Guide

The RPA cyber cover conditions, checked

A plain-English guide for school business managers and IT staff. Last checked against the DfE's guidance on 4 October 2026.

Most state schools and academies in England are covered by the DfE's Risk Protection Arrangement (RPA) instead of commercial insurance, and the RPA includes cover for cyber incidents. That cyber cover has four conditions. If a school has not met them when something goes wrong, it may not be covered — so they are worth checking now, not after the ransomware note appears.

1. Offline backups

What it asks. Backups of your important data that are kept offline — disconnected from your network, so an attacker who gets in cannot reach them — following the NCSC's guidance on backing up data. They should be tested, so you know you can actually restore from them.

Where schools trip up. “The backups are on the NAS” (which sits on the same network as everything else); cloud backups synced by an account the attacker now controls; backups nobody has tried restoring in years.

Evidence that answers it. Where the offline copy lives and how it is kept offline; the date of your last successful test restore, and what you restored.

2. NCSC cyber security training

What it asks. Everyone who uses the school's IT systems — staff and governors — completes the NCSC's free cyber security training for school staff.

Where schools trip up. New starters and governors joining mid-year; supply and peripatetic staff who have accounts; no record of who has done it.

Evidence that answers it. A list of who has completed it and when, kept up to date as people join.

3. Police CyberAlarm

What it asks. Registration with Police CyberAlarm, a free Home Office-funded service that watches the traffic at your internet connection for signs of attack and sends you reports.

Where schools trip up. Police CyberAlarm moved to a new platform recently, and registrations on the old one were not carried over — a school that signed up a few years ago may need to register again. Check that yours is on the current platform and that someone actually reads its reports.

Evidence that answers it. Your registration confirmation and who receives the reports.

4. A cyber response plan

What it asks. A written plan for what you will do if you suffer a cyber incident: who to call (including the RPA's own helpline), who decides what, how you keep the school running, how you tell staff and parents. The RPA provides a template.

Where schools trip up. A plan written once and filed; contact numbers that only work if email and the phone system are up; nobody else knowing where it is.

Evidence that answers it. The plan, dated, with a printed copy somewhere that does not depend on the network — and a note of when you last walked through it with the people named in it.

A quick self-check

Where Groundskeeper helps — and where it does not

Groundskeeper is IT monitoring for schools. Of the four conditions, it helps with the first and supports the fourth; the other two are outside what it does.

Groundskeeper is free for schools to use.

Find out more about Groundskeeper

More guides: The DfE filtering and monitoring standards, explained · Cyber Essentials for schools: what you actually need.

The official guidance: Risk protection arrangement (DfE Cyber Security Hub). This guide is a summary to help you find your way around it; where they differ, the RPA's own terms are what count, and the RPA can confirm what applies to your school.