Schools, colleges and universities are now some of the most targeted organisations online, and the numbers back that up. Nearly every UK higher education institution reported a breach or attack in the past year, ransomware gangs are shifting their attention toward universities, and the global cybersecurity workforce still has millions of empty seats. Cybersecurity education stats from GOV.UK, IBM, ISC2 and Comparitech all point the same way: attacks on education are frequent, costly and rising fastest where training hasn’t kept up.
This guide pulls together the latest verified data on breach rates by school type, the true cost of an education sector breach, the skills gap driving the problem, and what the UK’s incoming cyber laws mean for governors and IT leads. We’ll also look at the Northern Ireland and Republic of Ireland picture, which most global reports skip, and set out what actually reduces risk once you’ve read the numbers.
Table of Contents
The 2026 Snapshot: Headline Cybersecurity Education Stats
Before the sector-by-sector detail, here are the figures that matter most for anyone building a case for training budget or board attention this year.
- 98% of UK higher education institutions reported at least one cyber breach or attack in the past 12 months, according to the government’s Cyber Security Breaches Survey 2025/2026.
- 73% of UK secondary schools reported a breach, up sharply from 60% the year before.
- The global cybersecurity workforce gap stood at 4.8 million unfilled roles in ISC2’s most recent Workforce Study, even as the active workforce grew to 5.5 million.
- IBM’s Cost of a Data Breach Report 2026 puts the average education sector breach at $4.15 million, a 9% rise on the year before.
- Comparitech recorded 251 confirmed ransomware attacks on educational institutions worldwide in 2025, with almost 4 million records exposed.
Each of these sits behind a wider story about why schools and universities keep appearing in breach data, and what’s actually changing in 2026.
The Global Skills Gap Behind the Numbers
Before looking at attack figures, it helps to understand why education keeps losing this fight: there simply aren’t enough trained people to go around, in schools or in the wider economy that trains them.
ISC2’s Cybersecurity Workforce Study found a global shortfall of 4.8 million unfilled cybersecurity roles, even with an active workforce of 5.5 million professionals. That gap grew by around 19% in a single year. The World Economic Forum has said the profession would need to grow by 87% to close it entirely. Regionally, Asia-Pacific has the largest shortfall, at roughly 3.4 million roles, while China and India each have over 1 million unfilled vacancies.
It’s fair to say this figure is debated. Some analysts have pointed out that it measures what organisations say they need rather than confirmed job openings, and ISC2 itself has since shifted its reporting focus. Even so, the direction of travel matches what schools report on the ground: too few staff with real cyber skills, stretched IT budgets, and training that too often stops at an annual tick-box session. For education specifically, this shows up as under-resourced IT teams trying to defend networks built for teaching, not for fending off organised ransomware crews.
Schools and colleges also lose out in the competition for scarce cyber talent. A qualified security analyst can usually earn more in financial services or the private sector than a school or further education college can offer, which pushes many institutions toward outsourced IT support instead of an in-house specialist. That’s not necessarily a weakness on its own, but it does mean day-to-day security awareness training, spotting a suspicious email, checking a link before clicking, reporting a lost laptop straight away, has to be built into staff routines rather than left to a single IT contact who may only visit site once a week.
Key Terms Behind the Cybersecurity Education Stats
A few terms recur in breach surveys and ransomware reports, and it helps to know exactly what each one covers before using these figures in a board paper or staff briefing.
- Breach or attack: any incident where someone attempted, or succeeded, in gaining unauthorised access to systems or data. Surveys usually count attempts and successful breaches together, which is why headline percentages look high.
- Impersonation attack: an email, call, or message that pretends to be a trusted contact, such as a headteacher, finance officer, or supplier, used to trick staff into making a payment or transferring data.
- Ransomware: malicious software that encrypts files and demands payment for their release, often alongside a threat to publish stolen data if the school or university doesn’t pay.
- Quishing: phishing carried out through a fake QR code, often placed on posters, payment signs or emails, that leads to a scam website when scanned.
- NIS2 / Cyber Security and Resilience Bill: the EU and UK’s updated network and information security laws, which extend formal cyber security duties, including staff training requirements, to a wider range of organisations and suppliers.
Sector Deep Dive: Schools, Colleges and Universities
Breach rates vary enormously by institution type, and the GOV.UK Cyber Security Breaches Survey 2025/2026 (built from 273 primary schools, 222 secondary schools, 33 further education colleges and 49 higher education institutions) is the most reliable UK source for that split.
| Institution type | Breach or attack rate | Named senior lead for cybersecurity |
|---|---|---|
| Primary schools | 49% | 85% |
| Secondary schools | 73% | 73% |
| Further education colleges | 88% | 82% |
| Higher education institutions | 98% | 100% |
Primary and Secondary Schools
Primary schools reported the lowest breach rate of the group at 49%, but that figure has been climbing year on year. Secondary schools reported a much sharper picture: 73% identified a breach or attack in the last 12 months, up from 60% the year before, a jump that outpaced every other part of the survey. Impersonation attempts, fraudulent emails pretending to be a headteacher or supplier, hit 31% of primary schools and 44% of secondary schools, both well above the 28% seen across ordinary businesses.
