Skip to main content
Control Inbound. Protect Outbound. Train People Better.See What's Launching

Aug 28, 2026

Cybersecurity in UK Higher Education: Building an Institution-Wide Defence Strategy

Build your university's cybersecurity programme with this step-by-step UK playbook, from free NCSC and Jisc services to University Council reporting.

Alyssa Harmon

Key Insights

33% of BEC targeting higher ed came from compromised internal accounts—54% when the target was a student—versus a 13% average across industries.

98% of UK universities identified a breach or attack in the past 12 months, compared with 43% of businesses.

Impersonation sets universities apart: 79% of breached further and higher ed institutions reported it, vs 28% of businesses.

Cybersecurity in UK Higher Education: Building an Institution-Wide Defence Strategy

UK universities are not the under-governed, under-informed sector the breach statistics might suggest. Every higher education institution surveyed by the government last year had a board member, trustee, governor, or senior manager who owned cybersecurity, up from 81% the year before.

Nearly all described it as a high priority for their governing body. On the government's own 10 Steps to Cyber Security framework, 45% of institutions had acted on all ten, against 3% of private-sector businesses. And 98% of them still identified a breach or attack.

That combination is the real story for university security leaders. The gap is not awareness, governance, or even baseline controls. It is that the attacks now reaching campus inboxes are designed not to look like attacks, which makes them very hard to stop with the controls that governance frameworks ask about.

Across the 159 million attacks analysed in Abnormal AI’s 2026 Attack Landscape Report, higher education was the clearest outlier in one specific respect: the proportion of attacks arriving from inside the institution rather than outside it. That single characteristic explains most of what makes university email hard to defend, and it is not something a governance framework asks about.

This playbook sets out how to build a phased, resource-realistic programme to protect your institution. 

Higher Education Cybersecurity Explained

UK GDPR and the Data Protection Act 2018 govern personal data handling, with the ICO as regulator. Institutions running sensitive or dual-use research are also expected to follow NCSC and NPSA Trusted Research guidance, which is designed to protect academic freedom and international collaboration while managing the risk of research theft.

The Cyber Security and Resilience (Network and Information Systems) Bill, introduced to Parliament in November 2025, adds a further dimension. Most universities are not directly designated as operators of essential services under the Bill, but as Jisc has pointed out to the sector, institutions will feel it through their managed service providers, their data centres, and the supply chains they sit inside. 

Jisc's advice to institutions preparing for it is unglamorous and worth repeating: get the fundamentals right first, confirm that existing Cyber Essentials certification is actually operating as intended, and then look at whether the same standard holds across your suppliers.

The Attacks Universities Actually Face

Phishing remains near-universal, reported by 96% of further and higher education institutions that identified a breach. But the government's data shows a sharper pattern underneath it.

Among institutions that identified a breach or attack, 79% reported people impersonating their organisation or their staff in emails or online. The equivalent figure for businesses was 28%. Impersonation of universities has also risen fast, up from 68% the previous year. For a sector whose entire operating model depends on unfamiliar people emailing each other credibly, that is the number to plan around.

Four patterns account for most of the damage:

  • Vendor impersonation. Fraudulent invoices and bank detail change requests reach finance and procurement teams, frequently from a genuinely compromised supplier account rather than a lookalike domain. 

  • Payroll fraud. Attackers impersonate staff to request changes to salary payment details. Institutions with thousands of academic and professional services staff, many of whom rarely interact with payroll directly, are particularly exposed. 

  • Fee-payment fraud during admissions cycles. Prospective and newly enrolled international students are targeted through spoofed university domains and impersonated finance office emails.

  • Account takeover across a sprawling user base. With tens of thousands of students, staff, and visiting researchers cycling through annually, compromised credentials are a persistent risk. Around one in five institutions identifying a breach reported attempted takeovers of email, website, or social media accounts. 

Higher Education's Lateral Attack Problem

Impersonation at that scale raises an obvious question: who is doing it? In higher education, a substantial share of the answer is the institution's own accounts. Across all industries, 2.3% of phishing originates from a compromised account inside the target organisation. 

In education that figure is 7.1%—more than seven times the next-closest industry, and the largest sector outlier in Abnormal’s 2026 Attack Landscape Report. For students, nearly one in eight phishing emails arrives from inside their own institution

The business email compromise picture is more pronounced still. A third of all BEC targeting higher education (33%) is lateral, meaning it comes from a real internal account rather than a spoofed one. When students are the target, that rises to 54%. Across every attack type, students show a 14.9% lateral rate—the highest of any job category we measure, against a 2.7% average.

