Smart guides

Blog

Safeguarding meets cyber security

Safeguarding meets cyber security

What KCSIE 2026 means for your school

Hands protecting a laptop displaying a secure padlock icon.
Photo of Anna Westlake
Photo of Anna Westlake

Anna Westlake

|

Insights

'Keeping Children Safe in Education 2026’ (KCSIE 2026) came into force on 1st September 2026, and for the first time it says outright what a lot of schools have suspected for a while: cyber security isn't just an IT problem, it's a safeguarding one. If your governing body hasn't yet joined the dots between your data systems and your statutory safeguarding duties, this is the moment to do it.

What's actually changed

Schools and colleges have always had a statutory responsibility to keep children safe online as well as offline, set out in Keeping Children Safe in Education (KCSIE). What's new in the 2026 edition is how explicit that responsibility has become. The section entitled "Information security and access management" now sets out clearly that governing bodies and proprietors should take measures to safeguard children by protecting personal information and ensuring appropriate cyber security systems are in place, and that this sits within the school's wider safeguarding responsibilities, not alongside them. Schools are directed to the DfE's cyber security standards for schools and colleges as the recommended approach to meet that expectation.

It's a small wording shift with a real consequence. A weak firewall or a poorly managed set of user permissions is no longer just an operational risk to flag with IT. It's a safeguarding gap, which means it now sits squarely on the desk of the designated safeguarding lead and the governing body, not just the network administrator.

Person managing data securely at a computer.

How this affects independent schools

Independent schools may assume this is a maintained-sector issue, tied to funding agreements that don't apply to them, but it isn't. Independent schools must meet KCSIE, the same statutory safeguarding framework that applies to every school in England. They're assessed against the Independent School Standards, which the Independent Schools Inspectorate (ISI) inspects rather than Ofsted, with safeguarding being one of the areas ISI inspects closely. 

In practice, that means the governing body of an independent school carries exactly the same accountability here as a maintained school, even though the two sit in different regulatory systems.

Which systems are in scope

Strip away the legal language and this is really about three things: who can see sensitive pupil data, where that data lives, and how well it's protected in transit between systems. For most schools, that's a wider footprint than it first appears. It covers the obvious things like your MIS and your safeguarding record-keeping software, but it also covers the less obvious ones like admissions enquiry forms, the CRM those enquiries land in, and any data syncs that move information between them.

Every point where pupil or family data crosses from one system to another is a point where access management and security controls matter. A school that has never mapped out where its admissions data actually travels (for example, website, to CRM, to MIS, and back again) may find that mapping exercise reveals more than expected.

Person mapping a user's journey through a website.

What to ask your suppliers

This is where relationships with digital suppliers matter as much as a school’s internal IT policy. The standards don't expect every school to become a security expert overnight; they expect governing bodies to be able to show they've taken reasonable, evidenced measures, and that includes the measures taken by the third party suppliers handling their data.

A few questions worth putting to any supplier who touches pupil or family data: 

  • Is their information security independently tested, or only self-declared? 

  • Who has access to school data, and is that access properly scoped and logged? 

  • How is data secured both at rest and while it's moving between platforms? 

Cursor holds Cyber Essentials Plus certification, the higher tier of the government-backed scheme which is independently tested each year rather than self-assessed, and we are able to confidently answer these questions for the schools we work with. If your suppliers can't answer clearly, that's worth knowing before September's changes are tested by an inspection, not after.

Key takeaways

KCSIE 2026 hasn't invented a new duty so much as sharpened an existing one, and made it unambiguous that cyber security sits inside safeguarding rather than beside it. Independent schools aren't exempt because they sit outside the maintained sector's funding rules; KCSIE and the DfE's cyber security standards reach them via ISI's inspection of safeguarding. The practical starting point for most schools is straightforward: map where pupil data actually flows across your systems and suppliers, and make sure you can evidence that every link in that chain takes security as seriously as you do.

If you'd like a second pair of eyes on where your admissions or pupil data moves between systems, or how solutions like our HubSpot to iSAMS Admissions Sync might fit into that picture, get in touch. You can also see how we've assisted other schools via our case studies.

Articles, tips and knowledge delivered straight to your inbox

Articles, tips and knowledge delivered straight to your inbox

Articles, tips and knowledge delivered straight to your inbox