CREST-ACCREDITED PENETRATION TESTING

Cyber Security Audit for Schools

A cyber security audit for schools reviews your defences against the controls insurers commonly ask about and the DfE digital standards set out, then gives you a prioritised fix list your IT team can act on. It is a plain-English review built for school business managers and IT leads, not a report only a security engineer can read.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori

AUDIT SCOPE

What the audit covers

The audit reviews the controls that decide whether a school incident is an inconvenience or a closure.

The DfE angle

The DfE’s cyber security core standard asks schools to conduct a cyber risk assessment annually and review it every term; this audit is a straightforward way to run that assessment with specialist eyes.

The Cyber Essentials angle

If you are working towards Cyber Essentials, the audit doubles as a gap check against the five controls the scheme assesses.

We review
User accounts and MFABackupsPatchingStaff and student network segregationMIS accessRemote accessThird-party apps

If staff phishing is the worry, pair it with a phishing assessment that measures it directly.

RPA COVER

RPA cover and cyber evidence

If your school or trust is an RPA member, cyber cover comes with conditions.

What the rules say

The RPA membership rules state that when you claim you will be required to evidence compliance with the cover conditions.

What the audit gives you

An audit checks that evidence exists before you ever need it, and gives commercially insured schools the same proof for an insurer’s questionnaire.

That includes meeting the DfE’s cyber security standard on backups: at least 3 backup copies of important data, on at least 2 separate devices, at least 1 must be off-site.

AUDIT OR TEST

Audit or penetration test?

An audit reviews your controls; a penetration test attempts to defeat them the way an attacker would.

Start with an audit

Start with an audit if you have never had an independent review.

Step up to a test

Step up to a penetration test when you want proof of what an attacker could actually reach.

In our experience, trusts often audit every school and test a sample.

PRICING

What it costs and how long it takes

How it is priced

A school audit is built on our published day rate of £1,100 to £1,400 and quoted as a fixed price for a defined scope, so the price you agree is the price you pay.

How long it takes

The number of days is agreed at scoping, and we schedule in or out of term time to suit you.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

FAQ

Frequently asked questions

Can a MAT audit all its schools at once?

Yes. A trust-wide audit reviews central IT and shared platforms once, then applies a consistent per-school checklist, so every academy gets its own fix list without paying for the same central work twice. Ask for a trust-wide quote and we will price it as one engagement.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a pen test quote in 24 hours

Tell us what needs testing and a CREST-accredited UK team replies within one business day with a fixed price.