Penetration Testing for Schools
Find the gaps in your school’s defences before someone else does.
Policies say your school is secure. A penetration test finds out whether that’s true. Our education-focused security specialists probe your network, cloud tenancy and staff processes the way a real attacker would — safely, within an agreed scope and agreed hours — and then tell you, in plain English, exactly what they found and what to fix first.
We’ve worked in school IT since 2000, and we support 249 schools and 20 multi-academy trusts across the UK. That matters here, because a school pen test isn’t a corporate pen test with the logo swapped: it has to understand MIS systems, safeguarding duties, shared classroom devices and a network that half the county’s teenagers are actively trying to outwit. Ours does.

Trusted by schools across the UK
Why schools put their defences to the test
Because “we think we’re okay” isn’t evidence.
Firewalls, filtering and MFA can all be in place and still be misconfigured. The only honest way to know whether your defences work is to test them the way an attacker would — and get a written answer.
Because schools are targets.
Education is one of the most-attacked sectors in the UK. Schools hold personal data on children and staff, run payroll, and leave networks switched on through every holiday. Most successful attacks exploit ordinary, findable weaknesses — exactly what a test is designed to surface first.
Because assurance is now expected.
Governors, trust boards, auditors and insurers increasingly ask not just what protections a school has, but how it knows they work. A recent test report is a direct, credible answer — and it goes further than certification sampling: Cyber Essentials Plus audits a sample of devices against five controls, while a penetration test actively probes your whole agreed scope.
Because fixing beats hoping.
A test that ends with a scary PDF has failed. Ours ends with a prioritised fix list — and, for supported schools, the same team that found each issue is the team that resolves it.
What a school penetration test covers
Every engagement is scoped to your school or trust — a single site, a sample of schools, or a whole estate. Depending on what we agree, testing can cover:
External infrastructure.
What an attacker on the internet can see and reach: your public-facing services, remote access routes and boundary defences, tested from outside your network — no login, no inside knowledge, just what the world can find.
Internal network.
What someone already inside could do — a compromised laptop, a rogue device plugged into a classroom port, or a pupil pushing their luck. We test how far an intruder could move, what they could reach, and whether anything would notice them.
Web applications and cloud tenancy.
The systems your school actually lives in: web-facing applications, portals and your Microsoft 365 or Google environment, tested for weak configurations, excessive permissions and routes to the data that matters.
Wireless networks.
Whether your Wi-Fi keeps staff, student and guest traffic properly separated — and whether someone in the car park with a laptop can get further than they should.
Social engineering awareness.
By agreement, we can test the human layer with controlled, realistic simulations — because most school breaches start with a person, not a firewall. Findings feed coaching, never blame, and pair naturally with our ongoing compromise alerts and phishing training.
Every scope area is optional and agreed in writing before anything is tested. Nothing is ever probed without your sign-off.
Penetration test or security audit — which does your school need?
The two are close relatives, and schools often need both — but they answer different questions.
A cyber security audit is a review, not an attack. We examine your configurations, policies, backups and evidence, rate every finding red, amber or green, and map your position against the DfE cyber security standards. It’s broad, it’s governor-facing, and it’s the fastest route from “we think we’re okay” to knowing where you stand.
A penetration test is the follow-through: an active, hands-on attempt to get past the defences the audit described. The audit asks “is MFA rolled out?”; the pen test asks “can we get in anyway?”. It’s narrower and deeper — proof, rather than review.
Our honest guidance: if your school has never had an independent look at its security, start with the audit — it’s exactly the clearly scoped follow-up we recommend deeper testing from. If you’ve done the groundwork — audit findings closed, Cyber Essentials controls in place — a penetration test is how you prove the work holds up under pressure. Not sure which you need? One call on 0115 9170 197 settles it.

How a test runs — without breaking anything
A penetration test on a live school network has to be safe, or it’s worthless. Every engagement follows the same discipline:
1. Scoping and authorisation. We agree in writing what’s in scope, what’s off-limits, and when testing happens — typically evenings, weekends or holidays for anything intrusive, exactly as we schedule every other piece of disruptive work across the schools we support. Named contacts on both sides know testing is live.
2. Testing. Our specialists work through the agreed scope methodically, recording every step. Anything that looks like it could affect teaching, safeguarding systems or live services is flagged and agreed before it’s attempted — a test is controlled by design, and we stop the moment you ask.
3. Immediate escalation of critical findings. If we find something an attacker could exploit today, you hear about it that day — not in the report three weeks later.
4. Reporting and debrief. You get the findings twice: once as a technical report for IT staff, and once as a plain-English debrief pitched for heads, business managers and governors. No 90-page PDF nobody reads — a prioritised fix list with the risk, the evidence and the remedy for every finding.
Pupil and staff data is handled carefully throughout: testing is evidence-led, we take the minimum needed to demonstrate each finding, and our own infrastructure runs from UK data centres that are ISO 27001 compliant.

