How Police Leaders Can Prepare for a Cyberattack

Alabama’s Grid Down exercise serves as a model for testing how leadership handles the total loss of login services and critical databases. In the current landscape of municipal operations, law enforcement agencies are increasingly targeted by sophisticated ransomware groups and state-sponsored actors seeking to paralyze public safety infrastructure. A cyberattack is no longer a localized IT failure; it is a major operational emergency that requires the same level of command-level attention as a natural disaster or a civil disturbance. When digital systems fail, the ability to dispatch officers, verify warrants, and manage custody becomes dangerously compromised. Police chiefs and sheriffs must transition from viewing cybersecurity as a technical checkbox to recognizing it as a fundamental component of public safety and organizational resilience. This shift necessitates a proactive approach where the chain of command is deeply involved in technical preparedness, ensuring that the agency can continue to protect the community even when the screens go dark and the data becomes inaccessible.

1. Establish Mission Priorities Before Assessing Technology

The first priority for any law enforcement executive is to define which agency functions are absolutely essential for maintaining public order and ensuring the safety of personnel. This process involves a rigorous analysis of internal workflows, starting with the Computer-Aided Dispatch system and the Records Management System. Leaders must categorize these services based on their criticality, determining how long the agency can operate without them before public safety is significantly threatened. For instance, while administrative payroll systems are important, the inability to access real-time warrant information or officer location data presents an immediate physical risk. By identifying these high-priority assets before an incident occurs, command staff can provide the IT department with a clear roadmap for recovery efforts. This ensures that limited technical resources are focused on the systems that keep officers and citizens safe rather than on less critical business functions during the initial hours of a crisis.

Once the mission-critical systems are identified, the agency must develop and document manual backup procedures for each one. This means having physical paper forms for dispatch, manual logs for evidence intake, and hard-copy rosters for jail management. It is not enough to simply have these forms available; personnel must be trained on how to use them under high-stress conditions. Leadership needs to determine the exact point at which a lack of digital information becomes an unacceptable safety hazard, necessitating a change in patrol tactics or emergency response protocols. For example, if the radio system remains functional but the data terminals are down, a department might require two-officer responses for every call to mitigate the risks associated with incomplete background information. Establishing these operational thresholds in advance prevents hesitant decision-making during the chaos of an actual attack, allowing for a seamless transition to alternative methods of service delivery.

2. Formalize Decision-Making Authority in Writing

During a cyberattack, time is the most valuable commodity, and delays often stem from a lack of clarity regarding who has the authority to make high-stakes technical decisions. Law enforcement leaders should formally document who is empowered to initiate emergency backup protocols or, in extreme cases, authorize the complete shutdown of the department’s network to prevent the further spread of malware. This authority should not rest solely with the IT director, as these decisions have profound operational consequences that fall under the purview of the chief or sheriff. Having a written directive that outlines the hierarchy of decision-making ensures that everyone knows their role when the primary communication channels fail. This document should also include the power to authorize emergency spending, as the immediate procurement of hardware or external forensic services may be required to stabilize the environment and begin the recovery process without waiting for traditional budgetary approvals.

To make this authority effective, leadership must maintain a current, offline list of primary and secondary contacts for every individual involved in the emergency response plan. In the event of a total network lockout, digital directories and email systems will be unavailable, making physical or isolated digital copies of contact information vital. This directory should include not only internal command staff and IT personnel but also external stakeholders such as city or county legal counsel, public information officers, and key vendors. By formalizing these roles and ensuring that contact information is accessible without an internet connection, a department avoids the “paralysis by analysis” that often occurs when subordinates are unsure of their boundaries. This structure provides the necessary support for junior officers and civilian staff to take decisive action, knowing that their moves are backed by pre-authorized command directives designed specifically for these types of digital catastrophes.

3. Construct a Unified Contact and Reporting Directory

Effective response strategies rely on the ability to distinguish between different types of technical failures, as a routine hardware outage requires a different approach than a targeted criminal attack. A unified reporting directory should provide clear definitions for these scenarios, helping staff identify when a situation needs to be escalated to external law enforcement partners like the FBI or state-level cybersecurity offices. This directory serves as a central repository for all communication protocols, ensuring that the right people are notified at the right time. For example, a suspected ransomware incident must trigger an immediate notification to the department’s insurance provider and legal team to satisfy policy requirements and protect the agency from liability. By standardizing these definitions and reporting triggers, police leaders can ensure that their response is proportionate to the threat and that all regulatory and legal obligations are met from the moment the incident is discovered.

