ACRE

An A–F security report card for your institution

“How secure are we?” answered as a grade — not a 400-page report.

ACRE is the institutional security posture answer Boards, CISOs, and engineers can use at the same time. Executive leadership gets a headline grade, narrative, and peer comparison on one page. Engineers see the same finding with asset-level evidence and remediation guidance underneath. No translation layer, no “exec deck vs. technical report” gap where context gets lost.

Generic enterprise attack-surface tools treat every research subdomain as an “exposed asset” because they don't understand higher-ed. ACRE is calibrated for the campus city — your research subdomains, your federated identity surfaces, your decentralized DNS. The scoring rubric is built for institutions, not corporations.

What ACRE evaluates (from outside the walls)

Two views, one source of truth

Executive view

A–F headline grade, narrative summary, top findings, peer comparison. One page. Board-ready.

Technical view

Every finding with the asset it applies to, the evidence, the remediation step, and a state machine for tracking resolution.

The higher-ed security landscape today

ACRE currently tracks 5,994 higher-ed institutions across the United States with 4,323 scored. Two views from the live aggregate landscape — no individual institution data shown, drill-down is per engagement.

ACRE grade distribution across 4,323 scored higher-ed institutions: A=0, B=783, C=3,390, D=148, F=2, ungraded=1,671
Grade distribution across scored institutions. The big cluster at C is the opportunity: most institutions are mediocre on observable security signals, and that's where we help move you up the curve.
ACRE top US states by scored institution count: CA 475, NY 319, TX 254, PA 221, FL 201, OH 195, IL 156, NC 140, GA 112, MA 110, VA 110, TN 106
Top states by scored count. Anonymized peer comparison is built in — your institution scores against its actual peers, not Fortune 500 baselines.

Where it fits the service line

Security Assessments runs ACRE as the engine for the quarterly institutional baseline (we add manual depth on top). Compliance Readiness uses ACRE for the attacker-eye component — each district of the campus city evaluated from outside the walls before the auditor or attacker does it first.

Trust signals

Frequently Asked Questions

Is this a pentest?
No — ACRE is observation-only, attacker-eye view. No internal network access, no credentials, no agents.
Can we compare to peer institutions?
Yes — anonymized peer benchmarking is built into the executive view.
How often does it refresh?
Continuously per category, reported quarterly for Board-cycle alignment.
Why an A–F grade?
It's accessible. Boards, faculty, parents, and students all understand letter grades. The per-category subscores give engineers what they need underneath.
What if we disagree with the grade?
Methodology is documented per category — drill into the asset-level evidence and tell us where we're wrong. We'd rather get the rubric right than win the argument.
Can multi-campus systems get rolled-up views?
Yes — the multi-institution view supports state systems and consortia.

Try ACRE

Sign up at acre.synapticcyber.com to run an initial scan and see your institution's grade. Pricing surfaces in the product once you've seen the value.

Try ACRE →