What the DfE has actually confirmed

The DfE now identifies six core digital and technology standards: broadband internet, wireless networks, network switching, digital leadership and governance, filtering and monitoring, and cyber security. Its guidance says all schools and colleges should be working towards meeting these core standards by 2030.

The standards are broader than a list of equipment to buy. They connect technology with safeguarding, teaching and learning, financial planning, data protection, business continuity and governance. The DfE also maintains supporting standards covering cloud services, IT support, devices, accessibility, cabling, servers and storage.

The filtering and monitoring and cyber security standards support schools' existing statutory responsibility to keep children and young people safe online as well as offline. The 2030 direction should therefore be viewed as a structured improvement programme, not permission to postpone current safeguarding or security responsibilities.

Our practical outlook for 2027

The DfE has not published a separate list of new rules that begins on 1 January 2027. The points below are our practical interpretation of the current standards and what schools are likely to need during the year ahead as they move closer to the 2030 objective.

The central change is likely to be evidencing decisions. Schools may already have broadband, wireless networking, filtering, backups and external IT support, but the standards ask who owns each area, how suitability is checked, where risks are recorded and when plans are reviewed. In 2027, a verbal assurance that 'IT looks after it' will be less useful than documented responsibilities, current registers and a costed improvement plan.

1. Digital leadership will become more visible

The DfE leadership and governance standard says the headteacher or principal should appoint a senior leadership team member responsible for digital technology. That person does not have to be the technical expert; their role is to connect teaching, operations, safeguarding, data protection, finance, governance and IT support.

Schools should also maintain contracts, physical asset and information asset registers. These records support safer decisions, expose unsupported equipment and unwanted renewals, and help governors understand where spending or risk is accumulating.

The DfE expects a minimum two year digital technology strategy aligned with the school or college development plan and reviewed at least annually. For many schools, 2027 should be the year that isolated replacement requests become one coordinated roadmap covering educational outcomes, security, support and lifecycle costs.

  • Name the SLT digital lead and define their responsibilities.
  • Consider a digital link role for a governor or trustee.
  • Bring contracts, devices, systems and information into maintained registers.
  • Create a costed technology roadmap covering at least two years.
  • Review the strategy before budget decisions are finalised.

2. Cyber security will need termly governance, not an annual questionnaire

The DfE cyber security core standard calls for a cyber risk assessment every year and a review every term, as well as after a significant change or incident. The risk assessment should cover devices, systems, data, accounts, permissions, suppliers, physical security and the network, not only antivirus and passwords.

A school also needs a cyber response plan linked to business continuity. The DfE guidance asks schools to keep important documentation in diverse locations and notes that a cyber response plan is a condition of cover for schools using the Risk Protection Arrangement.

Cyber awareness should reach staff, students, governors or trustees and others with a login. The guidance says training should take place at least annually, with more frequent activity where a known risk exists. In practice, schools should schedule the year's risk reviews, exercises and training rather than waiting until renewal or an incident.

  • Review privileged accounts, leavers, shared users and multifactor authentication.
  • Confirm software and devices remain licensed, supported and patched.
  • Keep network diagrams, configuration records and supplier contacts current.
  • Test access to backups and essential systems during a simulated outage.
  • Give staff and pupils a clear route for reporting security concerns.

3. Filtering and monitoring will remain a safeguarding responsibility

Filtering blocks harmful or inappropriate content; monitoring helps identify concerning activity that may require safeguarding action. Neither should be left solely as a technical product managed by a supplier. The school needs an approach suited to its pupils, risks, devices and curriculum.

The designated safeguarding lead, SLT, governors and IT support need to understand what is filtered, what is monitored, how concerns are escalated and how the system is checked. Overly restrictive filtering can obstruct learning, while weak controls can expose pupils to harm.

For 2027 planning, schools should review whether coverage follows users across school devices and different networks, how reports reach safeguarding staff, and whether cloud applications, search tools and generative AI services have changed the risk picture.

4. Resilient infrastructure will need a funded plan

The three infrastructure core standards cover broadband, wireless networks and network switching. Reliable teaching, cloud services, safeguarding systems, telephony, CCTV and administration now depend on the same underlying connectivity, so failure in one component can affect far more than internet access in a classroom.