Maintaining the accuracy of this contact directory is a continuous task that requires a formal review process every three months. Personnel changes, updated phone numbers, and evolving after-hours procedures for state and federal agencies make an outdated list almost as dangerous as having no list at all. Leadership must assign a specific individual to manage these updates and verify that all internal leads are familiar with the reporting process. This includes establishing relationships with local field offices of the FBI and the Cybersecurity and Infrastructure Security Agency before an attack happens. Knowing exactly who to call and having a pre-existing professional relationship with those experts can significantly speed up the investigative process and improve the chances of recovering stolen data. A well-organized directory serves as the tactical playbook for the communications side of a cyber crisis, allowing the agency to maintain transparency with the public while coordinating a complex multi-agency response.

4. Confirm That Fundamental Security Measures Are Active

While law enforcement leaders do not need to be technical experts, they must be able to verify that the agency’s basic security posture is sound. Utilizing industry-standard frameworks, such as the Center for Internet Security Implementation Group 1, allows chiefs and sheriffs to ask the right questions of their IT staff and vendors. Leadership should demand a complete accounting of every device connected to the department’s network, as unmanaged hardware often provides the easiest point of entry for attackers. Furthermore, it is critical to confirm that every account, from administrative staff to the chief, is protected by more than just a password. Multifactor authentication is no longer an optional security feature; it is a mandatory requirement for modern policing. By verifying these fundamental controls, leaders can significantly reduce the “attack surface” of their organization and ensure that common, automated threats are blocked before they can gain a foothold in the system.

Data integrity and the ability to restore from backups are the ultimate safety nets for any digital operation. Police leaders should regularly verify that their agency’s data restoration plan has been tested and that the backups themselves are protected from being encrypted alongside the primary systems. This means ensuring that a copy of the department’s most critical databases is stored in an “immutable” format or an off-site location that is not directly connected to the main network. Simply having a backup is insufficient if that backup cannot be restored in a timely manner or if it has been corrupted by the same malware that took down the production servers. Command staff should request regular reports on restoration tests, asking for evidence that specific sets of data were successfully recovered within the timeframes established in the mission priority plan. This oversight ensures that the technical team remains focused on the practicalities of recovery rather than just the theoretical existence of a backup system.

5. Restrict Remote Access and Isolate Critical Systems

The separation of business networks from operational technology is a critical security architecture that every law enforcement agency must implement. Systems that control physical infrastructure, such as jail door locks, building security, and digital radio repeaters, should never be on the same network as the public-facing website or the standard office email system. This concept of network segmentation ensures that if an administrative assistant’s computer is compromised by a phishing email, the attacker cannot easily pivot into the systems that control the physical safety of the facility. Leaders must mandate that these safety-critical systems are isolated and that any communication between them and the general business network is strictly monitored and limited. This structural safeguard prevents a digital incident from escalating into a physical security breach, protecting both the inmates and the officers working within the department’s buildings.

Remote access represents one of the most significant vulnerabilities for modern police departments, especially with the rise of mobile data terminals and remote administrative work. Every single remote login, whether it is an officer checking records from a patrol car or a vendor performing maintenance on a server, must require multifactor authentication. Furthermore, law enforcement leaders should establish a policy that no safety-critical equipment can undergo system updates or reconfigurations without a formal operational review and explicit approval from the system owner. This prevents a scenario where a third-party vendor inadvertently introduces a vulnerability or where an attacker uses legitimate administrative tools to sabotage equipment. By maintaining strict control over who can access the network and how they are allowed to change it, the department creates a “defense in depth” strategy that makes it much harder for an adversary to cause widespread damage.

