Wednesday, 30 September 2026

Where technology leaders come to think out loud

ColumnCybersecurity

UK education’s cyber gap is the patch queue, not the attack count

SonicWall’s own UK telemetry shows intrusion attempts on schools, colleges and universities climbing while ransomware stays rare. The numbers point governors to patching, not more monitoring

Spencer Starkey, executive vice-president, EMEA, at SonicWall
Image: SonicWall
In brief
  • SonicWall’s UK figures are dominated by automated probing of web-facing systems, with the old Log4j flaw the leading signature against schools.
  • The government’s breaches survey finds at least nine in 10 institutions have firewalls, but fewer than half of primary schools have a 14-day patching policy.
  • Governors should ask how quickly critical fixes are applied and what cannot be patched, rather than how many attacks were detected.

SonicWall, a network security vendor that markets its products to schools and universities, has issued new UK figures on attacks against education. According to the release, carried by Intelligent CISO on 24 September, SonicWall recorded more than 19.3 million medium- and high-severity intrusion attempts against UK schools, colleges and universities so far in 2026, against 11.5 million across the whole of 2025. Its UK education sensors logged only 36 ransomware events, fewer than in any other UK sector SonicWall tracks.

These are SonicWall’s own telemetry. The release says the analysis is based on intrusion prevention system (IPS) data from UK-registered education sensors in 2026. The figures count attempts those sensors saw, which is a measure of pressure, not of damage.

Most of that activity, the release says, is probing of web-facing education systems: the four most common path traversal and directory manipulation signatures alone accounted for 10.2 million hits. In primary and secondary schools, the most frequent single signature was an exploit of the Apache Log4j2 remote code execution flaw, at about 660,000 hits, a weakness the National Cyber Security Centre (NCSC) warned about in December 2021. “We’re seeing relentless automated scanning of the systems schools and universities depend on every day, from student portals to learning platforms, as attackers look for something that has been left exposed,” said Spencer Starkey, SonicWall’s executive vice-president for Europe, the Middle East and Africa.

Read together, the numbers describe a sector being swept for old, known weaknesses. For security leaders and governors, that settles where the next pound goes: into knowing what is connected and closing known flaws quickly, ahead of more spend on watching the attempts arrive.

Low ransomware counts prove little

“The low number of ransomware events is encouraging, but it shouldn’t create a false sense of security,” Starkey said. “If attackers find an unpatched vulnerability, exposed directory or overlooked network service, that initial intrusion can quickly become a much bigger problem.”

SonicWall’s education report card of 2 September goes further. It says education recorded the lowest absolute ransomware volume of any sector SonicWall tracked in the first half of 2026, and reads that as a sign of deliberate, targeted intrusion rather than broad automated attack. SonicWall’s release that day says 44 education organizations detected active ransomware campaigns in the same period. Those figures cover SonicWall’s whole education dataset, not the UK alone.

The government’s own survey counts institutions that identified a breach or attack, a measure that includes attempts such as phishing. The Cyber Security Breaches Survey 2025/2026 education annex, published by the Department for Science, Innovation and Technology (DSIT) on 30 April, found that 98% of higher education institutions, 88% of further education colleges, 73% of secondary schools and 49% of primary schools had identified one in the previous 12 months. Almost half (49%) of the colleges and universities that did so reported a negative outcome on their systems. The telephone survey reached 577 institutions between August and December 2025, only 33 of them further education colleges.

The gap sits behind the firewall

At least nine in 10 institutions in every tier had rules or controls covering firewalls, secure configuration, user access and malware protection. The Cyber Essentials area that the fewest addressed was patch management, defined as a policy to apply security updates within 14 days. Only 45% of primary schools had one, against 62% of secondary schools, 73% of further education colleges (down from 90% a year earlier) and 84% of universities.

One university interviewed for the survey put the problem plainly: “We know we should be doing more proactive patching, but there’s nobody there to do it.” Its team, it said, had gone from five people to one.

SonicWall’s 2 September figures point the same way. It says a Hikvision camera command injection flaw disclosed in 2021 is present on 28% of the education networks in its dataset, and that Log4j2 generated 6.7 million hits against learning management and administrative middleware in the first half of 2026. That 6.7 million is SonicWall’s figure across its whole education dataset; the UK schools count is the 660,000. Education has largely bought the perimeter. The survey finds the gaps in the patch cycle behind it.

Governors should ask about days, not attacks

The annex found that 72% of primary schools, 67% of secondary schools, 90% of further education colleges and 73% of universities include the number of significant attacks detected in cybersecurity updates to governors or senior managers. In a year when SonicWall’s UK count has already passed the whole of 2025, that figure can rise whatever the institution does. It says more about the internet than about the school.

The Department for Education’s cyber security core standard for schools and colleges, last updated on 16 September, already names the better measure. It says vulnerability fixes for operating systems, applications and firmware must be completed within 14 days of release where a flaw is rated critical or high. Where a high-risk patch is not available, it says the device should be isolated. It asks for end-of-support dates to be recorded in the asset register, and for governors to check licensing as part of their normal compliance review.

That gives governors and trustees three questions for the next meeting:

  • What share of critical and high-rated fixes was applied within 14 days last term, starting with internet-facing systems?
  • Does the asset register include cameras, phone systems and other network-connected devices, with their end-of-support dates?
  • What is connected that cannot be patched, and when will it be isolated or replaced?

The scanners will keep coming whatever the budget. The better bet for staying out of next year’s ransomware count is to close what they look for inside 14 days.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. SonicWall UK education release, as carried by Intelligent CISO, “19,300,000+ cyberattacks put UK education on alert”, 24 September 2026. https://www.intelligentciso.com/2026/09/24/19300000-cyberattacks-put-uk-education-on-alert/
  2. SonicWall, “SonicWall Research Issues Education Cybersecurity Report Card as Attackers Exploit the Industry’s Most Open Networks”, press release, 2 September 2026. https://www.sonicwall.com/news/sonicwall-research-issues-education-cybersecurity-report-card-as-attackers-exploit-the-industry-s-most-open-networks
  3. SonicWall, “Report Card: Education Is the Most Attacked Network Environment in SonicWall’s Telemetry”, company blog, 2 September 2026. https://www.sonicwall.com/blog/report-card-education-is-the-most-attacked-network-environment-in-sonicwall-s-telemetry
  4. Department for Science, Innovation and Technology, “Cyber security breaches survey 2025/2026: education institutions findings”, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026-education-institutions-findings
  5. Department for Education, “Cyber security: core standard” (Meeting digital and technology standards in schools and colleges), guidance, last updated 16 September 2026. https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/cyber-security-core-standard
  6. National Cyber Security Centre, “Alert: Apache Log4j vulnerabilities”, alert, 10 December 2021. https://www.ncsc.gov.uk/news/apache-log4j-vulnerability
  7. SonicWall, “Spencer Starkey”, blog author profile (title check), undated. https://www.sonicwall.com/blog/authors/spencer-starkey
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →