By Angelis Pseftis
A cyberattack does not have to knock out 911 to put officers and the public at risk. Phones and radios may still work while computer-aided dispatch (CAD), records, warrant checks, jail systems or digital evidence disappear. At that point, the question for command staff is no longer, “Is this really a cyber incident?” It is, “What must keep working right now, and who has the authority to make that happen?”
That is why a serious network disruption belongs in the incident command conversation from the first hour. The chief or sheriff may have to activate manual procedures, move personnel, isolate systems, preserve evidence, request help and brief the public before anyone can say whether the cause is ransomware, equipment failure or a vendor outage.
The central mistake is treating the event only as an information technology (IT) recovery job. For a police agency, it is also a problem of keeping essential services running, preserving evidence, supporting a criminal investigation and maintaining public trust.
The radio can work while the rest of policing goes dark
The FBI received more than 3,600 ransomware complaints in 2025 and identified government facilities among the sectors most affected by the 10 most frequently reported types of ransomware. Those figures are reports, not a census. The FBI also cautions that its loss total generally excludes downtime, lost files and equipment, recovery work by outside vendors and incidents reported only to field offices. For police leaders, those uncounted operational costs are often the part that matters most.
Curry County, Oregon, shows the difference. An official account from the Cybersecurity and Infrastructure Security Agency (CISA) says that during the county’s 2023 ransomware attack, the 911 center could still take calls and communicate by radio, but CAD, warrant and license-plate queries, jail records, juvenile records and parole and probation records were unavailable. Officers could not book people into the county jail. The public could still call for help; much of the machinery behind the response had stopped.
Scale does not remove the problem. During Dallas’ 2023 ransomware response, 911 and 311 call takers used practiced backup procedures and radio dispatch while the city checked about 1,900 police and fire mobile devices linked to the dispatch system before returning them to service. The city’s official updates show public safety, court and other city services coming back in phases rather than all at once.
These incidents had different causes, systems and recovery paths. They should not be collapsed into a single story. They do reveal the same command reality: a department can keep answering calls while losing speed, visibility and confidence across the rest of the operation.
Titles vary by jurisdiction, but every agency needs the same functions represented: law enforcement command, technology staff, emergency management, a fusion center or other intelligence channel, the FBI field office, CISA regional staff and owners of affected infrastructure.
Before an incident, know who can decide, who can assist and who can restore service.
A police agency may be the victim and the investigator
A police department can be the victim of an attack, the custodian of evidence and a participant in the criminal investigation at the same time. Those roles overlap, but their authorities do not. Command sets mission priorities and activates continuity procedures. The designated IT authority isolates or reconnects computer systems. The facility or infrastructure owner approves changes that affect physical processes. Investigators coordinate evidence and investigative decisions with the FBI or other partners as appropriate.
Procurement, public information and restoration decisions may belong to other officials. Put those authorities and responsibilities on one page. A system owner should not restore a service merely because it boots, and an incident commander should not be asked to approve technical changes outside the commander’s authority.
Public-safety leaders do not need to configure firewalls or industrial control equipment. They do need to own the command decisions that determine which services must remain available; when to activate manual or reduced operations; who may isolate systems; how life safety and evidence will be protected; who will speak publicly; and what checks are required before restoration.
Consider a suspected cyber intrusion discovered while CAD is unavailable and a jail door-control system is still operating but cannot be independently verified. Technology staff can describe the condition. Command must decide whether to move dispatch to paper, add personnel, restrict movement, preserve digital evidence, notify partners and delay restoration until both technical and operational checks are complete. That is an incident-command decision, not a help-desk ticket.
If these answers live only in someone’s phone or in a vendor contract, the agency will lose time debating authority while conditions change. Write them into the continuity and cyber response plans, then exercise them.
Treat information systems and physical controls differently
Information technology (IT) and operational technology (OT) can fail together, but they cannot always be handled the same way. The National Institute of Standards and Technology (NIST) describes operational technology as the systems that monitor or control physical equipment and processes, including industrial controls, building automation, transportation and physical access systems. For those systems, keeping a physical process safe and running can matter more than quickly updating or rebuilding a computer.
An IT team may isolate or rebuild a compromised server with limited physical consequence. Applying the same response to a water-control network, jail door-control system, generator controller or building-safety system could interrupt a real-world process. Changes to operational technology require the system owner’s approval, engineering review, vendor coordination when appropriate, a tested way to reverse the change and confirmation that staff can still operate the system manually.
CISA’s May 2025 guidance highlights three measures for command staff: protect vendor and employee remote access; separate business and operational networks so an intrusion cannot move easily between them; and retain a manual way to operate critical equipment. Each measure requires more than a technical setting. Leaders must decide who has authority, what downtime is acceptable, how safety will be protected and how the agency will operate if automation is unavailable.
Use CIS and MS-ISAC as a starting point, not a substitute
For a chief or sheriff without a large cybersecurity staff, the first problem is often knowing where to begin. The Center for Internet Security (CIS) is a nonprofit organization that publishes practical, prioritized cybersecurity guidance. Its CIS Controls turn the broad instruction to “protect the network” into specific work: know which devices and software the agency uses, control accounts, protect data, keep recoverable backups and prepare for an incident.
Within the CIS Controls, Implementation Group 1 is the starting level. It contains 56 foundational safeguards designed to help organizations with limited cybersecurity resources defend against common attacks. Command staff do not need to administer the safeguards. They should use them to ask the city, county or contracted technology provider three questions: What is complete? What has been tested? What remains open?
The Multi-State Information Sharing and Analysis Center (MS-ISAC) is a CIS program for state, local, tribal and territorial government organizations, including public-safety agencies. It is designed to help members share information about cyber threats and reach outside expertise.
