RPA cyber cover depends on four conditions. Can your trust evidence them?
What the Risk Protection Arrangement asks of academy trusts, where Cyber Essentials fits, and the questions boards should be asking before the next audit or claim.
What is the Risk Protection Arrangement and why does cyber cover depend on conditions?
The RPA is the Department for Education’s alternative to commercial insurance for academy trusts, funded by the government rather than underwritten by an insurer, and used by the significant majority of trusts in our own client base.
Cyber cover was added to the arrangement following a pilot, but unlike the arrangement’s more general property and liability sections, cyber cover carries specific conditions attached.
If a trust cannot evidence that those conditions were in place at the time of an incident, the cyber element of its cover will not respond, regardless of how the rest of its RPA membership is standing.
What are the four conditions for RPA cyber cover?
Offline backups
At least one backup held genuinely offline, disconnected from the live network other than when a backup is actively running, so that an attack on the live environment cannot reach it.
NCSC Cyber Security Training
Completed annually by every employee and governor with access to the trust’s IT systems, not only IT staff, with evidence of completion retained.
Police CyberAlarm registration
Registration is the requirement itself, not installation of the monitoring software, though installing it is worth doing for the vulnerability reporting it provides.
A documented cyber response plan
Covering roles, escalation and who does what in the first hours of an incident, reviewed regularly rather than written once and filed.
Where does Cyber Essentials fit if it is not one of the four conditions?
Cyber Essentials is a separate, NCSC-backed certification built around five technical controls:
It is not, on current DfE guidance, a stated condition of RPA cyber cover, and any suggestion that it is should be treated with caution until confirmed against the trust’s own membership terms.
What it does provide is independently reviewed evidence covering much of the same ground as the RPA’s four conditions, since a trust that can pass a Cyber Essentials self-assessment has, in practice, demonstrated the kind of basic control discipline the RPA conditions are trying to establish.
For trusts bidding into DfE-linked procurement or contracts involving pupil data, certification is increasingly expected in its own right, separate from RPA membership altogether.
Is Cyber Essentials Plus worth the additional step?
Cyber Essentials
Self-assessment
A self-assessment questionnaire, reviewed by an accredited certification body but not independently tested. For a trust that has never been tested, this is the sensible starting point.
Cyber Essentials Plus
Independently tested
Adds hands-on technical testing by an assessor, verifying that the controls a trust has described are actually working rather than simply documented.
For a trust preparing for a funding bid, renegotiating insurance, or recovering credibility after a near miss, the independent verification behind Cyber Essentials Plus carries more weight with funders, auditors and insurers than a self-assessment alone.
What should trust boards ask before the next audit or claim?
- Can we produce evidence, not recollection, for each of the four RPA conditions today, with dates attached?
- When were our backups last tested for actual recovery, rather than simply confirmed as having run?
- Do our training records show completion by every governor and member of staff with system access, not only IT staff?
- Are we registered with Police CyberAlarm, and does someone specific own that registration and any resulting alerts?
- Would our current controls pass a Cyber Essentials self-assessment if we were asked to sit one today?
None of these questions require a major project to answer well. They require someone to have looked recently, and to be able to show what they found.
A documented answer, not an assumed one
A short RPA compliance review, run alongside a Cyber Essentials readiness check, gives trustees a documented answer rather than an assumed one, and is a natural next step for any trust that has not looked at this formally in the past year.
Ask about an RPA compliance review