 to 1035016.92%2,70722.51%1,225,95522.77%
Large MAT, 11 to 2024111.65%3,49829.09%1,341,87924.93%
Very large MAT, 21 to 501004.83%2,97124.71%1,132,47021.04%
Mega MAT, 51 or more70.34%4583.81%256,0514.76%

Seven mega-trusts run 458 schools, and IT support for schools is not built for them

At the top of the distribution sit seven mega-trusts of 51 schools or more, holding 3.81% of academies and 4.76% of academy pupils. The largest single trust on the register runs 96 schools with 70,467 pupils across 38 local authorities. At that scale IT support for schools stops resembling procurement and becomes an internal service organisation with a supplier panel — but the seven of them are 0.34% of trusts, which is precisely why the sector’s shared tooling is built for organisations a fiftieth of their size.

Mixed-phase trusts make IT support for schools hold two postures at once

Of the 1,138 MATs, 662 — 58.17% — run schools in more than one phase of education, and 557 — 48.95% — run both primary and secondary schools. That matters more for IT support for schools than the headcount does. A trust with both phases is running two safeguarding postures, two device models, two curriculum software stacks and two management information systems, and any standardisation programme has to hold both without flattening either.

Trust growth is the real driver of IT support for schools demand

Every conversion adds a school to a trust that already has an identity platform, a filtering contract and a device standard, and creates an integration project nobody budgeted for. The register shows the accumulated result: 11,094 schools inside multi-school trusts, the overwhelming majority of which joined an existing organisation rather than founding one. The dominant unit of work in IT support for schools today is not building a new estate but absorbing another school into an existing one.

The Domain Sprawl Finding IT Support for Schools Inherits

it support for schools e watering can body long spout

This is the most useful number we found, and as far as we can tell nobody publishes it. Every school on the register may publish a website address, and 22,454 of the 22,986 state-funded schools do — 97.69%. If you group those addresses by trust, you can measure how fragmented a multi-academy trust’s public digital estate actually is. The answer is: almost completely, and it defines the first year of any trust-wide IT support for schools engagement.

Only 2.64% of multi-academy trusts run their schools on one domain

Of the 1,138 MATs, exactly 30 — 2.64% — have every one of their schools on a single shared web domain. The mean MAT runs 9.30 distinct domains. And 1,022 of them — 89.81% — have a completely distinct domain for every single school, with no shared namespace at all. That is the estate IT support for schools walks into on day one of a trust engagement: not one organisation with one identity, but nine or twelve or twenty organisations wearing the same logo.

Three quarters of trusts run more than one domain suffix

Worse than the count is the inconsistency. Of the 1,138 MATs, 858 — 75.40% — publish schools under more than one top-level suffix: a .sch.uk here, a .co.uk there, an .org from the school that converted last year. Across the whole state-funded estate the mix is 32.06% sch.uk, 30.66% co.uk, 14.59% org.uk, 9.78% .org and 7.33% .com. Only 32.54% of schools sit inside the education or government namespace at all.

Domain suffix of the 22,454 state-funded schools publishing a website, England, 22 August 2026
sch.uk 32.06%
co.uk 30.66%
org.uk 14.59%
.org 9.78%
.com 7.33%
Everything else 5.58%

Why the domain count is really the identity count IT support for schools inherits

A web domain is rarely just a website. It is normally also the mail domain, which means it is the login suffix, which means it is a separate identity boundary. A trust with 9.30 domains is very often a trust with multiple tenants, multiple sets of conditional access rules, multiple password policies and multiple places a leaver’s account can survive. Every consolidation programme in IT support for schools begins here, whether the trust describes the problem this way or not. Nothing else in IT support for schools moves until the identity question is settled.

Domain fragmentation gives IT support for schools a safeguarding cost

If a pupil moves between two schools in the same trust, a single-tenant estate transfers the account. A nine-domain estate creates a new one and orphans the old. If a member of staff is dismissed, a single-tenant estate disables one identity. A nine-domain estate requires somebody to remember which of nine directories held them. The ICO reprimand issued to Finham Park Multi Academy Trust turned precisely on account controls, and account controls are much harder to hold consistent across nine namespaces than one.

Consolidation is a three-year programme for IT support for schools

Nothing about this is quick. Mail domains carry inbound parent correspondence, exam board registrations, safeguarding referrals and supplier contacts, so they cannot simply be switched off. The pattern that works in IT support for schools is to stand up a single trust identity platform first, then move schools into it one summer at a time, keeping the legacy domain live as a routed alias for at least two academic years. The register suggests almost the entire sector still has this work in front of it, which makes consolidation the defining project of IT support for schools this decade.

What to ask for before you sign anything for IT support for schools

Ask a prospective provider to give you the count first: how many domains, how many tenants, how many directories, how many filtering contracts, how many firewall vendors, how many backup products, how many management information systems. A provider of IT support for schools who cannot produce that inventory in the first fortnight is not going to produce it later either, and every consolidation estimate they give you before it exists is a guess.

Multi-Academy Trusts Are Not One Site, and the Numbers Prove It

it support for schools f door key round bow two teeth

The word “trust” implies a single organisation. Geographically it very often is not. We measured the spread of every multi-academy trust on the register by local authority, by region and by the greatest straight-line distance between any two of its schools.

Half of all MATs cross a local authority boundary

Of the 1,138 MATs, 567 — 49.82% — operate schools in more than one local authority, and 178 — 15.64% — operate in more than one English region. Seen from the school’s point of view rather than the trust’s, the effect is larger still: 7,637 of the 12,025 academies, or 63.51%, belong to a trust that spans more than one local authority, and those schools hold 3,243,254 pupils, or 60.25% of the academy population.

Which means a local authority service cannot deliver IT support for schools in a trust

This is the structural fact that decides how IT support for schools is bought at trust level. A local authority schools ICT service is scoped, priced and staffed for schools inside that authority. A trust with schools in three authorities cannot buy one service, cannot get one contract, and cannot get one escalation path for IT support for schools. The mean MAT spans 2.22 local authorities; 120 of them span three, 70 span four and 48 span five, with one trust spanning 38.

The median MAT estate is 20.8 km wide and the widest is 498.7 km

Distance matters because engineer travel is the single largest hidden cost in multi-site IT support for schools budgets. Measuring the greatest distance between any two schools in each of the 1,138 MATs gives a mean of 37.6 km and a median of 20.8 km. The seventy-fifth percentile is 46.1 km and the ninetieth is 83.3 km. The widest trust on the register spans 498.7 km between its two furthest schools — an estate that cannot be served by one van under any circumstances.

Share of the 1,138 multi-academy trusts whose estate spans more than a given distance
More than 10 km 70.39%
More than 25 km 45.34%
More than 50 km 23.02%
More than 100 km 6.85%
More than 200 km 1.93%

Onsite IT support for schools has to be modelled, not promised

Our modelled trust spans 46 km, the seventy-fifth percentile. One technician day per school per week across a 39-week academic year is 468 onsite days, which is between two and three full-time equivalents once travel, holidays and sickness are counted. Any proposal for IT support for schools that promises onsite cover without showing that arithmetic has not done it. Ask for the day count, the travel assumption and the named cover for absence.

Remote-first IT support for schools is the only design that scales

The corollary is that everything capable of being done remotely must be done remotely, so that onsite time is reserved for the things that genuinely need hands: cabling, hardware swaps, exam-hall setup and physical audits. Zero-touch device enrolment, cloud-managed wireless, remote firewall management and self-service password reset are not luxuries in multi-site IT support for schools. They are what makes the travel budget survive contact with a 46 km estate.

Standardisation is worth more to IT support for schools than to any other sector

Because the same fault appears twelve times. A trust running one wireless vendor, one firewall vendor, one device image and one backup product converts twelve investigations a year into one. Trusts that standardise usually find the saving is not in licence cost but in the collapse of variety: fewer runbooks, fewer vendor relationships, fewer surprises. This is the strongest argument for consolidating IT support for schools at trust level rather than leaving each school to buy locally.

The DfE Digital and Technology Standards IT Support for Schools Must Meet

England is unusual in having a written national specification for school technology. The Department for Education’s digital and technology standards for schools and colleges, last updated 24 June 2026, set out twelve areas, six of which are core. This is the document that turns IT support for schools from a matter of taste into a matter of compliance, and it should sit behind every specification.

