Skip to main content
DistrictReady

Free self-assessment

The District Cyber Scorecard

Fifteen plain-language questions about identity, devices, data recovery, training, and governance, drawn from the CIS Controls, the framework Florida's auditors use. Most people finish in about ten minutes.

Your results come back as a scored PDF by email: an overall grade, a bar for each of the five areas, and your top gaps in plain English. No account, no software, no student data.

Answer from memory. An honest estimate is more useful than a perfect one, and "Not sure" is a real answer.

0 of 15 answered

Identity and access

Does every staff account require multi-factor authentication?

Multi-factor authentication (MFA) is a second step at sign-in, such as a code or a prompt on a phone.

Do your administrators do administrative work from a separate account, not the one they read email with?

An administrative account is one that can change settings, add users, or reset passwords across a system.

When someone leaves the district, are all of their accounts turned off within a set number of days, every time?

This is offboarding: closing every account tied to a person, including email, the student information system, and remote access.

Devices

Do you have a current list of the computers, servers, and other devices on your network?

A spreadsheet counts, as long as someone owns it and it is kept up to date.

Are security updates applied to district computers and servers within a stated window, such as 30 days?

Applying these updates is often called patching.

Is endpoint protection running on every district computer and server?

Endpoint protection is software that watches a device for malicious activity. It is sold as antivirus or as EDR (endpoint detection and response).

Data recovery

Are the systems the district could not run without backed up on a regular schedule?

Think of the student information system, finance, email, and file storage, including anything a vendor hosts for you.

Have you restored real files or a real system from backup in the last six months?

A restore test is the only way to know a backup can actually be used.

Is at least one copy of your backups kept separate from the network it protects?

Separate means offline, in a different account, or held by a provider, so that a problem on the network cannot change or delete the backup.

Training

Has every staff member with a district account completed security awareness training, including phishing, in the last 12 months?

Phishing is a fake message that tries to get someone to give up a password or click a harmful link.

Do staff know exactly how to report a suspicious email, and does that route reach someone who acts on it?

One button or one address is enough, as long as people know it and someone watches it.

Do new hires get your security expectations in writing when they receive their district account?

Acceptable use, password and sign-in rules, and how to report a problem are enough to start.

Governance

Is one named person responsible for cybersecurity at the district, with that duty written into their role?

It does not have to be a full-time security job, but it should be a person, not a department.

Do you have a written contact list for a security incident that you could reach without the district network?

This is the first page of an incident response plan: who to call and in what order, including leadership, your insurer, and any outside help.

Do you have a current list of the vendors and apps that hold or handle district data?

This includes the student information system, learning apps, transportation and food service software, and anything staff signed up for on their own.

Where should we send your Scorecard?

Add your details and we will email you the scored PDF.

An estimate is fine.

We use this only to send your Scorecard and follow up. No student data, ever.