RPA cyber cover: is your academy trust up to standard?

Most academy trusts fund their equivalent of business insurance through the Department for Education’s Risk Protection Arrangement (RPA) rather than commercial cover, and RPA now extends to cyber incidents.

That protection is conditional. Cover only responds if a trust can evidence four specific requirements, and the point at which most trusts discover a gap is after an incident, when a claim depends on evidence they assumed they had rather than evidence they can actually produce.

This article sets out the four conditions that determine whether RPA cyber cover actually applies, where Cyber Essentials fits alongside them, and the practical questions trust boards should be asking to evidence compliance rather than assume it.

What is the Risk Protection Arrangement and why does cyber cover depend on conditions?

The RPA is the Department for Education’s alternative to commercial insurance for academy trusts, funded by the government rather than underwritten by an insurer, and used by the significant majority of trusts in our own client base.

Cyber cover was added to the arrangement following a pilot, but unlike the arrangement’s more general property and liability sections, cyber cover carries specific conditions attached.

If a trust cannot evidence that those conditions were in place at the time of an incident, the cyber element of its cover will not respond, regardless of how the rest of its RPA membership is standing.

What are the four conditions for RPA cyber cover?

  • Offline backups: at least one backup held genuinely offline, disconnected from the live network other than when a backup is actively running, so that an attack on the live environment cannot reach it.
  • NCSC Cyber Security Training: completed annually by every employee and governor with access to the trust’s IT systems, not only IT staff, with evidence of completion retained.
  • Police CyberAlarm registration: registration is the requirement itself, not installation of the monitoring software, though installing it is worth doing for the vulnerability reporting it provides.
  • A documented cyber response plan: covering roles, escalation and who does what in the first hours of an incident, reviewed regularly rather than written once and filed.

Where does Cyber Essentials fit if it is not one of the four conditions?

Cyber Essentials is a separate, NCSC-backed certification built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.

It is not, on current DfE guidance, a stated condition of RPA cyber cover, and any suggestion that it is should be treated with caution until confirmed against the trust’s own membership terms.

What it does provide is independently reviewed evidence covering much of the same ground as the RPA’s four conditions, since a trust that can pass a Cyber Essentials self-assessment has, in practice, demonstrated the kind of basic control discipline the RPA conditions are trying to establish.

For trusts bidding into DfE-linked procurement or contracts involving pupil data, certification is increasingly expected in its own right, separate from RPA membership altogether.

Is Cyber Essentials Plus worth the additional step?

Standard Cyber Essentials is a self-assessment questionnaire, reviewed by an accredited certification body but not independently tested.

Cyber Essentials Plus adds hands-on technical testing by an assessor, verifying that the controls a trust has described are actually working rather than simply documented. For a trust that has never been tested, standard certification is the sensible starting point.

For one preparing for a funding bid, renegotiating insurance, or recovering credibility after a near miss, the independent verification behind Cyber Essentials Plus carries more weight with funders, auditors and insurers than a self-assessment alone.

What should trust boards ask before the next audit or claim?

  • Can we produce evidence, not recollection, for each of the four RPA conditions today, with dates attached?
  • When were our backups last tested for actual recovery, rather than simply confirmed as having run?
  • Do our training records show completion by every governor and member of staff with system access, not only IT staff?
  • Are we registered with Police CyberAlarm, and does someone specific own that registration and any resulting alerts?
  • Would our current controls pass a Cyber Essentials self-assessment if we were asked to sit one today?

None of these questions require a major project to answer well. They require someone to have looked recently, and to be able to show what they found. A short RPA compliance review, run alongside a Cyber Essentials readiness check, gives trustees a documented answer rather than an assumed one, and is a natural next step for any trust that has not looked at this formally in the past year.

How can Price Bailey help?

A short RPA compliance review checks each of the four conditions against the evidence a trust can actually produce, not just the policy it believes it holds, and flags any gaps before it is tested by a claim – rather than after.

We can run a Cyber Essentials readiness assessment alongside the review, identifying what would need to change to pass a self-assessment or a Cyber Essentials Plus technical test, and supporting the trust through certification itself.

This service is not available to trust for which Price Bailey acts as an independent auditor, in line with independence requirements under the FRC Ethical Standard.

For more information as to how our team can support you, you can fill out the form below.

We always recommend that you seek advice from a suitably qualified adviser before taking any action. The information on this page is intended as a general guide only. While we work to keep our content accurate and up to date, we cannot guarantee that it reflects the position at the time you are reading it. No responsibility for loss occasioned by any person acting or refraining from action as a result of this material can be accepted by the authors or the firm. For more information on our editorial process, click here.

Sign up to receive exclusive business insights

Join our community of industry leaders and receive exclusive reports, early event access, and expert advice to stay ahead – all delivered straight to your inbox.

Sign up

We can help

Contact us today to find out more about how we can help you

Top