Six core standards and a 2030 deadline for IT support for schools

The six core standards are broadband internet, network switching, wireless network, digital leadership and governance, filtering and monitoring, and cyber security. The Academy Trust Handbook 2026 puts the expectation in writing at paragraph 1.21: trusts “should be working towards meeting DfE’s digital and technology standards and meeting the 6 core standards by 2030”. Filtering and monitoring is carved out as already mandatory, because it also sits in statutory safeguarding guidance.

Six more standards sit inside any serious contract for IT support for schools

Beyond the six, the standards cover cloud solutions, digital accessibility, IT support itself, laptops and desktops and tablets, network cabling, and servers and storage. None of these carries the 2030 deadline, but all of them describe what a competent estate looks like. A specification for IT support for schools that does not reference them is being written from scratch when a national baseline already exists.

Core standardWhat it actually demandsEvidence a trust must be able to produce
Broadband internetFull fibre; 100Mbps down and 30Mbps up minimum for primary, 1Gbps for secondary and colleges; a backup connectionCircuit contracts, speed tests, failover test records
Network switchingManaged switching with the capacity and resilience to carry the wireless estateSwitch inventory, firmware versions, support status
Wireless networkCurrent wireless standards for performance, coverage, management and securityAccess point inventory, coverage survey, SSID and authentication design
Digital leadership and governanceA named senior leader and a named governor or trustee owning digitalRole descriptions, board minutes, reporting cadence
Filtering and monitoringBlocklists that cannot be overridden, annual checks, weekly monitoring reportsDated check records, monitoring reports, review minutes
Cyber securitySeven sub-standards: risk assessment, awareness, anti-malware and firewall, accounts, updates, backup, reportingRisk register, training completion, patch reports, backup tests

Broadband: the numbers IT support for schools has to hit

The broadband standard is explicit. Primary schools need “a minimum of 100Mbps download speed and a minimum of 30Mbps upload speed”. Secondary schools, all-through schools and further education colleges need a connection capable of “1Gbps download and upload speed”. Broadband “should be provided using a full fibre connection”, and a backup connection is required, delivered through “multiple broadband connection services of different service types” with routers configured for automatic failover.

The upload figure is the one that catches people out

Schools have historically bought asymmetric consumer-shaped circuits because download is what feels visible. The standard names upload explicitly, and upload is what cloud backup, video lessons, CCTV offload and Teams calls actually consume. When IT support for schools reviews an estate against this standard, the failure is far more often the 30Mbps upload floor than the 100Mbps download one, and the fix is a circuit change rather than a configuration change.

A backup connection means a different service type, not a second contract

Two fibre circuits into the same building, down the same duct, from the same wholesale provider, are one circuit with extra billing. The standard asks for different service types precisely to defeat that. In practice this means a fibre primary with a 4G or 5G failover, or a fibre primary with a fixed wireless secondary — and a router configuration that has actually been tested to fail over, with the test written down by whoever provides IT support for schools.

Standards compliance is a procurement lever for IT support for schools

Because the standards exist and are public, a trust can specify against them rather than negotiating from a vendor’s brochure. The strongest requests for proposal in IT support for schools quote the standard, ask the bidder to state compliance line by line, and require the evidence artefact for each. That converts a subjective comparison of providers into a checkable one, which is exactly what an accounting officer needs.

The Seven Cyber Security Standards, Read as a Contract

The cyber security standards for schools and colleges are the most operationally detailed part of the whole framework. Read them as a service specification and most of a contract for IT support for schools writes itself, standard by standard.

Standard one: risk assessment annually, reviewed every term

The first standard asks schools to review digital assets and cyber risks annually with termly reviews, maintain a record of processing activities for systems holding personal data, assess staff access and permissions, keep network documentation current, and put a cyber response plan in place. The DfE notes that the response plan “is also a condition of cover if you have risk protection arrangement (RPA) cover” — which turns a good-practice item into a claims-validity item.

Standard two: a cyber awareness plan, with training at least annually

Training “should be given at least annually, or more regularly if there is a known cyber risk” and must cover phishing, password security, online safety, social engineering, physical device security, removable media, multi-factor authentication, incident reporting, data breach reporting and data protection. Staff, governors, trustees and temporary workers are all in scope of the awareness plan that IT support for schools has to evidence, and students need age-appropriate equivalents. For RPA members, the free NCSC training must be evidenced annually.

Standard three: centrally managed anti-malware and a properly configured firewall

Anti-malware “must include anti-virus” on all devices, “centrally managed, actively monitored and kept up to date”, scanning web pages, files on access and email attachments, with alerts routed to IT support and USB storage prohibited by default. The firewall must protect against denial of service, have its default administrator password changed, have multi-factor authentication on its administrative interface, block inbound unauthenticated connections by default, and have its firmware checked termly.

Standard four: multi-factor authentication is not optional any more

The account standard is blunt. MFA “must be enabled for all staff accounts with access to cloud services or remote access to on-site systems” and for “IT administrative accounts”. Users must be authenticated with unique credentials, password strength enforced at system level, compromised passwords changed immediately, and accounts protected by lockout after no more than ten failed attempts. Accounts must be disabled immediately on departure and reviewed termly, which makes joiner and leaver automation a core deliverable of IT support for schools.

Standard five: fourteen days to patch, and it is written down

This is the hardest single line in the standards for most schools: “IT support must complete vulnerability fixes for operating systems, applications and firmware within 14 days of the fix being released” where the vendor rates the vulnerability critical or high risk, or the CVSS v3.1 base score is 7.0 or above, or no severity rating is given. Devices that cannot be patched must be isolated. The breach survey says only 45% of primary schools manage this, and closing that gap is the highest-value thing IT support for schools can automate.

Standard six: 3-2-1 backups, immutable, and never taken home

The backup standard cites the National Cyber Security Centre: three copies of the data, two on separate devices, one off-site, far enough away to survive fire, flood and theft. Backups must be tested termly or after significant change, and “must be immutable, this means that they cannot be changed once they have been created”. Physical backups must be encrypted if taken off-site, and the standard is explicit that “backups should never be taken to anyone’s home”.

Standard seven: report attacks, and to more places than you think

Incidents go to IT support and the senior leadership digital lead internally, then externally to Action Fraud and to “the DfE sector cyber team at [email protected]”. Also in scope: the RPA or commercial cyber insurer, the NCSC where there is long-term closure or multi-school impact, the ICO within 72 hours for high-risk personal data breaches, and Jisc for further education. IT support for schools should hold that list inside the response plan, not in somebody’s memory.

What the Breaches Survey Says About IT Support for Schools

The government surveys the education sector every year, and the 2025/2026 results published on 30 April 2026 are the best single evidence base for what school technology actually looks like. The headline is that schools are attacked at rates far above the general business population, and that the gap between phases is enormous.

Half of primaries and three quarters of secondaries identified an attack

Among the 273 primary schools surveyed, 49% identified a breach or attack in the previous twelve months. Among 222 secondary schools it was 73%, among 33 further education colleges 88%, and among 49 higher education institutions 98%. Secondary schools rose from 60% the year before to 73% — a jump of 13 points, or 21.67% in a single year. Whatever IT support for schools was doing in 2024 is no longer sufficient at secondary level, and the trend line is going the wrong way.

Identified a cyber breach or attack in the last 12 months, education institutions, 2025/2026
Higher education institutions 98%
Further education colleges 88%
Secondary schools 73%
Secondary schools, previous year 60%
Primary schools 49%

Phishing is the attack, and everything else is a rounding error

Of institutions identifying any breach, 90% of primaries, 96% of secondaries and 96% of further and higher education reported phishing. Impersonation follows at 31%, 44% and 79%. Malware sits at 11%, 15% and 51%. Ransomware was reported by 0% of primaries, 6% of secondaries and 14% of further and higher education. Any budget for IT support for schools that spends more on exotic controls than on mail security and staff awareness is misallocated.

Insider access is a real and phase-dependent problem

Unauthorised access to files or networks by staff was reported by 2% of primaries, 12% of secondaries and 29% of further and higher education. Unauthorised access by students was reported by 1%, 10% and 23%. Those student numbers are the reason IT support for schools cannot treat pupil accounts as inherently low-risk: in a secondary school, one in ten breach-reporting institutions had a pupil get somewhere they should not.

