When your municipality's 911 system goes offline at 5:45 am on a Wednesday, you're not just managing an IT incident, you're managing a public safety crisis. That's what happened to Suisan City, California, on August 7, forcing the city to declare a state of emergency and route emergency calls through county dispatch while federal investigators worked to contain the threat.
This isn't an isolated incident. Coweta, Oklahoma, and Washburn County, Wisconsin, both disclosed ransomware attacks within days of each other in early August 2026. Municipal governments have become reliable targets because attackers know these organizations operate under resource constraints unimaginable to most enterprise security teams.
This checklist provides actionable steps for municipal IT and risk managers to build ransomware resilience within budget and staffing realities. Each item includes specific requirement references and measurable outcomes.
Prerequisites
Before implementing this checklist, ensure you have:
Executive sponsorship: Your city manager or mayor must approve budget allocation for cybersecurity, even if modest. Good looks like: a line item in your annual budget specifically labeled for information security controls.
Current asset inventory: You can't protect what you don't know exists. Good looks like: a documented list of all servers, workstations, network devices, and critical applications, updated within the past 90 days.
Defined critical services: Identify which systems directly support public safety and essential services. Good looks like: a written list ranking services by impact if unavailable (911 dispatch, water treatment, payroll, etc.).
Ransomware Defense Checklist
1. Implement offline, immutable backups of critical systems
Requirement: NIST Cybersecurity Framework PR.IP-4 (Backups of information are conducted, maintained, and tested)
Ransomware works by encrypting your data and holding it hostage. The only reliable defense is having clean copies the attacker can't reach.
Action steps:
- Configure daily backups to storage that is physically or logically disconnected from your network.
- Test restoration quarterly by actually recovering a non-production system from backup.
- Document your backup retention schedule and stick to it.
Good looks like: You can restore your 911 dispatch system from a backup taken yesterday, and that backup is stored on media the ransomware can't encrypt because it's offline or uses immutable storage technology.
2. Segment your network to isolate critical services
Requirement: NIST CSF PR.AC-5 (Network integrity is protected)
When Suisan City's IT network was infected, they had to shut down everything to contain the threat. Proper segmentation limits how far an attacker can move laterally.
Action steps:
- Place 911 dispatch, police/fire CAD systems, and water/utilities SCADA on separate network segments with firewall rules between them.
- Restrict administrative access to critical segments to specific workstations, not the entire network.
- Document which systems can communicate with which other systems, and block everything else by default.
Good looks like: If ransomware infects your administrative workstations, it cannot spread to your 911 dispatch system because firewall rules prevent that traffic path.
3. Disable Remote Desktop Protocol (RDP) or require multi-factor authentication
Requirement: CIS Control 6.3 (Require MFA for Remote Network Access)
Most municipal ransomware attacks begin with compromised RDP credentials. Attackers scan the internet for exposed RDP ports and use stolen or weak passwords to gain access.
Action steps:
- Audit your network for any systems with RDP (port 3389) accessible from the internet.
- Either disable RDP entirely or place it behind a VPN that requires multi-factor authentication.
- If you must expose RDP, implement account lockout policies after five failed login attempts.
Good looks like: An external scan of your network shows no RDP ports accessible from the internet, or RDP access requires both a password and a code from an authentication app.
4. Establish an incident response structure with defined roles
Requirement: NIST CSF RS.RP-1 (Response plan is executed during or after an incident)
Suisan City declared a state of emergency to access resources and support. You need to know who makes that call and what happens next before the incident occurs.
Action steps:
- Designate an incident commander (typically IT director or city manager).
- Pre-identify who contacts law enforcement, who communicates with the public, and who manages technical response.
- Draft a one-page decision tree: "If 911 is affected, we do X. If only administrative systems are affected, we do Y."
- Share this document with your city council and department heads now.
Good looks like: When malware is detected, your IT director knows to immediately call the FBI field office (number already in the plan), your city manager knows to prepare a public statement using pre-approved language, and your police chief knows to activate backup dispatch procedures.
5. Conduct tabletop exercises with public safety stakeholders
Requirement: NIST CSF RS.RP-1 (Response plan is tested)
The most sophisticated technical controls fail if your fire chief doesn't know what to do when dispatch goes offline.
Action steps:
- Schedule a 90-minute tabletop exercise twice per year with IT, police, fire, and city management.
- Use a simple scenario: "It's 6 am. Our network is encrypted. 911 routing is down. What do we do in the first hour?"
- Document gaps identified during the exercise and assign owners to close them.
Good looks like: During your tabletop, your fire chief immediately states, "We route calls through county dispatch," because you've already established that mutual aid agreement and tested it.
6. Apply security patches to internet-facing systems within 30 days
Requirement: CIS Control 7.2 (Perform Automated Vulnerability Scans of Internal Enterprise Assets)
Attackers exploit known vulnerabilities in unpatched systems. You don't need to patch everything instantly, but internet-facing systems (email, websites, VPN) must be current.
Action steps:
- Identify which of your systems are accessible from the internet.
- Subscribe to vendor security bulletins for those systems.
- Create a 30-day patching window for critical and high-severity vulnerabilities on internet-facing assets.
- Document exceptions when a patch breaks functionality, and implement compensating controls.
Good looks like: Your public-facing web server is running software released within the past 30 days, or you have documented why you're running an older version and what additional controls you've implemented to mitigate the risk.
Common Mistakes
Assuming cyber insurance replaces preparation: Insurance may cover ransom payments and recovery costs, but it won't restore your 911 system faster or prevent the attack. Treat insurance as a financial backstop, not a security control.
Relying solely on antivirus software: Modern ransomware often evades signature-based detection. Antivirus is necessary but insufficient. You need the layered controls in this checklist.
Waiting for more budget: Start with what you can do now. Offline backups and network segmentation cost primarily staff time, not capital. Document what you've implemented and what you still need when requesting additional resources.
Skipping the tabletop exercise: You will not think clearly at 5:45 am when your systems are encrypted. The decisions you make in the first hour determine whether you're down for days or weeks.
Next Steps
This week: Complete items 4 and 5. Your incident response structure and tabletop exercise cost nothing but time and immediately improve your readiness.
This month: Audit your backup procedures (item 1) and RDP exposure (item 3). These are the highest-impact technical controls.
This quarter: Work with your network team on segmentation (item 2) and establish a patching cadence (item 6).
Document everything: When you request budget next fiscal year, show your city council this completed checklist and the specific gaps that require funding. "We need $50,000 for immutable backup storage" is more compelling than "We need better cybersecurity."
Municipal governments manage critical infrastructure with enterprise-level threats and small-business budgets. This checklist won't eliminate your risk, but it will make you a harder target than the city down the highway, and in the current threat landscape, that's often enough.





