A school network has a population of users with time, curiosity and an incentive to get around the rules, which makes it unlike almost any corporate environment. It also holds safeguarding records, staff payroll and pupil data. The Department for Education’s cyber security standards for schools and colleges set expectations around access control, filtering and backups, and wireless is where several of those expectations are tested daily.
Separating students from everything else
The student network should reach the internet and the specific services students need, and nothing else. That sounds obvious and it is routinely undone by convenience: a printer shared with the staff network, a management interface reachable from the student VLAN, or a shared authentication server that lets a student credential reach a staff resource. Testers approach this exactly as a student would, connecting to the student network and mapping what answers. The management information system is the target that matters, and it should be unreachable from that position. So should the finance system, the safeguarding records and anything the site uses for door access.
See also: NAEGELI Remote Deposition Services in Tacoma, WA
Filtering, monitoring and the ways around them
Statutory expectations around filtering and monitoring apply to the devices and networks the school provides, and students test them constantly. Personal hotspots, VPN applications, alternative DNS servers and encrypted proxies are all in daily use. A wireless assessment should include whether a device on the student network can bypass filtering through DNS over HTTPS or a tunnel, since that finding matters for safeguarding as much as for security, and it is often the one that prompts a change of platform.
“Schools tell me their wireless is fine because it uses a password students do not have. Students have it by the second week of term, usually from a supply teacher who wrote it on a board. Design on the assumption that every credential a student could possibly obtain has been obtained, and check what that access reaches.”

William Fieldhouse, Director, Aardwolf Security Ltd
Devices the school does not own
Bring your own device is normal in secondary and further education, and it means unmanaged hardware sits on your network every day. Put those devices on a network that is genuinely separate from the one managed devices use, with client isolation so they cannot see each other. Parents evenings, exam invigilators and visiting sports teams all need something too, and a guest network with a rotating credential is easier to manage than a series of exceptions on the staff network. Write down who may issue that credential and how often it changes.
Planning testing around the school year
Term time gives you a realistic picture and holidays give you room to break things. A sensible pattern is passive survey and configuration review during term, when the network is loaded and students are present, followed by active testing in the first week of a holiday so any disruption falls where it costs least. Wireless network testing covers the radio and segmentation layers, and internal network reviews answer what a device on each network can reach, which is the finding that matters when a student credential turns up somewhere it should not.
Frequently asked questions about school wireless
These questions come up whenever an education network is reviewed.
Should students and staff share access points?
Sharing hardware is normal and efficient. Sharing networks is not. Separate SSIDs mapped to separate VLANs with a firewall policy between them gives you the separation without buying two sets of equipment.
How often should a school test its network?
Annually as a baseline, and after any significant change such as a new building, a platform migration or a merger into a larger trust. Trust-wide estates benefit from sampling sites in rotation.

