The basic controls are universal, and the ones IT support for schools supplies are not

Malware protection sits at 95% in both primary and secondary. Firewalls 96% and 96%. Restricted admin rights 98% and 99%. Password policy 95% and 97%. Two-factor authentication 89% and 86%. Cloud backup 86% and 90%. These are good numbers. The problem is everything that requires ongoing effort rather than a one-off purchase, and that is precisely the layer IT support for schools is bought to supply.

Control or activityPrimarySecondaryFE collegeHigher education
Malware protection95%95%100%100%
Boundary firewall96%96%100%96%
Two-factor authentication89%86%94%98%
Cloud backup86%90%79%86%
Patch within 14 days45%62%73%84%
Security monitoring tools51%66%79%96%
Mock phishing tests51%61%88%71%
Vulnerability audit40%46%55%80%
Penetration testing23%38%52%84%
Reviewed supplier cyber risk42%47%48%80%
Formal incident response plan73%77%79%92%
Cyber Essentials awareness20%57%85%98%

Patching is the number IT support for schools should act on first

Only 45% of primary schools and 62% of secondary schools apply software updates within fourteen days, against a DfE standard that says fourteen days is the requirement. That is more than half of primary schools failing a written national standard on the single control that closes the most exploited attack path. Any credible proposal for IT support for schools should lead with automated patch management and a monthly compliance report, not with a helpdesk response time.

Cyber Essentials awareness in primary schools is 20%

Only one in five primary schools has even heard of Cyber Essentials, against 57% of secondaries, 85% of colleges and 98% of universities. Across ten comparable controls, the mean gap between higher education and primary schools is 45.00 percentage points, with the widest on Cyber Essentials awareness at 78 points, threat intelligence at 74 and penetration testing at 61. The sector’s weakest estates are also its least informed buyers of IT support for schools.

Which is why most primaries already buy IT support for schools externally

The survey records that 77% of primary schools use an external provider to manage their cyber security, against 54% of secondary schools, 36% of colleges and 51% of universities. Primary schools have concluded — correctly — that a 225-pupil school with twenty-seven adults cannot run this in house. The question at that end of the market is not whether to buy IT support for schools, it is how to tell a good provider from a bad one.

Unprotected personal data is the quiet failure

Asked whether they hold personal data that is not protected by anonymisation or encryption, 14% of primary schools, 18% of secondary schools, 27% of colleges and 49% of universities said yes. In a school, that data is about children. It is the single line in the survey most likely to turn a routine IT support for schools incident into a reportable one, and it is entirely fixable with the encryption and information protection tooling most schools already own but have never configured.

Filtering and Monitoring: The Standard IT Support for Schools Gets Wrong

Filtering and monitoring is the only technology standard that is also statutory safeguarding guidance, which makes it the one with the sharpest consequences. It appears in the DfE digital standards and in Keeping Children Safe in Education, and the two documents have converged on the same expectation: leadership oversight, documented checks, and evidence.

There are four filtering and monitoring standards, and the first is about people

The filtering and monitoring standards begin by assigning roles: governors or proprietors hold “overall strategic responsibility”, a named senior leader and a named governor are “responsible for ensuring these standards are met”, the designated safeguarding lead leads on safeguarding and checks reports, and IT support — in-house or third party — maintains the systems and provides the reports. IT support for schools is named in the standard, but it is not the accountable party, and no contract can transfer that accountability.

Reviews happen at least once every academic year, and on trigger events

Provision must be reviewed “at least once every academic year”, and additionally after safeguarding incidents, changes to working practices, the introduction of new technology, major software updates or network configuration changes. The review is done by the responsible senior leader, the DSL, IT support and the responsible governor together. Keeping Children Safe in Education 2026 reinforces this at paragraph 171 and — for the first time — explicitly requires schools to keep records of those filtering checks.

Blocklists cannot be overridden by anyone, including IT

Filtering systems must implement blocklists from the Internet Watch Foundation and the Counter Terrorism Internet Referral Unit, and those “cannot be disabled, overridden, or altered by any user”. This applies to school-managed devices, bring-your-own-device schemes and guest access alike. Systems must be able to identify “device name or ID, IP address, and where possible, the individual” — which quietly requires that filtering be identity-aware rather than purely network-based.

Monitoring means weekly reports and immediate high-risk alerts

The monitoring standard sets a floor of “weekly monitoring reports highlighting incidents”, with “immediate reports when an incident is classed as high-risk”. Devices with mobile and app content need a technical monitoring system applied to the device rather than the network, because network-level filtering cannot see inside an app on a 4G connection. This is where a lot of otherwise-good IT support for schools quietly fails the standard.

Off-network devices are the gap IT support for schools most often misses

A laptop taken home leaves the school firewall behind. If filtering is delivered only at the network boundary, that device is unfiltered from the moment it reaches the front door. Meeting the standard requires an agent or DNS-level control that travels with the device, tied to the pupil identity. Where a trust runs 1:1 devices, this is not an optional extra for IT support for schools — it is the majority use case.

The evidence pack is what IT support for schools actually delivers here

What an inspector or a trust board actually asks for is dated proof: the annual check record, the weekly monitoring reports, the incident log, the review minutes and the role descriptions naming the responsible leader and governor. A provider of IT support for schools should be producing that pack on a schedule without being chased, because the school’s ability to demonstrate compliance is the thing being bought.

Safeguarding Records and the Retention Clocks That Outlive Everyone

School data has the longest retention profile of any sector we write about outside healthcare. The clocks are set by a mixture of statutory instruments, the Academy Trust Handbook and the IRMS Information Management Toolkit for Schools, and they run from three days to forty years. Designing storage and backup for IT support for schools without them is guesswork, and expensive guesswork at that.

The pupil record runs to the pupil’s twenty-fifth birthday

The IRMS toolkit is unambiguous: “The Pupil Record should be retained as a whole for 25 years from the date of birth of the pupil, after which time, if no longer required, it can be deleted or destroyed.” For a child who starts reception at four, that is twenty-one years after they leave your primary school. Child protection records follow the same clock — date of birth plus 25 years, then review — agreed in consultation with safeguarding bodies.

SEN records run six years longer than that

Special educational needs and other support service records “can be retained for a longer period of 31 years to enable defence in a ‘failure to provide a sufficient education’ case”. Thirty-one years from date of birth is longer than most schools have existed in their current legal form, longer than any storage platform’s product lifetime, and vastly longer than the retention of the management information system the data was created in.

The Academy Trust Handbook adds a six-year funding clock

Separately from pupil data, paragraph 6.5 of the handbook requires that the trust “must retain records to verify provision delivered by it, or its sub-contractors, in relation to this handbook and its funding agreement, at least 6 years after the period to which funding relates”. That covers finance systems, procurement records, payroll and contract files — a completely different data set from the safeguarding one, with its own clock.

And the employers’ liability certificate runs forty years past closure

The longest clock in the schedule is not about children at all. Employers’ liability insurance certificates are retained for “closure of the school + 40 years”. Staff records where there has been negligence or a claim of child abuse are held for “at least 15 years”. Meanwhile a DBS check on a governor is destroyed at “date of DBS check + 6 months” — a near-zero maximum sitting in the same filing cabinet as a forty-year minimum.

RecordRetentionSourceWhat it means for the IT estate
High-risk personal data breachReport within 72 hoursUK GDPRDetection and triage must be same-day, not next-term
DBS check on a governorDate of check + 6 monthsIRMS toolkit 1.2.8Needs scheduled deletion, not indefinite storage
Successful admission recordDate of admission + 1 yearIRMS toolkit 3.1.2Admissions data must be separable from the pupil record
Attendance register entry3 years from the entryDfE attendance guidanceRegister data has a shorter clock than the pupil file
Trust funding and provision records6 years after the funding periodAcademy Trust Handbook 6.5Finance archives outlive finance systems
Staff personnel fileEnd of appointment + 6 yearsIRMS toolkit 2.3.1Leaver data cannot be deleted with the mailbox
Staff records, child abuse claimAt least 15 yearsIRMS toolkit 2.3.1Legal hold must be a supported feature, not a folder
Pupil record and child protection fileDate of birth + 25 yearsIRMS toolkit, pupil record guidanceSurvives every platform migration you will ever do
SEN and support service records31 yearsIRMS toolkit, pupil record guidanceThe longest child-data clock in the schedule
Employers’ liability certificateClosure of the school + 40 yearsIRMS toolkit 2.5.1Outlives the organisation that created it

Scaled against one another, the clocks are absurd and that is the point

Take the twenty-five year pupil record as the baseline. Counting back from 22 August 2026, twenty-five years is 9,131 days. Against that, the 72-hour breach notification is 0.03% of the clock. A governor DBS check at six months is 2.02%. An attendance register entry at three years is 12.00%. The handbook’s six-year funding record is 24.01%. The fifteen-year staff record is 60.00%. SEN records at thirty-one years are 124.01%, and the employers’ liability certificate at forty years past closure is 160.00%.

