Suisin City, CA hit with cyberattack and declares state of emergency 

Over the weekend, Suisin City, California declared a state of emergency in light of a cyberattack that impacted critical services like 911 routing, police and fire dispatch and more.

After malicious software infected systems, the city shut down its entire IT network to contain the threat and preserve evidence.

More info is available here: https://www.suisun.com/Community/20260807Cybersecurity-Incident-Updates

Arvind Parthasarathi, CEO and founder, CYGNVS had this to say:

“What happened in Suisun City shows why cyber recovery is fundamentally an operational resilience issue. Malware affected systems supporting 911 routing, police and fire dispatch, records and other municipal services, forcing the city to shut down its IT network. The fact that dispatchers were able to shift 911 operations to Solano County and keep emergency calls moving is exactly the kind of continuity organizations need to plan for before an incident occurs.

With the city’s systems still offline and every network function needing to be inspected and cleared before restoration, the next challenge is coordinating a safe recovery.

 Organizations should have an out-of-band command center ready to bring together security, IT, legal, risk and compliance teams with external counsel and forensics providers. Those teams need tested playbooks and regular tabletop exercises so that when critical systems go down, they already have the muscle memory to maintain essential operations, investigate the incident, restore systems safely, and manage regulatory and stakeholder reporting.”

This is all good advice that organizations should follow. The question is if organizations will follow it.

UPDATE: Seemant Sehgal, Founder & CEO, BreachLock had this comment:

“Municipal IT and security teams, more often than not, operate under resource constraints that most enterprise security organizations would find genuinely difficult to imagine, and when you see three incidents like this in the same news cycle, it’s clear that attackers have figured that out.

“Suisun City, Coweta, Washburn County — these are not outliers, they are a pattern, and the pattern tells us that local government infrastructure is being treated as a reliable target. The people responding to these incidents are doing exactly what you do when you have limited staffing and a network that cannot go dark for long without causing a real emergency, and the hard reality is that the window between ‘contained’ and ‘encrypted’ is often shorter than any reasonable detection and response process can close.”

Ashley Knowles, Security Consultant for Black Hills Information Security, Inc.:

“City services are always a lucrative target due to attackers’ ability to directly impact critical services, residents, and sensitive data. Government IT departments often operate with constrained budgets while wearing multiple hats, and in the age of AI-assisted attacks, that combination makes municipalities a prime target. That said, it appears the city made the right calls, which underscores exactly why having a business continuity plan and regularly practicing it is so important.

“From here, the focus will likely shift to forensic investigation to identify the root cause and initial access vector, followed by a methodical restoration of systems from known-good backups. The declared State of Emergency positions the city well to access the resources needed for a full recovery while federal partners assist with the investigation.”

John Strand, Owner, Black Hills Information Security, Inc.:

“Once again, I think a lot of these local IT departments for cities and counties are doing the right thing by pulling the plug and shutting things down as quickly as possible before the attack has an opportunity to spread. In the middle of an active attack, sometimes that is absolutely the right move.

“But what I hope is happening with these breaches is that they’re hitting the news enough that they’re starting to reach mainstream consciousness. Municipalities all over the United States need to realize that they have to start being proactive about their security. They can’t just sit back and hope they don’t get hit.

“They need to start having honest conversations about where they actually stand. They need security assessments performed by professionals who can look at the organization as a whole, identify the total security risk, and determine just how exploitable that organization actually is.

“We’re seeing attacks against water systems. We’re seeing attacks against municipalities. And these attacks seem to be kicking up quite a bit.

“I just hope we’re finally reaching critical mass in the mainstream news space where counties and cities start to wise up and move a little bit faster with their computer security programs.

“Because at this point, simply hoping you’re not going to be the next municipality that gets hit is not a security strategy.”

Denis Calderone, CTO, Suzu Labs:

“Suisun City’s network shutdown is disruptive, but the dispatch handoff to Solano County is what a resilient public-safety system is supposed to look like. Whatever technical and operational arrangements were already in place between the two jurisdictions, Suisun City could take its network offline while Solano County continued receiving calls, keeping a cyber incident from becoming a public-safety failure.

 “That outcome did not happen by accident. 911 centers cannot improvise a handoff in the middle of a cyber incident. The specific technical arrangement here has not been publicly disclosed, but the ability to shift operations to a neighboring jurisdiction gave Suisun City room to contain the incident while police and fire continued responding.”

“Municipal leaders should learn from this incident and the others affecting their peers. The immediate priority in an incident like this is to contain it while preserving evidence, then determine how attackers got in, eradicate their access, and recover safely. Make sure your incident-response and business-continuity plans provide for tested backups, manual operating procedures, and workable fallback arrangements while the affected environment is offline. Be diligent about common attack paths: Internet-facing remote access, privileged accounts, gaps in MFA coverage, overdue patches, and vendor connections. Those basic controls matter, but so does gaming out these scenarios with your neighbors.”

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading