As cybersecurity professionals, we understand that technical tools are vital, yet we also understand that tools alone don’t stop incidents from occurring – People do. The best firewall that money can buy loses its value without a strong human firewall. This makes cybersecurity everyone’s responsibility. Creating a supportive environment where staff feel safe and encouraged to report suspicious behavior is critical to our success. 

I have personally witnessed staff being reluctant to report something suspicious. Sometimes it was because they felt it was insignificant and didn’t want to bother us. Other times they were concerned about getting in trouble. Whatever the reason, that silence creates a gap in our cybersecurity posture that no technical tool can fill. 

Comfort in Reporting

In cybersecurity, the time it takes to respond to an event is the most critical factor. The sooner we are alerted to a potential threat, the more likely we are to contain it and prevent it from spreading. We ask our staff to report things like suspicious emails or when they click something they shouldn’t have. It’s not always that simple, though. The reality is, staff members may feel embarrassed, fear being judged poorly, or worry about potential consequences. To counter this, it is our job to empower staff to speak up, rather than shaming or punishing. This fosters a culture that results in stronger security for the entire organization.

Steps for Changing the CultureMan talking to group

To actively shift the culture toward shared responsibility, consider these key ideas:

  • Show Vulnerability From the Top: Share real-life stories from IT staff and Administration of times they personally nearly fell for a phish, or made a mistake. When leaders admit to moments of imperfection, it shows that it could happen to any of us, and that the important part is how we respond.
  • Encourage open communication: Include regular reminders in meeting agendas and district newsletters to promote a “See something, say something” mindset. Publicly recognize and thank staff members who demonstrate this behavior. 
  • Reinforce shared responsibility: Dedicate professional development opportunities to train staff on procedures for reporting suspicious activity. Just as important is to explain the “Why” behind these actions. Explain who and what we are trying to protect, and what the bad actors can accomplish when there are holes in our defenses. 

Cyber-Strong Schools Are Built On Trust

Beyond technical tools, the strongest defense a district can build is a culture of trust to support our cybersecurity programs. When staff feel safe and empowered to report mistakes or suspicious activity, they become active partners in securing the organization. Tools matter, but people matter more. 

AUTHOR: Tony Dotts, CISSP, CvCISO, CETL, CCRE
Director of Technology Services, Barrington 220 School District (IL)
CoSN Cybersecurity Committee member

tonydotts Tony Dotts brings more than 25 years of dedicated experience to K-12 educational technology. A deeply committed leader within the CoSN community, he serves as co-chair of the CIRCUITS Advisory and contributes as a member of the Cybersecurity Advisory and Student Data Privacy Committees.

With a strong specialization in K-12 information security and technology leadership, Tony holds several premier industry credentials, including the CISSP, vCISO, CCRE, and CoSN’s prestigious Certified Education Technology Leader (CETL) designation. He is dedicated to safeguarding student data and building resilient, secure learning environments that empower both educators and students.

Published on Aug 12 , 2026

CoSN is vendor neutral and does not endorse products or services. Any mention of a specific solution is for contextual purposes.