Retention clocks scaled against the 25-year pupil record (9,131 days), measured from 22 August 2026
Breach notification, 72 hours 0.03%
Governor DBS check, 6 months 2.02%
Attendance register entry, 3 years 12.00%
Trust funding records, 6 years 24.01%
Staff records, abuse claim, 15 years 60.00%
Pupil record, date of birth + 25 years 100.00%
SEN support records, 31 years 124.01%
Employers’ liability, closure + 40 years 160.00%

What the clocks mean for backup design in IT support for schools

No school should be planning to hold a thirty-one-year record inside a management information system with a five-year contract. The design that survives is to separate the long-clock records into an archive with its own retention labels and its own export path, and to treat the operational system as somewhere data lives temporarily. IT support for schools that does not distinguish backup from archive will fail one of these clocks eventually, and it will fail it silently.

The Academy Trust Handbook and the Trustee Who Signs

For a trust, technology risk is governed by a document most IT providers have never read. The Academy Trust Handbook 2026, effective from 1 October 2026, is the rulebook the accounting officer answers to, and it has become noticeably more explicit about cyber.

Cybercrime has its own paragraph now

Paragraph 6.14 states that “academy trusts must also be aware of the risk of cybercrime, put in place proportionate controls and take appropriate action where a cyber security incident has occurred”, and that trusts “should take appropriate action to meet DfE’s cyber security standards”. That single paragraph makes the digital standards a governance matter rather than an IT preference, and it is the paragraph to quote when a board asks why the budget is going up.

Trusts must not pay a ransom, and that changes the recovery design

Paragraph 6.15 is unusually direct: “Trusts must not pay any ransom or extortion demands, including cyber ransomware.” The handbook cites the National Crime Agency’s position that payment has no guarantee of restoring access and is likely to result in repeat incidents. For IT support for schools this removes an option that commercial organisations retain, and it makes tested, immutable, offline-capable backup the only recovery path that exists.

Fraud, theft and irregularity above £5,000 must be reported to the DfE

Paragraph 6.10 requires the board to notify the DfE “as soon as possible of all instances of fraud, theft or irregularity exceeding £5,000 individually, or £5,000 cumulatively in any financial year”, with unusual fraud reportable regardless of value. The notification must include dates, the financial value, measures taken to prevent recurrence, whether the police were involved, and whether insurance or the RPA offset the loss. A successful invoice fraud is squarely within that.

The risk register is mandatory and the board must review it annually

Paragraph 2.43 requires that “the trust must maintain a risk register”, with ultimate oversight retained by the board, frequent review and “a full review of it at least annually”, covering “the full operations and activities of the trust, not only financial risks”. Paragraph 2.44 adds that risk management “must include contingency and business continuity planning”. Cyber risk belongs on that register with a named owner, and IT support for schools should be supplying the entries and the monthly movement.

Internal scrutiny will audit the controls IT support for schools delivers

Paragraph 3.1 requires “a programme of internal scrutiny to provide independent assurance to the board that its financial and non-financial controls and risk management procedures are operating effectively”. Non-financial controls include access management, backup and filtering. That is a formal, recurring audit of the things IT support for schools is contracted to deliver, and the provider should expect to produce evidence for it every year.

Delegated authority limits shape how you buy IT support for schools

Paragraph 5.20 sets delegated limits for certain transactions at “1% of total annual income or £45,000 (whichever is smaller) per single transaction” and 2.5% of annual income cumulatively, subject to a £250,000 ceiling. Those limits do not apply to ordinary operational procurement, but they set the board’s mental model of what needs approval. Structuring IT support for schools as a predictable annual operating cost, rather than lumpy capital events, is easier to govern and easier to approve.

RPA Cyber Cover and the Four Conditions That Void a Claim

Most academy trusts are members of the DfE’s risk protection arrangement rather than holding commercial insurance. Paragraph 2.45 of the handbook requires “adequate insurance cover in compliance with its legal obligations or be a member of the academies risk protection arrangement”. The RPA includes cyber cover — and that cover has conditions.

The four conditions are specific and technical

To be covered, a school must have offline backups, ensure staff and governors with access to IT systems complete NCSC cyber security training annually, register with Police CyberAlarm, and have a cyber response plan in place. These are not aspirations in a policy document; the DfE describes them as conditions of cover. IT support for schools that does not track all four conditions is leaving the trust exposed on the day it matters most.

“Offline” means offline, not “in a different cloud”

The requirement is at least three copies of important data, on two separate devices, with one held off-site and entirely offline. A second copy in the same cloud tenant, reachable with the same credentials, is not offline. Neither is an immutable snapshot that a global administrator can delete. Meeting this condition normally means either an air-gapped copy or immutable storage in a separate trust boundary with independent credentials.

Governors with a trust mailbox are in scope for training

The rule that surprises boards is that a governor or trustee holding a school or trust email account counts as having access to the IT system, and therefore must complete the NCSC training annually. In our modelled trust that is 108 governors and trustees on top of 609 staff — 717 people whose training completion has to be evidenced, refreshed every year, and produced if a claim is made.

Evidence is what gets tested, and IT support for schools produces it

The point at which these conditions are examined is a claim. If a phishing incident leads to a claim and the trust cannot evidence that the people involved completed the training, the claim may be invalid. That makes training completion reporting a core deliverable of IT support for schools, not an HR afterthought, and it should appear in the monthly service report alongside patch compliance and backup success.

A cyber response plan is both a standard and a condition

The response plan appears twice: as part of cyber security standard one, and as an RPA condition of cover. It needs to name who declares an incident, who contacts the DfE sector cyber team and Action Fraud, who assesses whether the ICO’s 72-hour clock has started, how the school communicates with parents without its own mail system, and what the manual fallback is for registration, safeguarding and catering. Rehearse it once a year, in a room, on paper.

Microsoft 365 Licensing for Schools: A1, A3 and A5

Almost every state-funded school in England runs Microsoft 365, Google Workspace, or both. The licensing decision is the single largest recurring technology cost most trusts have, and it is routinely made once and never revisited. This is what IT support for schools should be putting in front of a finance committee every year.

A1 is free, and that is genuinely most of what a school needs

Microsoft 365 Education A1 is provided free to eligible institutions and gives web-based Office applications, Teams, Exchange Online and the core education services. For the 5,160 pupils in our modelled trust, A1 costs nothing and covers essentially everything a pupil does. The temptation to licence pupils higher is almost always wrong; the money belongs on the adult accounts, where the risk and the administrative burden sit.

A3 and A5 are the adult tiers, and Microsoft publishes them in dollars

Microsoft’s published education list prices are in US dollars: A3 at $3.25 per user per month and A5 at $8.00 per user per month for faculty, with A1 free. Microsoft does not publish a sterling education list price — UK schools buy through resellers and framework agreements — so the dollar list is the only first-party anchor, and every sterling quote you receive should be tested against it.

The three-way comparison for a 717-adult trust

Modelled on those published figures, putting all 717 adult accounts on A3 costs $27,963.00 a year. Putting all 717 on A5 costs $68,832.00. The tiered option — 609 staff on A3 and the 108 governors and trustees left on the free A1 — costs $23,751.00, which is 34.51% of the all-A5 bill. The step from A3 to A5 across all adults is $40,869.00 a year, or $57.00 per adult.

Modelled annual licence cost, 717 adult accounts, as a share of the all-A5 option (Microsoft published USD education list)
All adults on A5, $68,832 100.00%
All adults on A3, $27,963 40.62%
609 staff on A3, 108 governors on A1, $23,751 34.51%
Everyone on the free A1 grant, $0 0.00%

What the free tier quietly leaves out

A1 does not include installed desktop Office applications, and — far more importantly for IT support for schools — it does not include the advanced identity, endpoint management and threat protection features that the DfE cyber standards effectively assume. Conditional access policies, risk-based sign-in, endpoint detection and response, data loss prevention and advanced audit all sit in the paid tiers. A trust running everything on A1 is meeting standard four with the free MFA and very little else, which leaves IT support for schools without the tooling the other standards assume.

