Cyber security can look like an IT problem, something for someone else to handle. It isn't. DPE has created as set of resources as a starting point to help you work out, role by role, who is accountable, who does the work, who should be consulted, and who just needs to be kept informed. Almost everyone in a trust or school appears somewhere on that list. That's the whole idea behind this year's theme: don't make it easy for them. Attackers rely on someone assuming it's not their job.
| Person in the organisation | Cyber risk | Cyber awareness | User accounts & access | Backup plan | Cyber attacks |
|---|---|---|---|---|---|
| SLT Digital Lead | Accountable | Responsible | Accountable | Accountable | Accountable |
| IT Support | Responsible | Consulted | Responsible | Responsible | Responsible |
| Governing Body | Informed | Informed | — | — | Informed |
| Governance Data Protection Lead | Consulted | Consulted | Consulted | Consulted | Consulted |
| DPO | Consulted | Consulted | Consulted | Consulted | Consulted |
| Headteacher/Principal | Consulted | Accountable | Informed | — | Informed |
| DSL | Informed | Consulted | Informed | Consulted | Consulted |
| Finance/Business Operations | Consulted | — | Consulted | Consulted | — |
| School Staff | — | — | Informed | — | Informed |
Accountable = owns the outcome.
Responsible = does the work.
Consulted = gives input before a decision.
Informed = kept up to date.
A few things stand out:
- The SLT Digital Lead carries the most accountability, but they're not doing it alone. IT Support does the day-to-day work on most of these areas, and everyone else has a defined role, even if it's just being consulted or informed.
- The Headteacher is accountable for cyber awareness specifically. Training and culture aren't delegated away from leadership.
- The DPO is consulted across almost everything. Cyber security and data protection are two sides of the same coin, so your DPO should be in the loop on risk, awareness, access, backups and incident response.
- School staff are "informed" on user accounts and cyber attacks, which is a floor, not a ceiling. Being informed means knowing how to report something and what to expect, not being a passive bystander.
Leadership and governance sit underneath all of this
The same structure applies at the governance level. Under the DfE's digital leadership and governance standard, the SLT Digital Lead is accountable for business continuity and the digital strategy, the Headteacher is accountable for overall responsibilities, and the Governing Body is consulted on responsibilities and informed on the rest, specifically so they can challenge plans and decisions, not simply rubber-stamp them.
What this means day to day
- If you're the SLT Digital Lead: you own the outcome, even for work IT Support carries out. Accountability doesn't mean doing everything yourself, it means making sure it gets done.
- If you're the Headteacher or Principal: you're accountable for cyber awareness across the school, and consulted on risk. You don't need to be technical, but you do need to ask the right questions.
- If you're a governor or trustee: you should be informed on risk and attacks, and consulted on responsibilities and registers, well enough to challenge what you're told, not just note it.
- If you're the DPO: you're consulted across nearly every area, so make sure that channel actually exists in practice, not just on paper.
- If you're a member of school staff: your role is smaller, but real. Know how to report a suspicious email or a lost device, and understand that "informed" still means you're expected to act if something looks wrong.
Cyber security works best when everyone understands their own slice of this table, rather than assuming accountability sits entirely with "IT."
A note on terminology: the DfE's own standards documentation sometimes uses the word "responsible" where a formal RACI chart would say "accountable." If you're cross-checking this table against the DfE guidance directly, that's worth keeping in mind, the RACI version is the more precise breakdown of who owns an outcome versus who carries out the work.
Your individual responsibilities include:
-
Practicing Good Cyber Hygiene: This is the foundation – using strong, unique passwords, enabling Multi-Factor Authentication (MFA), and being vigilant against phishing scams. These basic habits significantly reduce your personal risk.
-
Keeping Software Updated: Regularly installing updates for your operating systems, applications, and browsers patches known vulnerabilities that attackers exploit, this might include your phone.
-
Protecting Your Devices: Ensuring your personal devices (laptops, phones, tablets) are secured with passwords/biometrics and reputable antivirus software.
-
Being Mindful Online: Thinking before you click, sharing personal information judiciously on social media, and being aware of the risks of public Wi-Fi.
-
Reporting Suspicious Activity: If something looks or feels wrong, report it to your IT department (at work) or relevant authorities. Don't assume someone else will.
💡 Today's Cyber Tip: Know your own row in the table
Find your role in the table above. Are you clear on what you're accountable for, responsible for, or expected to be consulted or informed on? If not, that's a five-minute conversation with your SLT Digital Lead worth having this week.
FREE Resources for this month:
Our DfE Digital Standards Roles & Responsibilities RACI chart, covering all 12 standards, including leadership and governance, cloud, servers, networks, devices, and filtering and monitoring, is normally a member resource. It's free to download throughout October:
Prefer a quick reference for just your own role? Download our role cards, one per role, pulled straight from the full RACI chart.
It's free to download throughout October:
DPE Knowledge Bank Guidance and Support
Our DfE Digital Standards Tracker helps you track your cyber resilience and your progress: DfE Digital Standards Tracker
Review our Cyber Security Best Practice Area for micro learning, support, guidance and policies: Cyber Security Best Practice Area
Why not have a look at our 'specialist' trainer Harry the Hacker: Where's Harry the Hacker?
