Is your school cyber secure for the DfE’s Risk Protection Arrangement (RPA)?

30 January 2023

What is the RPA

The risk protection agreement (RPA) is available to schools in England and is an alternative to commercial insurance with tailored cover for schools and academy trusts that includes employers’ liability, professional indemnity, business interruption and cyber cover.  Full details of the cover is available on the government’s RPA website.

Cyber cover for RPA members

One area of cover that the RPA provides is the insurance against cyber incidents. The cover provides costs and additional expenditure that was reasonably incurred in order to minimise an interruption as well as incident response services and remediation services – full terms are available on the RPA.

Cyber Cover conditions for RPA members

In order to comply with the RPA’s conditions of cover for cyber incidents, members are required to evidence their compliance with the following conditions:

  1. Have offline backups that follow the NCSC’s offline backups rule, that are tested appropriately and that back-up all your key data, as per the NCSC’s guide for backing up data.
  1. Ensure all employees or governors (anyone with access to your IT systems) undertake the NSCS cyber security training for school staff. The training allows employees to self-learn by watching an online video and then download a certificate. 
  1. Register with Police CyberAlarm, a free tool funded by the Home Office that monitors and reports suspicious cyber activity on your Internet connection. 
  1. Have a Cyber Response Plan in place. Your in-house team or your IT support provider will be able to help with the technical details. The starting point is to download the template cyber response plan from the RPA risk management portal. 

This information is available in full from the RPA section of the gov.uk website under the section “Full details of your cover”.  Guidance is available for academy trusts, church academies, local authority maintained community schools, voluntary aided and voluntary controlled schools. 

How we can help

We provide managed IT services to schools and academy trusts and provide impartial advice on the best way to become compliant with cyber security elements of the risk protection agreement. You can get in touch to arrange a discussion today.

Share this post

Work with us

One of our dedicated IT experts will be in touch:

Let us call you back

DD slash MM slash YYYY
By clicking the submit button below, you consent to Primary Technology storing and processing the personal information submitted in this form to respond to your enquiry.
This field is for validation purposes and should be left unchanged.