Every new semester brings new credentials, new devices, and no institutional memory of last year's attacks. A corporate security team can enforce password policy and decommission inactive accounts on a predictable schedule. A university is onboarding thousands of new users while offboarding thousands more, permanently.

This is also why the controls that work elsewhere underperform here. A lateral attack passes authentication, because it is authentic. It comes from a real address, in a real domain, from a real person who genuinely holds that account. There is no spoof to detect, no lookalike domain to flag, and no reputation signal to fail. The only thing distinguishing it from legitimate mail is that the person behind it is not behaving the way they normally do.

How University Cybersecurity Programmes Work: A Maturity Framework

A phased framework helps institutions establish essential controls before adding specialised tooling.

Foundation Phase: No-Cost Controls

Start with credible free resources. Cyber Essentials, the government-backed certification scheme, gives a baseline across five technical areas and is increasingly expected by funders, insurers, and public-sector partners. Sector awareness is effectively universal, at 98% of institutions, so this is rarely a question of discovery and usually one of scheduling.

The NCSC's 10 Steps to Cyber Security and Cyber Security Toolkit for Boards provide structured, no-cost frameworks for technical planning and governance conversations. Awareness of the Board Toolkit already runs at 92% across higher education institutions, which makes it a low-friction way to open a conversation with Council.

Join Jisc for shared cybersecurity services, threat intelligence, and incident response through Jisc CSIRT. This is already the sector's default: 82% of higher education institutions cite Jisc or the Janet network as an information source, ahead of the NCSC at 78%. Register for Exercise in a Box for free tabletop scenarios that need no specialist facilitation.

Capability Phase: Certification and Testing

Add endpoint detection and response with AI-assisted triage to catch what perimeter controls miss, which reduces the volume of raw telemetry a small central team has to review by hand.

Reinstate or expand structured phishing simulations, with heightened frequency for finance, HR, senior leadership, and anyone with access to sensitive research data. Formalise incident response and business continuity plans, then test them with IT, finance, communications, and research integrity or export control leads in the room. Begin engaging with NCSC and NPSA's Trusted Research programme if the institution runs sensitive or internationally collaborative research.

The supply chain deserves specific attention here. Institutions have improved markedly on immediate suppliers, with 80% now reviewing them, up from 69%. Only 37% have looked at their wider supply chain.

Advanced Phase: Funded Protection

Add managed detection and response for round-the-clock coverage. Most institutions cannot staff out of hours internally, and attacks routinely land outside core office hours and during vacation periods.

Layer email and identity security on top of native Microsoft 365 or Google Workspace protections, given how central email remains to impersonation and account takeover. This is the phase where the lateral problem gets addressed directly, because internal-to-internal mail is the traffic native controls scrutinise least.

Build formal reporting into University Council, Audit Committee, or equivalent governance structures, supported by the NCSC Board Toolkit. Institutions are already well placed here, with 84% updating their governing body at least quarterly.

One area where the sector is visibly behind its own standards: among institutions using or considering AI, only 49% had specific cybersecurity practices in place to manage the associated risks. That is the lowest figure of any education tier, at a point where 63% of institutions have already adopted AI tools.

Best Practices for University Security Teams

  • Verify financial changes independently. Require phone confirmation, using a number already held on file rather than one supplied in the email, before actioning any payroll change or vendor bank detail update. This single control prevents a disproportionate share of BEC losses and costs nothing.
  • Treat user training as a control, not a compliance task. It remains the most effective defence against attacks that bypass technical controls, particularly given how many students arrive with limited security awareness.
  • Establish a baseline before commercial spend. Use Cyber Essentials and NCSC guidance to get the fundamentals in place, and lean on Jisc's shared services rather than building everything in-house.
  • Run simulations continuously, not annually. Repeated exercises produce a trend rather than a snapshot. Weight them toward finance, HR, senior leadership, and researchers with access to sensitive data.
  • Build cyber hygiene into student induction. Cover account security, phishing recognition, and MFA, recognising that a large proportion of the user base turns over every year.
  • Close dormant accounts deliberately. Alumni, former staff, and visiting researcher accounts accumulate quietly and are attractive precisely because nobody is watching them.
  • Monitor internal mail, not just inbound. Most email security is oriented toward the perimeter, which leaves the traffic where a third of higher education BEC actually originates comparatively unwatched. Treat student-to-student and student-to-staff mail as a monitored surface.
  • Give students a reporting route they will actually use. In an environment where compromised peer accounts are the primary vector, students are the sensor network. A reporting path that is faster than forwarding to a generic IT address materially shortens the window in which one takeover becomes twenty.
  • Engage research leads early on Trusted Research. Treat it as a conversation with academics about protecting their own work, not a compliance requirement imposed on them.
  • Use shared and managed services. Jisc and managed detection services extend a small central team's reach across a large estate. Around half of institutions (51%) now outsource some element of cybersecurity management, up from 26% two years earlier.