CapabilityA1 (free)A3A5Which DfE standard it serves
Web Office, Teams, mailYesYesYesCloud solutions
Installed desktop Office appsNoYesYesLaptops, desktops and tablets
Basic multi-factor authenticationYesYesYesCyber security, standard 4
Conditional access policiesNoYesYesCyber security, standard 4
Endpoint management and complianceNoYesYesCyber security, standards 3 and 5
Endpoint detection and responseNoNoYesCyber security, standard 3
Risk-based sign-in protectionNoNoYesCyber security, standard 4
Advanced audit and retention labelsNoPartialYesRetention and data protection
Per-user cloud storage ceiling100 GBUp to 1 TBUp to 1 TBCloud solutions, backup

A mixed-tier licence estate is usually right for IT support for schools

The pattern that survives scrutiny in most trusts is: pupils on A1, teaching and support staff on A3, and a small population on A5 — the senior leadership, the finance team, the data protection officer, the safeguarding leads and every administrative account. That puts the strongest identity and threat protection where the highest-value targets are, without buying it for a thousand children who do not need it.

Google Workspace changes the arithmetic for IT support for schools, not the standards

A large minority of schools run Google Workspace for Education Fundamentals, which is also free, with paid Standard and Plus tiers above it. The comparison is genuinely close, and the deciding factors are usually the management information system’s integration, the device estate and the staff’s existing skills. What does not change is the standard: filtering, monitoring, MFA, patching within fourteen days and 3-2-1 backup apply identically whichever platform IT support for schools is running.

The Storage Cliff Every Trust Hits

In 2024 Microsoft rewrote education storage from generous per-user allocations to a pooled tenant model. Most trusts have not yet run the arithmetic, and the ones that have not are the ones who will discover the ceiling during a term-time incident rather than during a planning meeting.

The pooled model in one paragraph

Every education tenant receives 100 TB of free pooled storage across OneDrive, SharePoint and Exchange, plus an additional 50 GB per paid A3 user and 100 GB per paid A5 user. Individual A1 users are capped at 100 GB of OneDrive within that pool. Additional storage is purchasable in 10 TB increments at an estimated $300 per month, which is $3,600 a year per increment.

Our modelled trust has 129.74 TB and is using 14.18% of it

For the twelve-school trust: 100 TB base, plus 609 A3 users at 50 GB each, gives 132,850 GB — 129.74 TB. Modelling demand at 1.5 GB per pupil, 12 GB per adult and 2,500 GB of shared SharePoint content gives 18,844 GB, or 18.40 TB. That is 14.18% of the entitlement, which sounds comfortable and is, for now.

It is video and photography that closes the gap, not documents

Coursework documents are tiny. What consumes an education tenant is media: drama and music recordings, sports days, PE video analysis, photography and design coursework, safeguarding CCTV exports, and Teams meeting recordings that nobody ever deletes. A single secondary school’s media growth can outrun its entire document estate. IT support for schools should be reporting pooled tenant consumption monthly with a trend line, not annually with a total.

The A1 100 GB cap is a per-pupil landmine

An A1 pupil is capped at 100 GB of OneDrive. That is generous until a media or games design course starts, at which point a handful of pupils hit the ceiling mid-project and the school discovers the cap during a deadline week. The fix is either a targeted A3 allocation for those courses or a shared project library with its own quota, and it needs deciding in September rather than in May.

Leavers are the biggest unmanaged storage consumer IT support for schools sees

Every year a school loses a cohort. If those OneDrive accounts are never archived or removed, the pool carries them forever. A trust of this size loses roughly 700 pupils a year; at 1.5 GB each that is about 1 TB annually of pure accumulation. A leaver process that archives, then removes, is worth more storage than any purchase, and it is exactly the kind of unglamorous automation IT support for schools should own.

Identity, MFA and Joiners and Leavers at School Scale

Identity is where the school-specific difficulty concentrates. The estate has thousands of accounts, an annual mass intake, an annual mass departure, a substantial supply-teacher population, and a governance layer of volunteers with mailboxes.

The joiners problem makes IT support for schools seasonal and enormous

In September a secondary school creates several hundred accounts in a week, each needing the right year group, the right filtering profile, the right software entitlements and the right storage quota. Doing that by hand is where errors enter the estate and never leave. Automated provisioning driven from the management information system is the single highest-value automation available to IT support for schools, and it pays for itself in one September intake.

The leavers problem is where the ICO finds you

Finham Park Multi Academy Trust received an ICO reprimand on 7 December 2023 under Articles 5(1)(f) and 32(1)(b) after “an unauthorised third party utilised compromised credentials to access and encrypt Finham Park’s systems”. The ICO recorded that 1,843 UK data subjects were affected and found the trust “did not have adequate account lockout or password policies in place”. Account hygiene is not a tidiness issue; it is the enforcement issue.

Supply staff and contractors need a shape of their own

A supply teacher may work three days in one school in a nine-school trust. Giving them a permanent account is wrong; giving them a shared one is worse. The pattern that works is a time-boxed guest or sponsored account with an automatic expiry date, scoped to one school, with no access to management information or finance systems, reviewed at the termly account review the cyber standard already requires.

Governors need mailboxes, and mailboxes need the full control set

The RPA training rule exists because a governor mailbox is a real identity with real access. It receives board papers, safeguarding summaries, financial reports and pupil-level information. It should carry MFA, conditional access, a retention policy and an offboarding process the same as any staff account. In practice this is often the least-managed population in the estate, and it is the one with the most sensitive inbox.

Termly account reviews are a standard requirement, not best practice

Cyber security standard four requires that accounts are reviewed termly and that “global or administrative accounts are not used for routine business”, with a process so that “a member of SLT or a trustee approves any changes to access levels or privileges”. Three reviews a year, evidenced, is the deliverable. IT support for schools should be producing the review list and the exception report; the school approves it.

Privileged access is the control IT support for schools most often finds missing

Almost every school has more administrators than it needs, usually because a technician left and nobody removed the account, or because a supplier was given global rights for a project in 2019. Break-glass accounts, just-in-time elevation and a named approval route are all achievable on the paid tiers. Counting the administrators is a five-minute job and it is the first thing a competent provider of IT support for schools does.

Devices: 1:1, Trolleys, BYOD and the Six-Week Window

The device estate is the most visible part of IT support for schools and the part with the most money tied up in it. It is also where the sector’s funding constraint shows most clearly, because devices are capital and capital is what schools have least of.

School-owned is the default, and free school meals is why

Across the estate, 82% of primary schools and 58% of secondary schools allow only organisation-owned devices on the network. With a mean free school meals eligibility of 26.87%, a bring-your-own-device policy in most English schools is a policy that excludes a quarter of the cohort. Trusts that have tried BYOD at scale have generally ended up funding a loan pool anyway, which is the expensive route to a school-owned estate.

Trolleys are cheaper per pupil and worse per lesson

A charging trolley of thirty devices shared across a year group costs a fraction of a 1:1 deployment and produces a characteristic set of faults: flat batteries, misplaced units, damaged charging leads and lessons that lose ten minutes to distribution. A 1:1 estate costs several times more and removes almost all of that. The honest framing from IT support for schools is simple: trolleys buy hardware and 1:1 buys teaching time.

Zero-touch enrolment is what makes the summer fit for IT support for schools

Twelve schools refreshing a third of their devices means several hundred machines to build in six weeks. Manual imaging cannot absorb that. Devices should arrive registered to the tenant, enrol themselves on first boot, receive their configuration, applications and filtering profile automatically, and be usable by a teacher without a technician touching them. This is the difference between a summer that finishes and one that does not.

Device lifecycles in IT support for schools run longer than vendors assume

Most trusts run devices for five to six years, well past the three-year commercial norm, because the funding to do otherwise does not exist. That has direct security consequences: older devices fall out of firmware support, cannot run current endpoint protection, and eventually cannot receive the operating system updates that standard five demands within fourteen days. A written end-of-support register, per model, is the artefact that turns this from a surprise into a plan.

