Keeping school networks and student data secure can feel like chasing a moving target. Threats change. Technology changes. Expectations change. For school systems, the challenge is not just knowing what cybersecurity practices matter—it is knowing where to focus next.
At the Suring School District in Wisconsin, that question has become part of an ongoing improvement process.
Each summer, Suring School District works with Cooperative Educational Service Agency 8 (CESA 8) in Wisconsin to conduct a focused cybersecurity assessment using the CoSN Cybersecurity Readiness for Education (CCRE) Cybersecurity Rubric, followed by periodic check-ins throughout the school year. The result is not simply a score. It is a set of guardrails for building a cybersecurity strategy.
The rubric provides Suring with a consistent way to measure cybersecurity maturity, identify areas requiring attention, establish annual goals, and demonstrate progress to district leadership. Those findings also help connect cybersecurity priorities to budget decisions—turning what can sometimes feel like an endless list of security needs into an intentional improvement strategy.
When a Gap Becomes an Action
The value of an assessment becomes most visible in what happens next.
Suring has used what it learned through this process to strengthen data privacy safeguards, upgrade critical network infrastructure, and conduct a cybersecurity tabletop simulation involving district administrators.
That tabletop provides a good example of the CCRE coming to life.
Within the CCRE Cybersecurity Rubric, the Respond function includes categories such as Incident Management and Incident Analysis—both of which can come into play during a cybersecurity tabletop exercise. Incident Management focuses on how an organization manages its response once an incident occurs, while Incident Analysis considers questions such as what happened, the scope and magnitude of the incident, and the information needed to support an effective response.
A tabletop exercise moves those concepts from the rubric into practice. It asks a much more important question than Do we have a plan?
Can we actually execute it?
Who makes decisions? What information do we need? Who communicates? How do we determine the scope of the incident? When do we escalate? Where might the process break down?
That is the difference between documenting cybersecurity readiness and building cybersecurity capability.
A Common Language for Improvement
Something else happened along the way.
Suring invited technology leaders from neighboring districts to participate in the summer assessment process. What began as an internal review grew into a regional peer network supported through CESA 8, allowing districts to benchmark alongside one another, exchange practical solutions, and learn from their collective experience.
That highlights another powerful benefit of the CCRE Cybersecurity Rubric: it gives education organizations a common language for cybersecurity readiness.
Districts may have different technologies, staffing levels, budgets, and challenges, but when they use a common framework, conversations become much more actionable. Instead of simply asking, What cybersecurity products are you using?, leaders can talk about capabilities, maturity, gaps, evidence, and progress.
And then they can learn from one another.
Cyber readiness in education isn’t a one-time project—it’s an ongoing discipline. By combining trusted regional partnerships with quantifiable benchmarks, Suring demonstrates how measuring progress can build lasting digital confidence. But the goal is not merely to achieve a higher score. The real value comes from what the assessment helps an organization do next.
A gap becomes a priority. A priority becomes an action. An action becomes measurable progress.
Year after year, the CCRE Cybersecurity Rubric provides the guardrails that help Suring School District, working in partnership with CESA 8, turn cybersecurity assessment into cybersecurity strategy.
Published: Oct 5th, 2026
AUTHOR: Jennifer Ambrosius
Jenny Ambrosius serves as the Director of Technology at Cooperative Educational Service Agency 8 (CESA 8) in Wisconsin. She oversees technology operations and instructional tech services for the organization, serving 27 member school districts in the northeastern part of the state. Drawing on her diverse background as a former elementary teacher, technology integration specialist, SIS administrator, and IT project manager, she drives the implementation of secure, innovative technological solutions to support student learning.
CoSN is vendor neutral and does not endorse products or services. Any mention of a specific solution is for contextual purposes.