Summary
- Comparitech examined 25,454 UK school websites against seven remotely observable browser-side security controls.
- Only 52 sites implemented all seven measures, while 7,001 — 27.5% — implemented none.
- The study does not assess server security, authentication, patching, internal systems, or schools’ overall cyber maturity.
More than a quarter of UK school websites assessed in a new study implemented none of seven common browser-side security controls, exposing a substantial gap between widespread use of modern encryption and adoption of additional web-hardening measures.
Comparitech examined 25,454 primary and secondary or private-school websites, comprising 20,450 primary sites and 5,004 secondary or private-school sites. Researchers checked each homepage for seven controls that can be observed remotely without access to internal systems.
Only 52 websites, or 0.2% of the sample, implemented all seven measures. At the other end of the distribution, 7,001 sites — 27.5% — implemented none of them.
The assessment covered HTTP Strict Transport Security, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, security.txt, and Permissions-Policy.
Adoption varied considerably between controls. Comparitech found HSTS on 63.3% of the sites, while fewer than a third used Content Security Policy or maintained a security.txt file. Permissions-Policy was the least widely adopted of the assessed controls.
Transport encryption was considerably stronger. The researchers found widespread support for current TLS versions and generally strong certificate configurations and cipher suites, suggesting that basic HTTPS provision is more consistently established than additional browser hardening.
That difference may in part reflect the role of hosting platforms and content-delivery providers, which can supply HTTPS and certificate configuration by default, while security headers and disclosure mechanisms often require more deliberate configuration.
The study should not be interpreted as a ranking of individual schools’ overall cyber security. Researchers checked homepages rather than every application or subdomain, and the work did not assess server-side vulnerabilities, software patching, authentication, endpoint security, identity management, internal networks, backups, or incident-response capability.
The individual controls also address different risks. A missing security.txt file affects how vulnerability researchers can find a reporting route, while Content Security Policy and X-Frame-Options can reduce exposure to particular browser-based attacks. Their absence does not establish that a website is vulnerable to every attack they are designed to mitigate or that it has been compromised.
The results nevertheless highlight the difficulty of establishing common technical baselines across decentralised public-sector environments. Schools can depend on internal staff, academy trusts, local authorities, website agencies, hosting companies, and education-technology suppliers, making ownership of relatively small configuration decisions difficult to see.
Websites are also only one element of the education technology estate. Account provisioning, cloud services, devices, and EdTech integrations create separate identity-governance pressures across schools and colleges.
The strongest conclusion from the new research is therefore narrower than a sector-wide judgement on cyber maturity. Secure transport appears widely established, while adoption of several additional browser protections and vulnerability-disclosure mechanisms remains inconsistent across a large sample of UK school websites.
For a sector handling student, parent, employee, safeguarding, and operational information across large numbers of separately managed technology services, that inconsistency adds another layer to the challenge of maintaining common security standards.