Building Your Institution's Security Roadmap

  • Assess current risk honestly. Perfection is not the bar. The goal is being a harder target than comparable institutions with weaker defences.
  • Sequence the quick wins. Achieve Cyber Essentials, close obvious external vulnerabilities, and restore baseline awareness training. These deliver meaningful risk reduction without a large budget uplift.
  • Secure governing-body buy-in with data. The DSIT statistics, peer incidents, and Jisc benchmarking data all translate into language a University Council or Audit Committee will engage with. The sector's governance engagement is already strong, so the conversation is usually about prioritisation rather than persuasion.
  • Confirm your insurance position. Specific cyber insurance cover has nearly doubled across the sector, from 34% to 61% of institutions. But 24% of higher education institutions remain uninsured against cyber breaches or attacks, a higher proportion than any other education tier. Know which group you are in before an incident, not after.
  • Track measurable metrics. Phishing simulation trends, patching and remediation timelines, training completion, and incident response drill outcomes. ==Add one the sector rarely tracks: the share of reported phishing that originated from an internal account. If it is climbing, the lateral cycle is running.== Programmes showing steady year-on-year improvement build the credibility needed to secure further investment.
  • Plan in multi-year terms. Mature programmes are the result of sustained investment, not a single large purchase.

Moving Your Institution's Cybersecurity Defence Forward

Effective cybersecurity in UK higher education depends on fundamentals: sustained user training, a credible baseline through Cyber Essentials and NCSC guidance, and sector resources like Jisc used properly before reaching for commercial tooling. No institution achieves perfect security. The realistic goal is consistently reducing risk and being a harder, less attractive target than peers.

But the data is clear that fundamentals alone will not reach the lateral problem. When a third of the BEC aimed at your institution comes from accounts that are genuinely yours, the question stops being whether a message can be authenticated and starts being whether the person sending it is behaving normally.

Abnormal AI builds a behavioural model of every person and vendor connected to your institution, which is how it identifies the impersonation and account-based attacks that vendor fraud, payroll fraud, and student-facing scams depend on.

It works alongside existing Microsoft 365 or Google Workspace protections rather than replacing them, helping stretched teams strengthen detection of sophisticated email threats while reducing manual review. Abnormal was named a Customers' Choice in the 2026 Gartner® Peer Insights™ Voice of the Customer for Email Security, the only email security vendor to achieve this recognition three times in a row.

Learn More about Abnormal AI

Frequently Asked Questions

Which cyber threats are UK universities most likely to face?

Phishing is the most widespread, reported by 96% of further and higher education institutions that identified a breach. The threat that most distinguishes the sector is impersonation, reported by 79% against 28% of businesses, and rising year on year. Denial of service attacks (49%), malware (51%), and unauthorised access by staff (29%) and students (23%) all run far above business rates, while ransomware was reported by 14%.

Does the Cyber Security and Resilience Bill apply to universities?

Most institutions are not directly designated as operators of essential services under the Bill, which was introduced to Parliament in November 2025 and amends the NIS Regulations 2018. 

In practice, universities are likely to be affected through their managed service providers, data centres, and designated critical suppliers, and through the supply chains they participate in. Jisc's guidance to the sector is to strengthen fundamentals and supplier assurance now rather than waiting for scope to be settled.

What is a lateral attack, and why does it affect universities more?

A lateral attack is sent from a genuinely compromised account inside the institution rather than a spoofed external one, which means it passes authentication and carries the trust colleagues and classmates extend to internal mail. 

In our 2026 Attack Landscape Report, 7.1% of phishing in education originates internally against a 2.3% cross-industry average, and 33% of BEC targeting higher education is lateral, rising to 54% when students are the target. The driver is structural: large transient student populations, widespread password reuse, dormant alumni accounts, federated academic mail, and lighter monitoring of student accounts than staff accounts.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.