Cyber security is no longer something organisations can afford to treat as a background issue. It is a live and ongoing risk that can affect day-to-day operations, learner experience, assessment delivery, data security and organisational resilience.
Recent messaging shared by Ofqual reinforces the urgency of this issue. The message is clear: organisations need to take immediate action on cyber security, not only to protect livelihoods and customers, but also because cyber resilience now forms part of the wider defence of our nation, economy and way of life.
For Approved Centres, this matters deeply. As an awarding organisation, we work in partnership with Centres to deliver trusted, inclusive and quality assured qualifications and assessments. That means cyber security is not simply an IT concern, it is part of protecting learners, safeguarding sensitive information, preserving assessment integrity and maintaining continuity of delivery. This aligns closely with Ofqual’s regulatory framework, which includes requirements around identifying and managing risks and incidents, maintaining appropriate arrangements with Centres, and protecting the confidentiality of assessment materials.
Why cyber security matters for Centres
A cyber incident can disrupt much more than systems. It can affect:
- access to learner records and registration data
- secure storage and transfer of assessment materials
- communication with staff, learners and external stakeholders
- continuity of teaching, learning and assessment activity
- confidence in the integrity and reliability of qualification delivery
In a regulated environment, these are not minor concerns. Ofqual’s Principles require awarding organisations to act with honesty and integrity, maintain public confidence in qualifications, and take a proactive approach to compliance. Strong cyber security across the wider delivery network supports those same outcomes in practice.
A practical resource for training providers
To support the sector, Centres are encouraged to make use of the Department for Education’s Cyber Security Hub, which provides practical guidance on both planning for and responding to cyber incidents.
Although the Hub is primarily aimed at schools and colleges, the information is highly relevant to many training providers and Approved Centres. It offers a useful starting point for organisations that want to strengthen their cyber awareness, review their preparedness, or understand what action to take if an incident occurs.
From an awarding organisation perspective, this is exactly the kind of practical support that can help Centres improve resilience and reduce disruption.
What Centres should be doing now
Cyber security can feel complex, but meaningful progress often begins with straightforward, well-managed actions. We encourage Centres to review their current arrangements and consider the following:
1. Review your cyber preparedness
Make sure you understand how well prepared your organisation is to prevent, detect and respond to a cyber incident. This should include who is responsible internally, what your escalation routes are, and how you would maintain business continuity if systems were affected.
2. Protect sensitive information
Centres routinely handle personal data, internal communications and, in some cases, assessment-related materials. Reviewing access controls, storage arrangements and sharing processes is an important part of reducing risk.
3. Strengthen staff awareness
Many cyber incidents begin with human error, such as clicking malicious links, weak password practices or responding to fraudulent emails. Regular reminders and short awareness updates can make a real difference.
4. Plan for disruption
If a system became unavailable, how would your Centre continue with key activities? A clear incident response plan can help minimise downtime and support effective communication with staff, learners and partners.
5. Use trusted guidance
The DfE Cyber Security Hub is a practical resource that can help Centres understand both prevention and response. Using recognised guidance supports a more consistent and informed approach across the sector.
Why this matters to learners
Ultimately, cyber security is about people as much as technology. Our shared mission is to provide learners, Centres and organisations with respected, valued, inclusive and quality assured qualifications and assessments. Protecting systems, information and delivery arrangements is part of protecting the learner journey itself.
Where cyber resilience is strong, Centres are better placed to:
- support uninterrupted learning and assessment
- protect learner information
- respond confidently to incidents
- maintain trust with employers and learners
That trust is essential. In the regulated qualifications environment, public confidence is a core principle, and strong organisational controls help uphold it.
Our message to Approved Centres
We encourage all Approved Centres to treat cyber security as a priority area for review and action.
Even where robust systems are already in place, now is a good time to revisit them, refresh staff awareness and ensure incident planning is up to date. Small improvements made now can significantly reduce risk later.
Cyber security is a shared responsibility across the qualifications and assessment landscape. By taking proactive steps, Centres can strengthen resilience, protect learners, support staff and help maintain the integrity of the services we collectively provide. Ofqual’s framework explicitly emphasises proactive compliance, risk management, incident management, centre arrangements and confidentiality, all of which are relevant to cyber readiness in practice.
Useful links
- GCHQ
Annual Lecture 2026:
https://www.gchq.gov.uk/speech/gchq-annual-lecture-2026-as-delivered - Department
for Education Cyber Security Hub:
https://cyber-security-hub.education.gov.uk/