Decoding the world of cybersecurity

Cyber remains undefined in England’s technical education plan

England’s planned technical pathways for pupils from age 14 include AI and digital subjects, although the place of cyber security within the curriculum has not been defined.

Cyber remains undefined in England’s technical education plan
Summary
  • Pupils will be able to combine core academic subjects with technical pathways and employer experience from Year 10.
  • AI, digital technology, manufacturing, energy, and other sectors are named, while cyber security is not listed separately.
  • Curriculum design will determine whether secure technology use becomes a core technical competence or remains dependent on local provision.

England’s planned expansion of technical education from age 14 will introduce pathways covering artificial intelligence, digital technology, manufacturing, energy, and other sectors, although the role of cyber security within the programme has not yet been defined.

The Department for Education said pupils will be able to combine English, mathematics, and science with technical learning, workplace experience, and contact with local employers from Year 10.

Schools, colleges, strategic authorities, mayors, employers, and local leaders will help design the pathways according to regional industries and skills needs. The government aims to begin national rollout in September 2028.

Advanced manufacturing, artificial intelligence, digital and technology, clean energy, life sciences, construction, health and care, and creative industries are among the areas identified in the policy. Cyber security is not named as a separate route, although detailed qualifications and curricula have not been published.

Security could be incorporated within digital, AI, engineering, manufacturing, or energy pathways as the programme develops. Funding arrangements, national standards, assessment models, and the division between common and locally designed content also remain unsettled.

The reforms are intended to place technical and academic education on a more equal footing, while changes to school inspection and performance measures will give greater recognition to practical pathways and progression into skilled employment.

Earlier contact with employers may help pupils understand how technical work is performed in operational settings rather than only through classroom exercises. The value of that involvement will depend on whether the curriculum develops transferable knowledge rather than training tied to individual products or short-lived technical fashions.

Security within technical competence

Cyber security sits across many of the sectors named in the reform. Manufacturing depends on connected machinery and remote support, energy relies on operational technology and digital control, while AI systems require protected data, software, cloud infrastructure, and managed access.

A separate cyber pathway could support specialist careers, but other technical routes still need to cover secure operation. Authentication, software maintenance, data handling, update integrity, incident reporting, and recovery now form part of ordinary engineering and technology work.

Graeme Stewart, head of public sector at Check Point Software, said: “Cyber security feels like the obvious missing piece.” He argued that security, trust, and resilience should form part of every pupil’s understanding of technology rather than being reserved for specialist IT roles.

Industry involvement can help keep course material connected to current practice, although national safeguards will be needed to prevent curricula becoming product training. Pupils require an understanding of system boundaries, dependencies, failure, trust, and accountability that remains useful when specific tools change.

AI education provides an immediate test. Familiarity with a generative service does not show that a pupil understands how uploaded information is processed, how model outputs should be checked, what permissions an integrated agent holds, or how automated decisions affect other systems.

Manufacturing and energy courses face comparable requirements. Future technicians do not all need specialist offensive-security skills, but they should recognise the operational consequences of shared credentials, exposed management interfaces, unverified software, and unsupported equipment.

The workforce requirement extends beyond jobs carrying a cyber security title. Organisations need developers who can maintain secure software, engineers who understand resilient control systems, procurement specialists who can examine supplier access, and managers who recognise when a technology change alters operational exposure.

Regional design could allow areas with strengths in defence, financial services, energy, technology, or advanced manufacturing to work closely with relevant employers. It could also produce uneven provision if security content depends entirely on the expertise available within each local partnership.

A common national baseline could establish secure digital and technical competence across every pathway, with deeper specialist routes available where local capacity supports them. Assessment could then examine applied judgement and system understanding rather than relying on awareness messages or memorised terminology.

The policy remains at an early design stage, leaving the curriculum open to those decisions. Pupils entering technical education in 2028 will work in environments where software, identity, data, and physical operations are closely connected, and the quality of the programme will depend partly on whether they learn how those systems fail as well as how they function.

×