Leadership diagnostic · Schools & Trusts

Digital Resilience Baseline Schools & Trusts

A short leadership diagnostic for examining cyber-security governance, assurance and organisational resilience.

0 of 27 checks answered
0 of 27 checks answered

This is a baseline diagnostic, not a compliance audit.

Choose the answer that best reflects what you can evidence today. “Partly / unsure” is useful: it identifies where leadership needs better assurance.

Use this diagnostic to support leadership discussion and prioritisation. It is not a technical security audit, compliance assessment or maturity certification.

Your answers stay in this page. They are not sent anywhere or saved automatically; closing or reloading the page clears them. Use Print / save result to keep a copy.

Leadership & governance

Can leadership and governance see and oversee digital resilience?

1. A named senior leader has responsibility for digital technology and cyber-security oversight.
What counts as evidence?

A role description, responsibility framework or governance record identifies the senior lead and their responsibilities.

2. Digital and cyber-security responsibilities are documented and understood by relevant staff.
What counts as evidence?

Responsibilities appear in governance documents, policies, role descriptions or equivalent records and are communicated to relevant staff.

3. Governors or trustees receive enough information about significant cyber risks, incidents and improvement activity to exercise oversight.
What counts as evidence?

Board or committee reports, risk-register discussions, minutes, dashboards or recorded escalation of significant issues.

IT responsibilities & accountability

Is it clear who is responsible for managing and supporting IT?

4. Responsibilities between the school or trust and its internal or external IT support are clear.
What counts as evidence?

Responsibilities are documented rather than assumed, including where services are shared, outsourced or provided by an LA or other organisation.

5. Service expectations, escalation routes and important supplier responsibilities are understood.
What counts as evidence?

Contracts, SLAs, service descriptions or other records define what support is provided and how significant problems are escalated.

6. The school or trust obtains evidence that important outsourced IT and cyber-security responsibilities are actually being carried out.
What counts as evidence?

Service reports, review meetings, assurance reports, control evidence or other information beyond simply being told that “IT handles it.”

Assets & cyber risk

Do we know what matters and what could go wrong?

7. There is a current record of important digital systems, services, data and relevant cloud services.
What counts as evidence?

Current asset, system, information-asset or service records identify important technology and information dependencies.

8. The school or trust has identified the systems, services and data whose loss or unavailability would cause significant disruption.
What counts as evidence?

Critical systems and services are explicitly identified through business-continuity, risk, asset-management or similar work.

9. Significant cyber risks are identified, with owners and actions.
What counts as evidence?

A current risk register or equivalent records significant cyber risks, ownership, controls and required actions.

Technical assurance

Can leadership obtain meaningful assurance over essential protections?

10. IT support can provide evidence that essential cyber-security protections are being managed.
What counts as evidence?

Appropriate reporting or assurance covering areas such as patching, firewalls, endpoint protection, secure configuration and vulnerability management.

11. Significant technical weaknesses and exceptions are visible to leadership.
What counts as evidence?

Unsupported systems, overdue critical updates, known vulnerabilities or significant control gaps are reported and escalated rather than remaining solely within IT.

12. Significant technical improvement actions have owners and are tracked.
What counts as evidence?

Improvement plans identify actions, owners and target dates, with progress followed through.

Identity & access

Can we be confident that access to important systems is controlled?

13. User access is managed so people have appropriate access for their role.
What counts as evidence?

An account-management process covers creation, changes to permissions and periodic review where appropriate.

14. Administrator and other privileged access is restricted and controlled.
What counts as evidence?

Privileged accounts can be identified, their purpose is understood and elevated access is limited to those who need it.

15. Multi-factor authentication and account lifecycle controls protect important accounts and systems.
What counts as evidence?

The school or trust can evidence appropriate MFA coverage and a reliable joiner/mover/leaver process, including prompt removal of access when someone leaves.

Backup & recovery

Can critical data and systems actually be recovered?

16. Critical systems and data have been identified for recovery.
What counts as evidence?

Recovery priorities identify what must be restored first following serious disruption.

17. Backup arrangements appropriately cover critical data and systems.
What counts as evidence?

A current backup plan or provider evidence shows what is backed up, how it is protected and how recovery would work.

18. Restoration from backup has actually been tested and the result recorded.
What counts as evidence?

There is evidence of successful restoration testing—not simply evidence that scheduled backup jobs have run.

People & cyber culture

Do people know how to recognise and raise cyber-security concerns?

19. Staff receive appropriate and up-to-date cyber-security awareness activity.
What counts as evidence?

Training or awareness activity is provided regularly, with additional support where particular roles or risks require it.

20. Staff know how and where to report suspected cyber incidents, mistakes or security concerns.
What counts as evidence?

Reporting routes are clearly communicated and staff know what to do if they click something suspicious, disclose information accidentally or notice unusual activity.

21. The school or trust encourages prompt reporting of cyber-security mistakes and concerns.
What counts as evidence?

Communications, training and leadership practice encourage people to raise concerns promptly so that problems can be investigated and contained.

Incident response

Are we prepared to respond to serious digital disruption or a cyber incident?

22. There is a current cyber incident-response or recovery plan linked to wider business-continuity arrangements.
What counts as evidence?

A documented plan addresses significant disruption to systems, services or data and connects with wider continuity arrangements.

23. The plan identifies roles, decision-makers, escalation routes and important contacts.
What counts as evidence?

People know who coordinates the response, who can make important decisions and which internal and external parties may need to be contacted.

24. Response and recovery arrangements have been discussed, exercised or tested.
What counts as evidence?

A tabletop exercise, scenario discussion, technical test or other activity demonstrates that the plan has been used rather than existing only on paper.

Review & improvement

Do we learn, review and follow through?

25. Cyber risks and resilience arrangements are reviewed regularly and after significant change or incidents.
What counts as evidence?

There is a defined review cycle plus additional review following significant incidents, technology changes or changes in risk.

26. Incidents, near misses, tests and exercises lead to learning and improvement where needed.
What counts as evidence?

Lessons are recorded and translated into changes to controls, processes, plans, training or other arrangements.

27. Agreed improvement actions are tracked through to completion.
What counts as evidence?

Actions have owners and target dates and remain visible until completed or formally accepted.

0 of 27 answered

About this diagnostic

The Digital Resilience Baseline is a leadership discussion and assurance tool for schools and trusts. It is designed to help identify where resilience arrangements are evidenced, where assurance is incomplete and where further attention may be needed.

It is informed by Department for Education digital and technology standards and National Cyber Security Centre guidance on cyber governance and resilience. It is not a compliance assessment, certification or substitute for the underlying guidance.

The diagnostic also incorporates broader governance and assurance principles. Not every statement is a formal DfE requirement.

Reviewed: October 2026

Sources and further guidance