Further Education Colleges
Further education colleges sat close to universities in exposure, with 88% reporting a breach or attack, a rise of three percentage points on the previous year. Colleges also reported strong senior-level engagement: 82% had a governor, board member or senior manager formally responsible for cybersecurity, second only to universities.
Higher Education: Where Breaches Hit Hardest
Universities are now almost universally affected. The 2025/2026 survey found that 98% of higher education institutions had identified a breach or attack, up from 91% the year before, and that every participating institution had a named board member or senior manager responsible for cybersecurity. Impersonation attacks reached 79% of further and higher education institutions combined, versus 31% for primary schools. Almost half of colleges and universities that identified a breach (49%) suffered a genuine negative outcome: compromised accounts used for fraud (23%), services knocked offline (16%), or lost access to files and networks (14%).
Ransomware data tells a similar story about where the pressure is shifting. Comparitech’s tracking shows 251 confirmed global education ransomware attacks in 2025, up modestly from 247 in 2024, with breached records jumping 27% to nearly 4 million. In the first half of 2026, attacks on schools (K-12) actually fell by 26%, but attacks on higher education rose by more than 8%, driven partly by a ransomware group called The Gentlemen, whose attacks on the sector grew 275% in six months and mostly targeted universities. The median ransom demand also jumped, from $275,000 in the second half of 2025 to $420,620 in the first half of 2026.
There’s a more encouraging thread in this data, too. Sophos’s State of Ransomware in Education 2025 study found encryption rates falling to four-year lows: 29% for schools and colleges and 58% for universities, indicating more attacks are being stopped before they cause damage. In lower education specifically, the share of attacks blocked before encryption rose from 14% to 67% year on year, and median ransom payments dropped sharply, from $6.6 million to $800,000. Better detection and stronger backups appear to be paying off, even as attack volumes hold steady.
The UK and Ireland Picture in 2026
Most global cybersecurity education stats are built on US data, which leaves a gap for anyone trying to plan a training budget or board briefing for a UK or Irish institution specifically.
Northern Ireland and the Republic of Ireland
Northern Ireland received a sharp reminder of this risk on 5 April 2026, when the C2K network, used by most primary and secondary schools across the region, was hit by a cyberattack that disrupted IT systems just ahead of exam season. The Education Authority said it detected and contained the incident early, with no data compromised, but the disruption itself shows how a single shared network can affect hundreds of schools at once.
In the Republic of Ireland, cybersecurity education is becoming as much a compliance issue as a safety one. The National Cyber Security Centre has been preparing organisations for NIS2 through its draft Risk Management Measures guidance and the voluntary CyFun framework, while the National Cyber Security Bill (still working through the legislative process) will formally require management boards to receive regular cyber security training. On the workforce side, the EU’s Digital Decade target calls for ICT specialists to reach 10% of the workforce by 2030, up from just over 6% in Ireland in 2024, a gap that education providers will need to help close.
New Rules: The Cyber Security and Resilience Bill and NIS2
The UK’s Cyber Security and Resilience Bill is the most significant update to cyber law since the 2018 NIS Regulations, and its progress has been fast. Introduced to Parliament on 12 November 2025, it passed its second reading in the Commons on 6 January 2026 and reached the House of Lords by 25 June 2026, with Royal Assent expected in late 2026 and phased implementation running through to 2028.
It brings managed service providers and larger data centres into scope for the first time, introduces mandatory ransomware reporting, and sets fines of up to £17 million or 4% of global turnover for serious failures, alongside a 24-hour incident reporting window. UK cybercrime already costs the economy an estimated £14.7 billion a year, which is the backdrop against which this legislation was drafted.
Schools and colleges aren’t classed as critical infrastructure, but many rely on IT suppliers and cloud platforms that will fall directly under the new rules. That means governors and IT leads should expect tighter contracts with suppliers, clearer incident-reporting duties, and closer scrutiny of how quickly breaches are escalated. None of this replaces good staff training, but it raises the cost of getting the basics wrong.
Does Cybersecurity Education Actually Work? The Case for Training
None of the figures above answers the question that actually matters for a budget conversation: does training reduce risk, or is it just a box-ticking exercise? The data here is more convincing than most people assume.