The DfE broadband standard includes an appropriate backup connection for resilience. Wireless and switching guidance focuses on suitable performance, coverage, security, management, support and future capacity. Schools should base upgrades on surveys and evidence rather than replacing individual access points or switches only when they fail.

A 2027 plan should identify unsupported switches, wireless dead zones, single points of failure, cabling limitations, capacity problems and contracts approaching renewal. Costs can then be phased across budget years instead of becoming emergency expenditure.

  • Record broadband contracts, capacity, service levels and renewal dates.
  • Confirm the backup connection is independent enough to be useful during an outage.
  • Review wireless coverage and capacity in real teaching conditions.
  • Document network switches, support status, configuration and power resilience.
  • Include cabling, firewalls, filtering and core services in the same design review.

5. Artificial intelligence will move from experiment to governance

Generative AI is not one of the six core standards, but the DfE's guidance makes it part of the wider technology, safeguarding and data protection conversation. Schools remain free to choose suitable uses while meeting their existing legal and statutory responsibilities.

The immediate benefits are often activities used by teachers, such as planning, resource creation and administration. Risks include inaccurate output, bias, unsafe content, personal data disclosure, intellectual property issues and convincing phishing or impersonation. DfE guidance recommends not entering personal data into generative AI tools and says use by pupils needs appropriate safeguards, supervision, age controls, filtering and monitoring.

Our expectation is that 2027 will bring wider everyday use, whether formally approved or adopted informally by staff and pupils. Schools should therefore maintain an approved tools process, clear acceptable use rules, staff training, data protection assessment and a method for reviewing educational benefit instead of relying on a blanket ban or uncontrolled adoption.

6. Schools will ask more of IT support and suppliers

The DfE standards repeatedly assign delivery tasks to internal or outsourced IT support while keeping accountability with school leadership. A support agreement should therefore explain more than response times: it should show who maintains inventories, reviews cyber risks, tests recovery, manages filtering, documents networks and advises on the technology strategy.

Schools should ask suppliers how they protect their own systems and access, how administrator accounts are controlled, how incidents are reported, and which tasks fall outside the contract. The DfE cyber guidance also suggests schools may wish to ask outsourced IT providers whether they hold Cyber Essentials or Cyber Essentials Plus.

An annual service review should compare what the school needs with what the support provider actually delivers. Gaps can then be funded, reassigned or included at the next renewal rather than remaining assumed responsibilities.

A sensible 2027 action plan

Schools do not need to replace everything at once. Start by assessing the six core standards using the DfE's Plan Technology for Your School service, record the current evidence and agree which gaps create the greatest safeguarding, operational or financial risk.

Turn those gaps into a phased plan with named owners, target dates, estimated costs and a review timetable. Quick governance improvements, such as assigning roles, updating registers and scheduling risk reviews, can run alongside longer infrastructure projects that need surveys, procurement and capital funding.

  • Complete a baseline review against all six core standards.
  • Assign an SLT digital lead and appropriate governor oversight.
  • Update asset, contract, information and risk registers.
  • Agree the top safeguarding, cyber and resilience priorities for the spring term.
  • Build infrastructure replacements into the 2027 and 2028 budget cycles.
  • Review filtering and monitoring with the designated safeguarding lead.
  • Create or update an AI acceptable use and approval process.
  • Test the cyber response, business continuity and disaster recovery plans.
  • Review whether the IT support agreement covers each assigned responsibility.
  • Report progress to governors or trustees at agreed points during the year.

How Bury I.T. Support can help

Bury I.T. Support works with schools to assess technology against educational and operational needs, document the current estate and turn DfE guidance into practical priorities. We can support cyber security, Microsoft 365, networks, wireless connectivity, cabling, backup, filtering discussions and ongoing IT management.

The aim is not to produce a long report that sits unused. A useful review should leave leadership with a clear picture of what already meets the standard, what needs evidence, what should change first and what needs to be included in future budgets.

Official sources and further reading

These primary sources were checked when this article was last reviewed.

Written by

Christopher Lomax

Director of Bury I.T. Support Ltd, with more than 20 years of hands-on experience supporting business IT, Microsoft 365, networks, servers and cyber security.

About the team