For forty years, I have watched water. As a lifeguard and a lifeguard instructor, I have trained hundreds of people to prevent, recognize, and respond to emergencies in pools, lakes, and rivers. For much of that same time, I have also worked to protect school networks. For years I treated these as two separate lives. 

Then it struck me that they are the same job. Both are ultimately about readiness: preventing what we can, recognizing trouble early, and knowing exactly what to do when something happens.Lifeguard instructors have been teaching cybersecurity principles for decades without even knowing it.

In K-12 education, the people responsible for cybersecurity are often generalists wearing many hats, and many would never call themselves security professionals. Here is the encouraging part: a lifeguard does not need to be a doctor to save a life. Lifeguard instructors take ordinary people, often teenagers, and make them reliably capable in emergencies. It works not because of expertise, but because of structure, habits, and practice. 

  • Those same ideas are at the heart of cybersecurity readiness and are reflected throughout CoSN’s Cybersecurity Rubric.
  • That is exactly what strong school cybersecurity requires, and it is a mindset every technology leader can adopt and share.

guarddata

Prevention Is the Job

Ask any lifeguard and they will tell you the best rescue is the one you never have to make. Good guards spend far more time preventing emergencies than responding to them. They enforce rules consistently, they explain the “why” behind those rules, and they position themselves to stop trouble before it starts.

School cybersecurity works the same way. Multi-factor authentication, locking screens, thinking before clicking, and consistent enforcement are our version of pool rules. None of it requires a security specialist. It requires a culture where the rules are understood and followed, every time, by everyone in the building.

In the CCRE framework, this is the work of building protection into everyday practice, supported by governance that makes expectations clear, consistent, and understood across the organization.

Trouble Is Quiet

The most dangerous misconception about drowning is that it looks like the movies. It doesn’t. There is no thrashing, no shout. Real drowning is quiet, and lifeguards train until recognizing it becomes automatic. Cyber trouble works the same way. It rarely arrives as a siren. It arrives as an email from a colleague that feels slightly off, a login at an odd hour, an invoice that is not quite right.

Lifeguards don’t learn the signs of distress by reading about them once. They study them, see them demonstrated, and practice spotting them until it takes no thought. Schools can do the same. Regular, low-stakes phishing exercises and simple reporting habits teach staff to notice the suspicious message before it becomes an incident. The point is not to catch people. The point is to train the eye.

In CCRE terms, this is what readiness in Detect begins to look like: people and systems prepared to recognize that something is wrong before the problem becomes a crisis. 

Everyone Should Know the Emergency Action Plan

In lifeguarding, you don’t wait until someone is drowning to figure out what to do. You have a written Emergency Action Plan (EAP) that documents who blows the whistle, who clears the pool, who calls 911, and who performs the rescue. Roles are assigned before the season begins, and the team practices until response is second nature. When the whistle blows, no one is inventing a plan. They are executing one. Cybersecurity incident response is exactly the same idea. You shouldn’t be figuring out who to call, how to contain the breach, or who notifies management while you are under attack.

Most schools have detailed plans for fire and lockdown, but far fewer have a practiced plan for a ransomware attack or a data breach. That gap is fixable, and it is less work than people fear. A one-page incident response plan with named roles, a simple activation process, and the first few steps for each scenario, practiced once a semester, will serve a district better than a hundred-page binder no one has opened.

A concise, actionable incident response plan with clearly defined roles, an activation process, and practiced first steps can be far more valuable in an emergency than an extensive plan that has never been exercised.

This is the heart of readiness in Respond: defined roles, practiced procedures, clear communication, and the ability to act without inventing the plan in the middle of an incident. 

Vigilance Is a Habit, Not a Talent

Perhaps the most reassuring lesson from the pool deck is this: vigilance can be taught. Lifeguards are not born watchful. They are trained to scan for trouble, rotate before fatigue sets in, and share the watch. Schools can build the same habits, making every adult in the building part of the defense. This is also where community helps: the more we share these approaches with one another as technology leaders, the stronger every school system becomes.

That is the larger goal of cybersecurity readiness: not simply completing cybersecurity activities, but building an organizational capability that becomes stronger through practice, assessment, and continuous improvement.

If you want a place to start, CoSN’s Cybersecurity Rubric provides a structured way to assess where you are today, identify gaps, and determine where greater readiness is needed. Like a facility safety inspection, it helps us see what is working, what needs attention, and where to focus next.

The best rescue is the one you never have to make. But when prevention is not enough, readiness determines what happens next.

lifeguardquote

If the whistle blew today, would your organization be ready?

randall AUTHOR: Randall Palmer, EdS, CISSP, CCRE
Information Technology Coordinator at Spectrum360, a nonprofit approved private school for students with disabilities in New Jersey.

As an American Red Cross Lifeguarding Instructor, Randall has trained hundreds of lifeguards over four decades and brings those same principles of prevention, recognition, and response to protecting K-12 learning environments. Randall will present “From the Pool Deck to the Server Room: Lifeguarding Lessons That Strengthen K-12 Cybersecurity” and “Security by Habit: Cultivating Cybersecurity Culture in Schools” at the Future of Educational Technology Conference (FETC) on January 26-27, 2027, at the Orange County Convention Center in Orlando, FL.

Published on: October 8, 2026

CoSN is vendor neutral and does not endorse products or services. Any mention of a specific solution is for contextual purposes.