根据英国考试监管机构 Ofqual 的调查,英格兰的中学报告的网络安全事件数量略有减少,且在遭遇灾难时学校的恢复速度也有所加快。在 2025/26 学年,有 27% 的中学报告了网络安全事件,这一比例低于前一年的 29% 和 2023/24 学年的 34%。Ofqual 于 7 月对英格兰的 3,775 名中学教师进行了调查。对于涉及整个学校的情况,调查仅统计了每所学校中最资深教师的回答,最终获得了约 2,162 所学校的样本数据。
England's secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by exams regulator Ofqual. Twenty-seven percent of schools reported an incident during the 2025/26 academic year, down from 29 percent a year earlier and 34 percent in 2023/24. Ofqual surveyed 3,775 secondary teachers in England in July. For questions concerning whole schools, it counted one response from the most senior participating teacher at each institution, producing a sample of up to 2,162 schools.
最常见的网络攻击类型是网络钓鱼攻击,其次是数据泄露、黑客攻击和勒索软件攻击;其中,2% 的受访者表示学校遭受了勒索软件的攻击。员工信息是最常被泄露的敏感数据,学生信息在 13% 的事件中受到影响,学生作业仅在 1% 的事件中受到影响。学校的恢复速度明显加快:在报告了网络安全事件的学校中,66% 的学校表示能够“立即”恢复正常运营(上一学年这一比例为 55%);另有 12% 的学校在半个学期(大约六到七周)内恢复了正常运营,1% 的学校需要超过半个学期的时间才能恢复正常,还有 1% 的学校需要整整一个学期的时间才能恢复。
Phishing was the most commonly reported type of incident, followed by data protection breaches, hacking, and ransomware. Ransomware affected 2 percent of respondents. Staff data was the information most commonly compromised. Student data was affected in 13 percent of incidents, while student work was affected in one percent. Recovery times improved more clearly. Among schools reporting an incident, 66 percent said they recovered "immediately," up from 55 percent the previous academic year. A further 12 percent recovered within half a school term – roughly six or seven weeks – while one percent took longer than half a term and another one percent required at least a full term.
Ofqual 表示,报告的导致“严重损害”的网络安全事件比例也从 10% 下降到了 7%。不过,“严重损害”的具体定义并未在调查中明确给出,监管机构表示受访者可以自行理解这个概念的含义。至于学校在过去一年中采取了哪些网络安全改进措施,54% 的教师表示“不清楚”;在剩下的 46% 的教师中,有一半表示学校制定了新的网络安全政策,22% 的学校采用了新的或经过测试的备份措施,20% 的学校完成了或更新了事件应对计划。
The proportion of reported incidents causing what respondents considered "critical damage" also fell from ten to seven percent, Ofqual said. "Critical damage" was not defined. The regulator told The that respondents were free to interpret the question in whatever way they felt best. Ofqual could not explain what had driven the apparent improvement. When asked what cybersecurity improvements their school had made during the past year, 54 percent of teachers selected "I don't know." Among the 46 percent who identified at least one change, half said their school had introduced a cybersecurity policy, 22 percent cited new or tested backup procedures, and 20 percent said they had completed or updated an incident response plan.
教师群体对谁应承担网络安全的首要责任意见不一。46%的教师认为应由IT团队负责,40%认为责任应由全体员工共同承担,只有9%认为是高级管理层。英国资格与考试管理局(Ofqual)认为,网络安全是管理层的责任,而非单纯的IT问题。Jamf教育总监马特·普伦表示,攻击频率和恢复情况的数据令人鼓舞,但各方对安全责任的理解仍令人担忧。
Teachers were divided over who bears primary responsibility for cybersecurity. Forty-six percent pointed to the IT team, while 40 percent said responsibility was shared among all staff. Just nine percent identified senior leadership. Ofqual argued that cybersecurity is a leadership responsibility rather than solely an IT problem. Mat Pullen, director of education at Jamf, said the attack frequency and recovery figures were promising, but the understanding of security responsibility was a concern.
普伦说:“减少安全事件固然重要,加快恢复同样重要。过去,网络攻击曾导致学校停课一周或更久,而本已受到新冠疫情冲击的教育又进一步受到干扰,家长请假也会影响更广泛的经济。归根结底,网络安全是IT部门、教师和高级管理层的共同责任,打破这些壁垒有助于保障技术安全和教学正常进行。”约三分之一的教师表示,过去一年里他们没有接受过任何网络安全培训,或不确定自己是否接受过培训,而一年前这一比例为28%。
"Reducing incidents matters, but so does recovering faster," Pullen said. "Cyberattacks have closed schools for a week or longer in the past, further disrupting an education already hit by Covid and affecting the wider economy as parents take time off work. "Ultimately, cybersecurity is a shared responsibility of IT, teachers and senior leadership, and breaking down these silos keeps technology secure and lessons running." Around a third of teachers said they had received no cybersecurity training during the past year or were unsure whether they had, up from 28 percent a year earlier.
另有比例相近的教师表示,接受的培训没有用。在接受过培训的人中,65%表示并未因此作出任何改变。英国资格与考试管理局的调查结果比政府4月发布的《网络安全 breaches调查》乐观得多。调查发现,在过去12个月中,49%的小学、73%的中学、88%的继续教育学院和98%的高校曾发现安全漏洞或攻击企图。两组数据不能直接比较。
A similar proportion said the training they received was not useful. Of those who received training, 65 percent said they made no changes as a result. Ofqual's findings look considerably rosier than the government's Cyber Security Breaches Survey, published in April. That research found that 49 percent of primary schools, 73 percent of secondary schools, 88 percent of further education colleges, and 98 percent of higher education institutions had identified a breach or attempted attack during the previous 12 months. The figures are not directly comparable.
英国资格与考试管理局询问的是中学教师所报告的网络安全“事件”,而政府调查则统计已发现的网络攻击和安全漏洞,无论其是否得逞。后者的调查对象还包括英国各地的教育机构,而非仅限英格兰的中学。
Ofqual asked secondary teachers about cybersecurity "incidents," while the government survey counted identified attacks and breaches regardless of whether they succeeded. The latter also covered education institutions across the UK rather than secondary schools in England alone.
即便如此,这项更广泛的调查仍显示学校遭遇攻击的频率之高。百分之二十七的继续教育和高等教育机构表示,它们至少每周都会发现攻击事件;在报告发生安全漏洞的机构中,近一半其系统受到不利影响。攻击一旦得手,可能迫使学校停课并关闭,直至系统恢复。6月,英格兰和威尔士多所学校因技术人员调查一起恶意软件事件而临时停课。英国信息专员办公室(ICO)去年表示,在英国教育领域归因于某一已知攻击组织的网络攻击中,超过一半是由学生实施的。®
Even so, the broader survey illustrated how frequently schools are targeted. Twenty-seven percent of further and higher education institutions identified attacks at least weekly, and almost half of those reporting a breach suffered an adverse impact on their systems. Successful attacks can force schools to close while systems are restored. In June, several schools across England and Wales shut temporarily while technicians investigated a malware scare. The ICO said last year that students were responsible for more than half of cyberattacks attributed to a known actor in the UK education sector. ®