Interactive panels, cameras and door entry are all on the network too

The device estate is not just laptops. Interactive whiteboards and panels, visualisers, CCTV, door entry, cashless catering tills, print devices, sports timing systems and building management controllers all sit on the network with their own firmware, their own default credentials and their own vendors. Standard three’s requirement to keep firmware up to date and check it termly applies to every one of them, and IT support for schools should hold that inventory. Most inventories do not include them.

Exam season is a hard deadline IT support for schools cannot move

Digital exams, on-screen assessment and coursework submission windows create a second immovable date each year. Devices, network, printing and identity all have to be verified before it, and no change should land during it. A change calendar for IT support for schools that does not blank out the exam window is a calendar that has not met a head of exams.

Network, Broadband and Wireless Under the Standards

Three of the six core standards are network standards, which tells you where the DfE thinks the sector’s weakness is. It is also the area where a trust gets the largest benefit from buying once rather than twelve times.

Wireless is the school network that IT support for schools really runs

In a modern school almost every device is wireless. A secondary school with 1,045 pupils may have 1,200 concurrent wireless clients in a single period, concentrated in teaching blocks and collapsing to nothing at break. That is a density problem for IT support for schools, not a coverage problem, and it is solved with access point placement, channel planning and per-radio client limits rather than with more transmit power.

Coverage surveys are worth more than access point counts

Schools are built of brick, concrete, plasterboard and — in older buildings — solid stone. Coverage cannot be inferred from a floor plan. A pre-deployment survey and a post-deployment validation are cheap relative to a failed rollout, and they produce the artefact that the wireless standard implicitly expects. Any proposal for IT support for schools that quotes a number of access points without a survey is quoting a guess.

Segmentation is a safeguarding control as much as a security one

Guest wireless, pupil wireless, staff wireless, building management, CCTV, catering and door entry should not share a broadcast domain. Beyond the obvious security argument, segmentation is what allows filtering and monitoring to be applied differently to different populations — which is exactly what the filtering standard requires when it asks that systems identify the device and, where possible, the individual.

Switching and cabling are where the standards get expensive

The switching standard asks for managed switching with the capacity and resilience to carry the estate; the cabling standard covers copper and fibre. In practice this is where a school with a 2011 refurbishment discovers that its risers cannot carry current power-over-Ethernet loads, or that its fibre backbone is a single run through a corridor. These are capital projects with long lead times, and they belong in a three-year plan produced by IT support for schools rather than in a quotation.

Failover has to be tested, and the test has to be dated

A backup broadband connection that has never been failed over is a line on an invoice. The standard asks for automatic failover through appropriate router configuration; the evidence is a dated test record showing the primary was taken down and service continued. Run it in the summer, run it again in February, and put both in the evidence pack.

The trust network estate is where IT support for schools standardisation pays first

Twelve schools with four firewall vendors, three wireless vendors and two switch vendors is not an estate, it is a collection. Standardising on one of each converts twelve renewal negotiations into one, twelve firmware processes into one and twelve escalation paths into one. It is the clearest single saving available in multi-site IT support for schools, and it is realised over three to five years as contracts expire.

Backup, Ransomware and the Rule That Trusts Must Not Pay

Because paying is prohibited, recovery is the only strategy an academy trust has, and IT support for schools has to be designed around that fact. That single fact should reorganise how a trust spends its security budget.

3-2-1, immutable, tested termly

Standard six is precise: three copies, two on separate devices, one off-site and far enough away to survive fire, flood and theft. Backups “must be immutable”, tested termly or after significant change, encrypted if taken off-site, and never taken to anyone’s home. The RPA adds that the off-site copy must be entirely offline. Those are compatible requirements, but only if the design starts from them.

What IT support for schools actually has to back up is longer than your list

The management information system, the finance system, the safeguarding system, the cashless catering database, the library system, the assessment platform, the CCTV archive, the door entry configuration, the wireless controller configuration and the firewall rule base. Most school backup scopes cover the first two and assume the rest are “in the cloud”. Cloud tenancy is not backup, and the software as a service contract almost never says it is.

Microsoft 365 data needs its own backup decision

Retention policies are not backup. The recycle bin is not backup. A ransomware event that encrypts files synced to OneDrive will happily replicate the encrypted versions. A trust needs an explicit decision, written down, about whether third-party backup of the tenant is in scope, and if it is not, what the recovery path is. This is one of the most common gaps IT support for schools finds during a first-term onboarding.

Recovery time for IT support for schools has to be expressed in school terms

“Four-hour recovery time objective” means nothing to a headteacher. “Registration can be taken on paper for one day, catering can run on a manual list for one day, and safeguarding referrals go by phone to the DSL” means something. Map each critical system to what the school does without it, for how long, and at what point the day becomes unsafe rather than merely inconvenient. That mapping is the business continuity plan the handbook requires at paragraph 2.44, and IT support for schools should write it with the school rather than for it.

Test restores, not backup jobs

A green backup report proves a job ran. It does not prove the data is recoverable, that the restore fits in the window, or that anybody knows the procedure. Restore one meaningful system per term, time it, and write down the result. Termly testing is what standard six asks for, and it is the only backup metric worth reporting to a board.

Ransomware in schools is rarer than phishing but far from theoretical

The survey records ransomware at 0% of primary schools, 6% of secondary schools and 14% of further and higher education among those identifying a breach. Low, but the consequence is total, and the handbook removes the payment option entirely. A trust that cannot restore is a trust that rebuilds from nothing during term time, which is why the backup line in a contract for IT support for schools deserves more scrutiny than the helpdesk line.

Data Protection the Trust Has to Evidence

Schools process some of the most sensitive personal data in the country, about people who cannot consent for themselves, and they do it under the same UK GDPR as everybody else. Two ICO cases define the practical boundaries for the sector.

The Finham Park case is about account controls

The 7 December 2023 reprimand against Finham Park Multi Academy Trust followed compromised credentials being used to access and encrypt systems, affecting 1,843 data subjects, with the ICO finding inadequate account lockout and password policies. It is the clearest available statement that basic identity hygiene in IT support for schools is a regulatory requirement, not a preference.

The Chelmer Valley case is about doing an assessment first

On 22 July 2024 the ICO reprimanded Chelmer Valley High School under Article 35(1) because “the school failed to complete a Data Protection Impact Assessment (DPIA) prior to introducing facial recognition technology for the purposes of cashless catering”. The technology was not the problem; deploying it without an assessment was. Any new system touching pupil biometrics, location, behaviour or monitoring needs a DPIA before procurement, not after deployment.

The data protection officer is mandatory, and IT support for schools has to feed it

A school is a public authority for UK GDPR purposes, so a data protection officer is required. In practice this role is frequently held alongside a full operational job, which creates both a capacity problem and a conflict of interest. IT support for schools cannot be the data protection officer, but it can supply the technical evidence the role depends on: processing records, access reports, retention configuration and breach timelines.

Subject access requests arrive from parents and they arrive fast

A parent asking for everything the school holds about their child triggers a one-month statutory clock across email, the management information system, safeguarding files, CCTV and staff notebooks. Estates that have never configured search and legal hold discover this the hard way. Configuring content search and retention labels before the first request is an hour of IT support for schools work; doing it during a live request is a fortnight of stress.

Third-party edtech is the surface IT support for schools has to register

A typical secondary school uses dozens of learning platforms, many procured by individual departments with a credit card and a click-through agreement. Each is a processor holding pupil data. Only 47% of secondary schools have reviewed the cyber risks of their immediate suppliers, and just 21% have looked at the wider supply chain. Maintaining the processor register is unglamorous, and it is one of the highest-value things IT support for schools can maintain.

AI tools are already in the estate whether the trust approved them or not

The survey records 53% of primary and 53% of secondary schools as having already adopted some AI tools, with a further 11% and 23% in the process of adopting. Marking assistants, lesson planning tools and reading support built on natural language processing are in classrooms now. Only 56% of primaries and 59% of secondaries have specific cyber security practices for managing AI risk, and KCSIE 2026 points schools to the DfE’s generative AI product safety expectations for exactly this reason.

Cyber Essentials for Schools: Certify the Trust, Not Twelve Schools

Cyber Essentials is the government-backed baseline that the DfE standards largely mirror, and it is the cheapest credible assurance a school can buy. It is also routinely bought in the most expensive possible way by IT support for schools buyers who certify site by site.

Cyber Essentials pricing IT support for schools should quote from

IASME publishes Cyber Essentials pricing by employee count: £320 plus VAT for 0 to 9 employees, £440 for 10 to 49, £500 for 50 to 249 and £600 for 250 or more. Cyber Essentials Plus, the audited version, is priced separately by the certification body according to the size and complexity of the network.

Certifying twelve schools separately costs nine times as much

In our modelled trust, a 225-pupil primary has roughly 27 adults and falls in the 10 to 49 band at £440. A 1,045-pupil secondary has roughly 123 adults and falls in the 50 to 249 band at £500. Nine primaries and three secondaries certified individually is £5,460 plus VAT, an average of £455.00 per school. The same trust certified once as a single 717-employee organisation is £600 plus VAT.

Cyber Essentials for a 12-school trust: certifying each school separately versus certifying the trust once
Twelve separate certificates, £5,460 100.00%
Nine primaries at £440 each, £3,960 72.53%
Three secondaries at £500 each, £1,500 27.47%
One trust-wide certificate, £600 10.99%

That is £4,860 saved, or 89.01%, for doing the paperwork once

The fragmented route costs 9.10 times the consolidated one. The saving is not the point on its own — the point is that a single certificate forces a single set of controls, a single scope boundary and a single answer to each question. Twelve certificates permit twelve different answers, which is exactly the fragmentation the domain analysis already showed. Consolidating certification is often the cheapest way for IT support for schools to force consolidation of everything else.

Certification is only honest if the IT support for schools scope is honest

A trust-wide certificate covering only the central team’s laptops is worthless. The scope should be the whole estate: every school, every staff device, every internet-facing service. Scoping games are the reason some certificates mean very little, and a provider of IT support for schools who offers to “keep the scope tight” is offering to sell you a document rather than an outcome.

Cyber Essentials awareness at 20% in primary is the real finding

Only one in five primary schools has heard of the scheme. That is not a failure of primary schools; it is a failure of the sector’s information flow, and it is an opportunity. A trust that certifies annually, keeps the scope whole and reports the result to the board is doing something 80% of primary schools do not yet know exists.

What IT Support for Schools Costs in the UK

Every school asks the price of IT support for schools first, and every honest answer starts with the shape of the estate. Below are the indicative UK ranges we use for scoping, followed by the arithmetic on our modelled trust. These are our own indicative ranges rather than a published benchmark, and the variables that move them most are site count, distance and the age of the network.

LineIndicative UK rangeBasisWhat moves it
Remote support and monitoring£9 to £15 per adult account per monthPer staff and governor accountHours of cover, response targets, estate age
Onsite technician£28,000 to £38,000 per FTE per yearEmployed or suppliedRegion, seniority, cover for absence
Strategic and compliance support£450 to £850 per dayDay rateStandards evidence work, audits, projects
Filtering and monitoring£2.50 to £6.00 per pupil per yearPer pupil on rollDevice-level agents, reporting depth
Backup, including Microsoft 365£3.00 to £7.50 per protected account per monthPer adult account plus serversRetention depth, immutability, offline copy
Cyber Essentials, trust-wide£600 plus VAT per yearIASME published, 250+ employeesPlus audit priced separately
Microsoft 365 A3, adult accounts$3.25 per user per monthMicrosoft published education listReseller and framework terms
Device refresh£280 to £520 per devicePer unit including enrolmentForm factor, warranty length, accessories

The per-account arithmetic for a 717-adult trust

At £9 per adult account per month, remote support and monitoring for 717 accounts is £77,436 a year, which is £15.01 per pupil. At £12 it is £103,248, or £20.01 per pupil. At £15 it is £129,060, or £25.01 per pupil. Those are the numbers to put beside the cost of a directly employed team, not the headline day rate.

Onsite cover is the line that surprises trusts

One technician day per school per week across a 39-week academic year is 468 onsite days. Allowing for annual leave, training, sickness and travel across a 46 km estate, that is between two and three full-time equivalents, or roughly £70,000 to £115,000 a year in salary alone before recruitment, cover and management. This is the arithmetic that decides whether IT support for schools is bought as a service or built as an in-house team.

Charging per pupil is easier to budget but harder to defend

Some providers price per pupil because that is how school funding arrives. At £2.00 per pupil per month, our trust pays £123,840 a year; at £3.00, £185,760; at £4.00, £247,680. Per-pupil pricing is simple and predictable, but it charges a school for 5,160 identities that generate almost no support load and undercharges for the 717 that generate almost all of it. Per-account pricing usually reflects the work of IT support for schools better.

The costs of IT support for schools that are always underestimated

Circuit upgrades to meet the broadband standard. Switch replacement to carry current power-over-Ethernet loads. Wireless refresh in buildings surveyed a decade ago. Third-party backup of the Microsoft 365 tenant. Device-level filtering agents for take-home devices. Migration effort when a school converts into the trust. None of these appear in a monthly support fee, and all of them appear in a three-year plan for IT support for schools that has been written honestly.

What a good proposal for IT support for schools contains

A named service scope by school, a response and resolution matrix, an onsite day count with travel assumptions, the standards mapped line by line to deliverables, an evidence pack schedule, a three-year capital plan, a named escalation path, and an exit plan with data in an agreed format. Anything shorter is a price, not a proposal — and a price you cannot compare is not a price at all. Our IT outsourcing page sets out how we structure that scope.

In-House, Local Authority, MAT Central Team or Managed Provider

There are four viable delivery models for IT support for schools and one hybrid, and the register data explains why no single one wins. The right answer depends on school count, geography and whether the trust crosses a local authority boundary.

The single school with one technician and no IT support for schools behind it

A standalone school with 234 pupils and a part-time technician has depth of local knowledge and no resilience whatsoever. One person cannot cover holidays, cannot be on call, cannot hold expertise across networking, identity, security and edtech, and cannot produce the standards evidence pack alone. This model works only when it is backed by something else, which is why 77% of primary schools already buy external cyber management.

The local authority ICT service as IT support for schools

For a maintained school inside one authority, the local service is often excellent value, familiar with the local network and used to school calendars. Its limitation is structural: it is scoped to the authority. With 63.51% of academies now in a trust that crosses a local authority boundary, this model cannot serve the majority of the academy estate — not because of quality, but because of geography.

The MAT central team delivering IT support for schools

At sufficient scale a trust employs its own team: a director of IT, a small central function and site technicians. This gives complete alignment with the trust’s priorities and the ability to standardise ruthlessly. It also means recruiting and retaining specialists on education salaries, carrying single points of failure in specialist roles, and funding out-of-hours cover. It becomes clearly viable somewhere around the large MAT band — the 11 to 20 school trusts that hold 29.09% of academies.

The managed provider of IT support for schools

A specialist provider brings a team rather than a person, holds security and standards expertise across many estates, absorbs holiday and sickness cover, and carries the tooling. The risks are the ones every outsourcing arrangement carries: a provider who does not understand school calendars, a contract written for offices, and knowledge that leaves when the account manager does. The mitigations are all contractual, and they belong in the specification.

Co-managed IT support for schools is what most trusts end up with

The commonest working shape at trust scale is site technicians employed by the trust, doing the physical and pastoral work they are best at, backed by an external team providing the specialist layer: security operations, identity, network engineering, standards evidence and project delivery. That split plays to both strengths and is usually the cheapest way for IT support for schools to reach the DfE standards inside a realistic budget.

ModelBest fitStrengthMain riskStandards evidence
Lone in-house technicianSingle school under 400 pupilsLocal knowledge, immediate presenceNo resilience, no specialist depthRarely produced
Local authority serviceMaintained schools in one authorityFamiliarity, value, school calendar awareCannot follow a trust across boundariesUsually partial
MAT central teamTrusts of roughly 11 schools and aboveFull alignment, ruthless standardisationRecruitment, retention, key-person riskGood when resourced
Managed providerAny size, especially multi-authorityTeam depth, tooling, cover, security skillsContract written for offices, not schoolsContractual deliverable
Co-managedMost multi-academy trustsSite presence plus specialist layerUnclear boundaries if badly specifiedStrongest in practice

The question that decides the IT support for schools model is evidence, not cost

Whichever model a trust picks, the board still has to show the accounting officer a risk register entry, a patch compliance figure, a training completion figure, a backup test result and a filtering check record. Choose the model that produces those artefacts as a by-product of normal operation. A cheaper model that cannot produce them will cost more the first time somebody asks.