KnowBe4’s Phishing by Industry Benchmarking Report 2025, based on 67.7 million simulated phishing tests across 14.5 million users, found a global baseline “phish-prone” rate of 33.1%, meaning roughly a third of untrained staff will click a simulated phishing link. After 12 months of regular, structured training, that figure dropped to 4.1%, an 86% reduction.
Most of the improvement happens fast: organisations saw a 40% drop within the first 90 days alone. Verizon’s 2025 Data Breach Investigations Report found the human element still involved in around 60% of breaches, which is exactly the risk that ongoing training, rather than a once-a-year assembly, is designed to close.
The lesson for education is straightforward. A single INSET day on phishing awareness won’t move the needle much. Short, repeated, realistic simulations, tied to real examples staff will recognise from their own inbox, are what actually shift behaviour. Cybersecurity education stats consistently show that training frequency matters more than training length: monthly five-minute sessions beat one long annual briefing almost every time.
AI and the Next Wave of Threats to Watch
Every recent report on education cybersecurity mentions artificial intelligence, but few explain what’s actually changed for schools and universities on the ground.
AI has mainly changed the quality of phishing attempts, not their volume. Convincing, personalised, well-written phishing emails, once a giveaway sign of a scam, no longer stand out the way they used to. That matters for schools especially, since staff and older pupils have spent years being taught to “look for the bad grammar,” a rule of thumb that’s increasingly unreliable.
Social media phishing is following the same pattern, with fake profiles and QR-code scams (known as quishing) growing quickly across platforms that pupils and staff use daily. Reports of QR code phishing to Action Fraud rose from around 100 in 2019 to nearly 1,400 in a single recent year, a trend our social media phishing statistics page tracks in more detail.
The practical response for education isn’t complicated: update phishing training examples every few months rather than reusing the same slide deck, add a simple QR-code checking habit to existing e-safety lessons, and make sure whoever manages the network is aware that ransomware groups are actively probing shared education networks for weak points, a pattern also visible in wider ransomware and malware trends across sectors beyond education.
Building a Cybersecurity Education Programme That Actually Sticks
Pulling all of this together, the schools and universities avoiding the worst outcomes share a few habits, not a single big investment.
They train little and often, rather than once a year. They test using realistic phishing simulations rather than relying on staff to self-report their confidence. They give one named senior leader clear responsibility for cybersecurity, which the survey data shows almost every higher education institution and the vast majority of colleges already do. And they treat cybersecurity education stats as a planning tool, not just a scare tactic: knowing that ransomware demands jumped 53% in six months, for instance, is a much stronger argument for backup testing than a vague warning about “hackers.”
If your institution is reviewing its own training programme this year, it’s worth checking how your current provision compares against the wider cybersecurity facts and statistics shaping the sector, and where the gaps in your last risk assessment actually sit.
What’s your school or college doing differently this year to close its own skills gap? Share your experience in the comments, we’d like to build a clearer picture of what’s actually working across UK and Irish institutions in 2026.
FAQs
These are the questions we’re asked most often when schools, colleges, and universities start digging into their own cybersecurity education stats, answered using the most current available data.
Why do cybersecurity education stats matter for schools right now?
Breach rates among secondary schools jumped from 60% to 73% in a single year, and ransomware demands against the sector rose 53% between late 2025 and early 2026. Institutions that can provide clear, up-to-date data to support their training budget requests are in a stronger position with governors and finance teams.
What percentage of cyber attacks are caused by human error?
Verizon’s 2025 Data Breach Investigations Report found the human element present in around 60% of all breaches, and the CIS MS-ISAC’s K-12 research found attackers targeting human behaviour at least 45% more than technical vulnerabilities.
Is there a cybersecurity skills gap in the UK and Ireland specifically?
Both nations face the same global pressures driving ISC2’s 4.8 million shortfall worldwide. In Ireland, the EU’s Digital Decade target aims for ICT specialists to account for 10% of the workforce by 2030, up from just over 6% in 2024, while the UK’s incoming Cyber Security and Resilience Bill will push more organisations, including many education IT suppliers, toward formal training obligations.
How many schools were hit by ransomware recently?
Comparitech recorded 251 confirmed ransomware attacks on educational institutions globally in 2025, and 104 attacks in the first half of 2026 alone, 36 of which were confirmed. K-12 attacks fell 26% over that period while higher education attacks rose over 8%.
Which part of the education sector has the least mature cybersecurity training?
Primary schools report the lowest breach rate (49%) largely because they’re a less lucrative target, not because their defences are stronger. Further education colleges and smaller institutions with limited IT budgets consistently show the weakest board-level engagement outside of universities.
Does cybersecurity awareness training actually reduce risk?
KnowBe4’s benchmarking data shows phishing click rates falling from a 33.1% baseline to 4.1% after 12 months of regular training, an 86% reduction, with 40% of that improvement showing up within the first 90 days.