Depending on the agency’s current membership and available services, MS-ISAC can provide government-focused warnings, peer contacts and access to a 24-hour security operations center — a team that analyzes threats and helps members respond. It may also help an agency respond to an incident and analyze what happened, as resources allow. For a small agency, that can mean another source of warning and expertise before or during an incident.
Before relying on that help, confirm what the agency can use, whom to call after hours and what support is included. A membership logo or completed checklist does not prove that protections work, satisfy the FBI’s Criminal Justice Information Services Security Policy or address the safety risks of systems that control physical equipment.
Neither organization takes command. CIS provides a starting checklist; MS-ISAC can advise and assist. The agency still decides which services must stay available, when to shift to manual operations, who may disconnect or restore systems, how evidence will be protected, what the public will be told and what must be verified before service returns. Put those decisions, names and backup procedures in the agency’s own continuity and incident-response plans, then exercise them.
Seven decisions every chief and sheriff should make now
1. Define the mission before inventorying the technology. Identify which services must continue without interruption and which must return within four, 12 or 24 hours. Include CAD, records management, jail management and evidence systems, account and login services, systems that support radio operations, fuel access, backup power, building controls and outside utilities or vendors. Document the manual alternative and the point at which reduced operations become unsafe.
2. Put authority in writing. Name who may activate continuity procedures, disconnect or reconnect computer systems, approve changes to operational or facility systems, authorize emergency spending, release public information and approve a system’s return to service when some risk remains. These may be different people. Record primary and alternate contacts and give command staff an offline copy.
3. Build one contact and reporting list. Distinguish among a service outage, a suspected cyber incident and a suspected cybercrime. List internal contacts, the official responsible for the system, insurer, state cyber office, MS-ISAC or another cyber-support contact, fusion center, FBI field office, CISA and any required regulator. The FBI can support the criminal investigation; CISA can help the agency assess affected systems, contain damage and plan recovery. Confirm contacts and after-hours procedures every quarter.
4. Verify that basic protections are in place. Use CIS Implementation Group 1 as the starting checklist for business systems, then add applicable FBI criminal-justice information requirements and federal guidance for emergency services and operational technology. Confirm results that command staff can verify: devices accounted for; accounts protected by more than a password; administrator accounts reviewed; services that should not be public removed from the internet; successful restores from protected backups; and response procedures exercised.
5. Control remote access and separate business from operational systems. Require IT staff and system owners to remove unnecessary internet exposure, protect remote access with multifactor authentication (more than a password), eliminate unused and shared accounts, keep business and operational networks separate and document the connections allowed between them. Never permit security testing, software updates or reconfiguration of safety-critical systems without the owner’s approval and a safety and operational review.
6. Preserve evidence without delaying safety. Decide how long system activity records are kept, ensure system clocks agree and establish contact procedures and evidence-handling responsibilities before an incident. Preserve short-lived digital evidence, such as active network connections and computer memory, when feasible, but do not let pursuit of a perfect digital evidence record delay an action required to protect life or prevent physical harm. Record who made each important decision, when and why.
7. Exercise command failure, not just technology failure. Take away account and login services, phones, vendor remote access, a critical database and one operational system. Make leaders choose among evidence preservation, service availability and life safety. Alabama’s “Grid Down” exercise is one state example. End with named owners, funded corrective actions and deadlines.
Make the decisions before the alert
Cyber readiness is not a promise that every system will stay online. It is the ability to keep serving the public when some systems do not.
CIS controls can give an agency a starting checklist. MS-ISAC may add threat warnings and outside response help. Neither decides when deputies switch to paper, how a jail operates when electronic controls cannot be trusted or what checks are required before a system returns to service. Those decisions remain with the people accountable for the mission.
At the next command-staff meeting, ask who can take CAD offline, who can activate manual operations and what must be verified before service returns. If the answer depends on who happens to answer at 2 a.m., the agency is not ready. Fix that before the next alert.
References
- Federal Bureau of Investigation, Internet Crime Complaint Center. 2025 IC3 annual report.
- Cybersecurity and Infrastructure Security Agency. Fall 2023 Joint SAFECOM-NCSWIC bi-annual meeting executive summary: Royal ransomware cyberattack in Curry County, Oregon.
- City of Dallas. City of Dallas statement on network outage and incident updates. Published May 2023.
- Alabama Office of Information Technology, Alabama Emergency Management Agency. OIT Access newsletter, quarter 4, 2025. Page 4.
- Cybersecurity and Infrastructure Security Agency. #StopRansomware guide. Published October 19, 2023.
- National Institute of Standards and Technology. Guide to operational technology (OT) security. NIST Special Publication 800-82, Revision 3. Published September 2023.
- Cybersecurity and Infrastructure Security Agency. Primary mitigations to reduce cyber threats to operational technology. Published May 6, 2025.
- Cybersecurity and Infrastructure Security Agency. Cross-sector cybersecurity performance goals.
- Cybersecurity and Infrastructure Security Agency. Emergency Services Sector cybersecurity framework implementation guidance.
- Center for Internet Security. CIS Critical Security Controls Implementation Group 1.
- Center for Internet Security. MS-ISAC services.
- Center for Internet Security. About us.
- Federal Bureau of Investigation. Criminal Justice Information Services Security Policy.
About the author
Angelis Pseftis is a Senior Security Architect and Principal Systems Engineer at George Mason University. His work spans critical infrastructure, operational technology, cloud infrastructure, resilient positioning, navigation and timing, and national-security systems.He is a retired U.S. Army Sgt. 1st Class and holds CISSP, OSCP, CEH, CompTIA A+, Network+, Security+, CIOS and CSIS credentials.He writes about cyber resilience, system assurance and risk-informed architecture for leaders responsible for mission-essential systems and services.