More than one in four UK school websites lack key browser security controls

More than one in four UK school websites lack key browser security controls

Research covering more than 25,000 UK primary and secondary school websites found 27.5% had none of seven commonly used browser-side security controls, while just 0.2% had implemented all seven.

More than one in four UK primary and secondary school websites lack all seven browser-side security measures assessed in new research highlighting potential gaps in the education sector’s web security.

Comparitech analysed 25,454 school websites, comprising 20,450 primary and 5,004 secondary and private school sites, to examine their implementation of common controls designed to mitigate threats including cross-site scripting, clickjacking, information leakage and insecure connections.

Only 52 websites – 0.2% of those analysed – had implemented all seven measures, while 7,001, or 27.5%, had none.

Primary schools performed better than secondary schools across every control assessed, implementing an average of 2.9 measures compared with 2.6 among secondary schools.

Content Security Policy (CSP), regarded as an important defence against malicious scripts and other unauthorised content, was present on fewer than a third of school websites.

More than 60% lacked X-Frame-Options, while over 40% did not have an X-Content-Type-Options header. Some 57.7% lacked a Referrer Policy and only 16% implemented a Permissions Policy.

The research found 36.7% of schools did not use HTTP Strict Transport Security (HSTS), which instructs browsers to use secure HTTPS connections. Fewer than a third also provided a security.txt file through which researchers can report vulnerabilities.

Rebecca Moody, Head of Data Research at Comparitech, said: “This latest research highlights an alarming gap in browser security within UK schools. This is particularly concerning because school websites not only house sensitive student and staff data but will often be trusted by students, staff and parents. If they lack key browser security controls, this leaves them (and their users) vulnerable to data breaches, phishing campaigns, and cyber attacks.

“Schools remain a key focus for hackers. So far this year, 11 UK primary and secondary schools have been targeted by ransomware groups alone. While it’s not clear how the ransomware groups gained access to the schools’ systems in these cases, our findings show that over 40% of them had three or fewer critical browser security controls in place. In one instance, the school had none of the controls in place and its ransomware attack led to four days of school closures.”

The study found stronger adoption of modern encryption, with 83.8% of school websites supporting TLS 1.3 and 93.9% supporting TLS 1.2.

Comparitech stressed that the study examined externally observable browser-side measures rather than server-side security, authentication, patching or vulnerability management. The results should therefore be viewed as an indication of website security posture rather than a comprehensive assessment of schools’ overall cybersecurity.

Browse our latest issue

Intelligent Edu.tech

View Magazine Archive