6. Secure Digital Evidence Without Compromising Safety

In the aftermath of a cyberattack, preserving digital evidence is essential for the criminal investigation and the eventual prosecution of the perpetrators. Police leaders must set clear policies regarding the retention of system logs and ensure that all server clocks are synchronized to a reliable time source. Accurate timestamps are the backbone of digital forensics, allowing investigators to reconstruct the sequence of events and identify exactly how the attackers moved through the network. However, the pursuit of digital evidence must never take precedence over the immediate need to protect human life or prevent physical injury. If a system must be wiped and restored to regain control over a critical safety function, leadership must be prepared to make that call, even if it means losing some forensic data. Establishing these priorities in advance allows technical teams to act quickly and decisively when the stakes are at their highest.

Balancing the needs of an FBI investigation with the operational requirements of a local police department requires a nuanced approach to incident response. While the FBI will want to preserve as much of the environment as possible to collect evidence, the chief’s primary responsibility is to return the agency to full service. To bridge this gap, departments should work with their forensic partners to identify “snapshots” of the system that can be taken quickly, allowing the investigation to continue while the recovery process moves forward. Policies should also dictate how long forensic records are kept and who has access to them, ensuring that the department remains compliant with both criminal justice standards and privacy laws. By treating digital evidence as a formal component of the response plan, police leaders can assist in the global fight against cybercrime without sacrificing the safety and stability of their own local operations.

7. Conduct Command-Level Simulations, Not Just IT Drills

True preparedness for a cyberattack comes from realistic simulations that challenge the decision-making capabilities of the department’s top leadership. These drills should not be limited to the IT department; they must involve the chief, the sheriff, and their entire command staff. A high-impact simulation might involve a scenario where the agency loses access to all digital communications, including phones and email, while simultaneously being locked out of the records management and dispatch systems. Under these conditions, leaders are forced to grapple with the reality of operating in a “dark” environment, making difficult choices about resource allocation and public communication without the benefit of real-time data. These exercises reveal the gaps in manual procedures and the weaknesses in the chain of command, providing a safe environment to fail and learn before a real attack occurs.

The value of a simulation is found in the rigorous after-action review that follows the exercise. Leaders must be willing to honestly assess their performance and the performance of their teams, identifying specific areas where the response was slow or disorganized. Every drill should conclude with a clear list of required improvements, ranging from the procurement of better backup hardware to the revision of manual forms. These improvements must be assigned to specific individuals with firm deadlines to ensure that the lessons learned are actually implemented. By making these command-level simulations a recurring part of the agency’s training calendar, police departments build a culture of resilience. Officers and staff become accustomed to the idea that the technology they rely on is fragile, and they develop the mental toughness and procedural knowledge necessary to maintain public safety when the digital tools they use every day are suddenly stripped away.

Strengthening the Resilience Framework

The transition toward a more resilient digital infrastructure was marked by a fundamental change in how law enforcement leadership viewed the intersection of technology and public safety. In previous years, the responsibility for defending against digital threats was often delegated entirely to technical staff, leaving a dangerous gap between operational needs and security measures. However, as the complexity of attacks increased, successful agencies recognized that their survival depended on the active involvement of command-level personnel. These leaders took the initiative to integrate cybersecurity into their broader emergency management strategies, ensuring that the department remained functional even under the most severe technical duress. They moved beyond simple compliance and focused instead on the practical realities of maintaining service in a compromised environment, which ultimately served to protect both their officers and the communities they swore to serve.

By formalizing the chain of command for digital incidents and prioritizing the isolation of critical infrastructure, departments successfully mitigated the risks of large-scale systemic failure. The implementation of rigorous training programs and simulations allowed staff at all levels to become proficient in manual operations, which acted as a vital buffer when automated systems were unavailable. Furthermore, the establishment of strong partnerships with federal and state agencies created a collaborative environment that improved the speed and effectiveness of the recovery process. These actions demonstrated that while technology is an essential tool for modern policing, the core mission of law enforcement remains rooted in leadership, preparation, and the ability to adapt to any challenge. The proactive steps taken by these agencies transformed cybersecurity from a looming threat into a manageable operational risk, ensuring the long-term stability of public safety services in an increasingly digital world.

Advertisement

You Might Also Like

Advertisement
shape

Get our content freshly delivered to your inbox. Subscribe now ->

Receive the latest, most important information on cybersecurity.
shape shape