Whether your school's data lives in a server cupboard down the corridor or in the cloud, the same question applies: is it protected from unauthorised access, corruption or theft, throughout its whole lifecycle? Data security combines physical, technical and administrative safeguards, and getting all three right matters more as schools move more of their data off-site.
The three layers of data security
- Physical security: locked server rooms, secure cabinets, and laptops that aren't left unattended. Physical access is often the easiest route in, and the easiest to overlook.
- Technical security: encryption of data at rest and in transit, access controls based on role, firewalls, anti-malware, and prompt patching.
- Administrative security: the policies, procedures and training that govern how people handle data day to day, including retention policies and an incident response plan.
Most schools now run a hybrid of servers and cloud
Very few schools are purely on-site or purely cloud-based today. The DfE's standards actively encourage moving from local servers to cloud solutions where it makes sense, since it can improve resilience to cyber attacks and reduce the cost and effort of maintaining on-site equipment. Some systems, such as door access control or cashless catering, may still need a local server. Whichever model you use, the same core security principles apply, but the practical steps differ.
If you still run on-site servers
Servers are a concentrated target: one compromised server can expose a large amount of data at once. Focus on:
- Least privilege and MFA for anyone with server access, especially administrative accounts, reviewed regularly.
- Patching, both the operating system and everything running on it, ideally through automated patch management.
- Network segmentation, keeping servers on their own segment behind a properly configured firewall with only necessary ports open.
- Encryption, at rest and in transit.
- Backups that are isolated from the main network, so that ransomware on your live systems can't reach and encrypt them too.
- Physical security, restricted access, and a locked server room. The DfE's servers and storage standard expects servers to be secure by design.
If you use cloud solutions
Moving to the cloud changes where responsibility sits, but doesn't remove it. Under the DfE's cloud solution standard, schools must still comply with data protection legislation, and you should work with your DPO to carry out a DPIA for any cloud solution that stores personal or special category data. In practice, that means checking:
- A data sharing agreement is in place with the provider, including a commitment to notify you promptly of any data breach.
- Data is stored in the UK or EU, unless an international transfer has been confirmed as compliant with UK GDPR.
- Access is centrally managed, ideally through a single ID and access management system rather than separate logins per tool, following your joiners-and-leavers process.
- Backup responsibility is understood. Cloud providers often only keep their own backups for a limited period, sometimes as little as 30 days, and accidental deletion by a user is the most common cause of cloud data loss. Ask your provider what they back up, where, and for how long, and don't assume "it's in the cloud" means "it's backed up". It is your responsibility to check the retention against your retention schedule.
A shared checklist, wherever your data lives
- Do you know where your most sensitive data is stored, on-site or in the cloud?
- Is access limited to the people who need it, and reviewed regularly?
- Is encryption switched on, both at rest and in transit?
- Are your backups isolated from your live systems, and have you tested restoring from them?
- Would you know who to call, and what to do, in the first hour of an incident?
💡 Today's Cyber Tip: Check your backup isolation
Whatever you use, on-site servers or cloud, check today whether your backups are isolated from your live network. If ransomware hit your main systems, could it also reach and encrypt your backups? If you're not sure, ask your IT support this week.
DPE Knowledge Bank Guidance and Support
Review the DfE's servers and storage standards and cloud solution standards for the full technical requirements.
Our DfE Digital Standards Tracker helps you track your cyber resilience and progress against both standards: DfE Digital Standards Tracker
We can review your server room and physical data security as part of our data walks ("Making the Rounds").
Review our Cyber Security Best Practice Area for micro learning, guidance and policies.