A 100-Point Scorecard for Choosing IT Support for Schools

Scoring makes a comparison of IT support for schools bidders honest. Weight the categories to the trust’s situation, score each bidder out of the maximum, and require evidence for anything above half marks. This is the scorecard we would hand a trust running a procurement.

Sector competence, 20 points

Does the bidder name the six core DfE standards without prompting? Can they explain the filtering and monitoring roles correctly, including the DSL’s? Do they know the fourteen-day patch requirement, the 3-2-1 backup wording and the RPA conditions? Have they worked with a management information system migration and a school census? Sector fluency is the fastest way to separate providers of genuine IT support for schools from general MSPs with an education page.

Standards evidence, 20 points

Ask to see a redacted evidence pack from a real client: the annual filtering check record, the weekly monitoring report, the patch compliance report, the training completion report, the termly account review and the backup test result. If the pack does not exist, the compliance work does not exist. This category is worth the most because it is the thing the board actually needs.

Security operations, 15 points

Who watches alerts, when, and what happens at 2am in August? Is there endpoint detection and response, and who triages it? Is there a documented incident process that names the DfE sector cyber team, Action Fraud, the ICO and the RPA? How many incidents did they handle last year across their education client base, and what did they learn?

Service delivery, 15 points

Named site presence, response and resolution targets by priority, cover for absence, escalation to a named engineer rather than a queue, and a change calendar that respects term dates, exam windows and the summer. Ask specifically what happens in the first week of September, because that is the week that tells you everything.

Commercial clarity, 10 points

A per-account or per-site price with the assumptions written down, a separate day rate for project work, an explicit list of exclusions, and no charges that depend on the provider’s own estimate of effort. Trust budgets are set in advance and audited afterwards; unpredictable billing is a governance problem, not just an irritation.

Roadmap and capital planning, 10 points

Can the bidder produce a three-year plan covering circuit upgrades, switch and wireless refresh, device lifecycle and the route to all six core standards by 2030? Costed, sequenced and mapped to summer windows? Very few can. The ones that can are the ones worth shortlisting for long-term IT support for schools.

Exit and data portability, 10 points

What happens at the end of the contract: documentation handover, administrator credentials, configuration exports, backup data in an agreed format, and a transition period with a named contact. An exit plan written at the start costs nothing and is worth a great deal at the point it is needed. Its absence is a warning about everything else.

The First 90 Days With a New Provider

Transition is where most of the value in IT support for schools is won or lost. A structured first term produces a documented estate and a working evidence pack; an unstructured one produces a helpdesk and a lot of unanswered questions.

Days 1 to 30: count everything

Inventory every site, circuit, firewall, switch, access point, server, domain, tenant, directory, management information system, edtech platform, administrator account and backup job. Confirm the domain and tenant count against the register data, because the answer is usually higher than the trust believes. Publish the inventory as the first deliverable of IT support for schools, not as an internal working document.

Days 1 to 30: fix the things that cannot wait

Multi-factor authentication on every administrative account. Disable dormant and leaver accounts. Confirm backups are running and restore one file. Verify the filtering blocklists cannot be overridden. Check the firewall administrative interface is not exposed. These are hours of IT support for schools work, not weeks, and they close the failure modes that actually cause incidents.

Days 31 to 60: baseline against the standards

Score the estate against all six core standards and the seven cyber sub-standards, school by school, with a red, amber and green rating and a named owner for every gap. Produce the first monthly service report in the format that will be used from then on, including patch compliance, training completion, backup test results and open risks. Take it to the board.

Days 61 to 90: plan the summer and the three years

Convert the gap analysis into a sequenced plan: what happens this summer, what happens next summer, what needs capital and when. Get the risk register entries written with the trust’s own language. Agree the change calendar, the exam blackout and the escalation path. By day 90 the trust should be able to answer any question the accounting officer asks about IT support for schools from a single document.

The measure of a good IT support for schools transition is boring

Ninety days in, the right outcome is not a transformed estate. It is a known estate: an accurate inventory, closed critical gaps, a working reporting rhythm, a costed plan and a board that knows where it stands. Everything after that is delivery, and IT support for schools delivery is much easier when the first term was spent on truth rather than on promises.

Frequently Asked Questions About IT Support for Schools

Is IT support for schools different from ordinary business IT support?

Substantially. The user population is mostly children, the change window is six weeks in August, filtering and monitoring is a statutory safeguarding control, retention clocks run to forty years, and the DfE publishes a written technical standard with a 2030 deadline attached. A provider of IT support for schools without sector experience will get the calendar and the evidence requirements wrong even if the technology is competent.

Do academies have to meet the DfE digital and technology standards?

The Academy Trust Handbook 2026 says at paragraph 1.21 that trusts “should be working towards meeting DfE’s digital and technology standards and meeting the 6 core standards by 2030”, and that filtering and monitoring is already expected because it sits in Keeping Children Safe in Education. In practice the standards are the benchmark any inspection, audit or insurer will apply to IT support for schools.

What broadband speed does a school actually need?

The standard sets a minimum of 100Mbps download and 30Mbps upload for primary schools, and a connection capable of 1Gbps in both directions for secondary schools, all-through schools and colleges, delivered over full fibre with a tested backup connection of a different service type. Upload capacity is the constraint most existing school circuits fail.

How quickly must schools apply security patches?

Within fourteen days of release, where the vendor rates the vulnerability critical or high risk, the CVSS v3.1 base score is 7.0 or above, or no severity rating is given. Devices that cannot be patched must be isolated. Only 45% of primary schools and 62% of secondary schools currently achieve this.

Can an academy trust pay a ransomware demand?

No. Paragraph 6.15 of the Academy Trust Handbook states that trusts “must not pay any ransom or extortion demands, including cyber ransomware”. That makes tested, immutable, offline-capable backup the only recovery route available, and it should be reflected in how the trust spends its security budget.

What does the RPA require for cyber cover to be valid?

Four conditions: offline backups, annual NCSC cyber security training completed by staff and governors with access to IT systems, registration with Police CyberAlarm, and a cyber response plan in place. Governors with a trust mailbox count as having system access. Evidence of training completion is what gets tested at the point of a claim.

How long do schools have to keep pupil records?

The IRMS schools toolkit sets the pupil record at 25 years from the pupil’s date of birth, with child protection records on the same clock and SEN or support service records at 31 years. Separately, the Academy Trust Handbook requires funding and provision records to be kept at least 6 years after the period to which the funding relates.

Should a multi-academy trust certify Cyber Essentials once or per school?

Once, covering the whole estate. On IASME’s published pricing, twelve schools certified separately in our modelled trust costs £5,460 plus VAT against £600 plus VAT for a single trust-wide certificate — a saving of £4,860, or 89.01%. More importantly, one certificate forces one set of controls instead of twelve different answers.

What should a trust budget for IT support for schools each year?

Our indicative ranges are £9 to £15 per adult account per month for remote support and monitoring, £28,000 to £38,000 per onsite technician, £2.50 to £6.00 per pupil per year for filtering and monitoring, and £3.00 to £7.50 per protected account per month for backup. For a 717-adult, 5,160-pupil trust that puts remote support alone between £77,436 and £129,060 a year.

Who is responsible for filtering and monitoring in a school?

Governors or proprietors hold overall strategic responsibility, a named senior leader and a named governor ensure the standards are met, the designated safeguarding lead leads on the safeguarding side and checks reports, and IT support maintains the systems and supplies the reports. Responsibility cannot be delegated wholesale to a third party, and KCSIE 2026 now requires records of the checks.

Does a school need a DPIA before deploying new technology?

Where the processing is likely to result in high risk to individuals — biometrics, monitoring, location, behaviour tracking — yes, and before deployment. The ICO reprimanded Chelmer Valley High School in July 2024 precisely for introducing facial recognition for cashless catering without completing one first.

Is Microsoft 365 A1 enough for a school?

For pupils, almost always. For adults, rarely. A1 gives web Office, Teams and mail but not conditional access, endpoint management, endpoint detection and response or full retention tooling — the controls the DfE cyber standards assume. The usual answer for IT support for schools is pupils on A1, staff on A3 and a small high-risk population on A5.

References and Further Reading