Bursar guide

How much should your school spend on cybersecurity?

Per-device benchmarks, total-cost models, and where AI-native security cuts the bill.

Industry benchmarks

Recent surveys put cybersecurity spend at 3-7% of total IT budget for education. Schools sitting below 3% typically have meaningful gaps; schools above 7% are usually paying for either redundancy or unmanaged tool sprawl. A defensible target for most schools is 4-5%.

Components of a school cybersecurity budget

A complete cybersecurity budget includes:

  • Licences (vendor product fees), usually 50-60% of total
  • Services / management, 25-30%
  • Staff time, 10-15% (existing IT lead time)
  • Training, 3-5%
  • Incident reserve, 5-10%

Missing the last two is a common pattern; both bite when an incident lands.

Where AI-native security saves money

Two main levers:

  • Auto-resolution: Coro's 95% automated handling means staff time on incident triage drops dramatically. For a school with 5,000 events / month, that is the difference between 80 hours and 4 hours of triage.
  • Tool consolidation: replacing 4-5 point products with one AI-native platform typically saves 30-40% of licence spend even before management cost reduction.

Building the case for the bursar

The framing that lands is "cost of prevention vs cost of incident". UK breach response cost has averaged £4,000-15,000 even without ransomware. Ransomware adds zeros. A £6,000 annual cybersecurity budget that prevents one incident over the term has paid for itself many times over.

Frequently asked questions

What % of school budget should go to cybersecurity?

3-7% of IT budget is the benchmark. Most schools should target 4-5%. Below 3% usually means meaningful gaps; above 7% usually means tool sprawl.

How much per device?

£20-60 per device per year, all-in (licences + management + training amortised). Endpoint-only deployments come in lower; full-stack deployments with email and managed response are at the top of the range.

Is there government funding for school cybersecurity?

Programmes vary by region. UK: DfE has periodic cyber-grants and the NCSC Schools cyber programme; NZ: MOE schemes change annually; AU: state-level frameworks. KB confirms current eligibility during scoping.

Want a personalised AI-readiness report?

Three-minute assessment. Your AI-readiness score, gaps, and the AI-native products that close them.