Reporting and remediation — where the test earns its fee
Most providers hand over the report and leave. We think the report is the halfway point.
Every finding is written to be actioned. Rated by severity, explained without jargon, and paired with a specific, practical fix — so your leadership team knows what’s urgent, what’s important and what can wait for the next budget cycle.
Remediation is our day job. For schools on our managed IT support, the engineers who fix the findings are the same 75-strong education-only team that already runs your network — tightening configurations, closing exposures and re-testing to confirm each gap is genuinely shut. No hand-off to a third company, no finger-pointing between your tester and your support provider, because they’re the same people.
Re-testing closes the loop. Once remediation is complete, we verify the fixes against the original findings — so “resolved” means demonstrated, not assumed.

Your findings become a live plan in AIT Horizon
A pen test report that sits in a drawer protects nobody. For our schools, every finding is loaded into AIT Horizon, the leadership platform included with our service — not sold on top.
The RAG compliance tracker holds each finding as a live red, amber or green item. When a critical exposure is closed, it turns green — and your evidence trail builds itself. Governors asking “what happened after the test?” get an answer on screen, not a shrug. In a trust, the Executive view shows the cross-estate picture while the Schools view gives each head their own site’s position.
IT Finance turns big findings into a fundable plan. When a test surfaces something structural — an end-of-life firewall, a server past its patch window — it drops into Horizon’s IT Finance module with 5-year projections across hardware refresh and software licensing, so the fix lands in a planned budget rather than an emergency one. (All figures illustrative.)
The strategy roadmap keeps momentum. Longer-term recommendations — segmentation, cloud migration, an annual re-test — take their place on your Horizon roadmap, so this test shapes the next three years of decisions, not just next term’s.
Horizon is one of four platforms we’ve built in-house — alongside Helpdesk Reporting, AIT Atlas and AIT Ordering — all reached through one login at the Customer Portal, and all included with our service.
Illustrative demo data
One test, one connected security plan
Penetration testing is one spoke of a complete security posture. Explore the rest of the cluster:
School IT security
the hub: every layer of how we defend schools
Cyber security audits for schools
the broad review that tells you where to test
Cyber Essentials for schools
certify the five controls, then prove them under test
Compromise alerts and phishing training
ongoing hardening of the human layer your test assessed
Managed backup and disaster recovery
the safety net a test will always ask about
IT support for schools
the day-to-day team that carries the fixes through
Frequently asked questions
No — safety is designed in from the scoping call. Anything with the potential to affect live services is scheduled outside teaching hours, agreed in writing first, and monitored while it runs. Unlike a real attacker, we have a phone number, a named contact and an instruction to stop on request. Lessons carry on as normal.
An audit reviews your defences on paper and in configuration; a pen test actively tries to defeat them. Cyber Essentials Plus has an assessor verify five fixed controls on a sample of devices; a pen test goes wherever your agreed scope allows and probes for whatever an attacker would actually use. Review, certify, test — most schools benefit from all three, in roughly that order.
As a rule of thumb: annually, and after any significant change — a new building, a major cloud migration, a merger into a trust. Because your findings live in Horizon’s RAG tracker and your re-test sits on the strategy roadmap, the next test is planned into your calendar and budget rather than remembered in a panic.
Yes. We support 249 schools and 20 multi-academy trusts nationwide, and penetration testing is delivered the same way as everything else we do: much of the work runs remotely by design, and any on-site elements are scheduled to your school wherever it is. Head office is in Nottingham; our service area is the country.
It’s a fixed fee agreed at the scoping call, based on the size of your estate and the scope areas you choose — external only costs less than a full internal, wireless and cloud engagement. No day-rate creep, no surprises, and for supported schools the remediation engineering is part of the service you already have. Call 0115 9170 197 and we’ll scope it in one conversation.
Ready to find out what an attacker would find?
One call agrees your scope. A few weeks later, your leadership team knows exactly where the gaps were, watches them turn green in AIT Horizon — and can prove it to anyone who asks.
Existing customers: sign in via the Customer Portal to talk to the team that already knows your network.

