Public Safety · Cybersecurity

Two ways to reroute 911

A California city declared a state of emergency last month after a cyberattack took down its dispatch systems. We performed the same maneuver for a Georgia county on a planned weekday. The difference between those two days is the whole subject of this article.

Southern Technology Partners September 2026 ~6 minute read

In August, a city of roughly 30,000 people in Northern California shut down its entire network after malware compromised its IT systems. Among the casualties: 911 call routing, police and fire dispatch, and city records. The city council met in special session and declared a state of emergency. City dispatchers began taking calls through the county dispatch center instead.

That last detail is the one we keep thinking about.

Routing a city's 911 traffic to a neighboring dispatch center is a legitimate, well-understood continuity maneuver. We have done it ourselves. When a South Georgia county relocated its E-911 center, the first thing we arranged — before a single cable was unplugged — was for that county's 911 calls to be handled by a neighboring PSAP. Residents dialed 911, reached a live dispatcher, and never knew their own center was in pieces on a truck. The whole move took one day.

Same maneuver. Entirely different day.

One county rerouted its 911 calls on a schedule it chose, with a vendor coordinated, a new facility already cabled, and dispatchers who knew the plan.

One city rerouted its 911 calls early one morning in August, under attack, while declaring a state of emergency.

The technical action is nearly identical. Everything else about those two situations is different — and the difference was decided months earlier, by whether anyone had thought about it.

This is not a big-city problem anymore

The instinct in a small county is to assume attackers are aiming at Atlanta, or at hospital systems, or at somebody with real money. That was roughly true a decade ago. It is not true now.

In the same few weeks as the California incident, reporting documented cyberattacks disrupting local governments in at least four states — including a town of about 12,000 in Oklahoma where ransomware hit every computer and digital service, a city in South Dakota that shut down its networks entirely, and two counties, one of which had phone and fax lines down for an extended period. Over the same stretch, attacks on water and wastewater systems affected at least a dozen states.

Towns of 12,000 are not collateral damage in these campaigns. They are the target profile. They run real infrastructure, hold real data, cannot tolerate downtime, and — critically — are usually defended by nobody.

80%+

of surveyed state and local agencies have fewer than five cybersecurity staff

$872,656

average ransom demand against government targets

$1.53M

average recovery cost, excluding any ransom paid

For a county with an 80-endpoint environment and a general fund that gets argued over line by line in an open meeting, a $1.5 million recovery is not a budget adjustment. It is a catastrophe that takes years to absorb.

How they actually get in

The entry points are disappointingly ordinary. Across analyzed government incidents, roughly a third began with an exploited vulnerability — unpatched software, an out-of-support system, an edge device nobody had updated. Around a quarter began with stolen credentials. Most of the rest came in through malicious email and phishing.

Almost none of that is exotic. There is no zero-day in most of these stories. There is a server that should have been replaced three years ago, a password that worked from anywhere in the world, and an email that looked close enough to real.

Which is the genuinely good news in an otherwise grim subject: the things that stop most of these attacks are unglamorous, well-documented, and affordable compared to the alternative.

The deadline on your calendar right now

If your organization is still running Windows Server 2016, you have a hard date: January 12, 2027. After that, no more security updates unless you are paying for Extended Security Updates through Azure Arc.

That is roughly four months away. For a small government, four months is not a long time — it spans a budget cycle, a procurement process, and a migration that has to happen without taking the tag office offline. Organizations that start this in December will be buying ESU, which is a recurring cost that buys time and nothing else.

Windows Server 2016 · End of support: January 12, 2027

Worth checking at the same time: Windows 10 reached end of support in October 2025. Any workstation still running it has been accumulating unpatched vulnerabilities for nearly a year.

Your insurer has already changed the rules

There is a second forcing function that gets less attention than ransomware itself, and it catches organizations completely off guard: cyber insurance underwriting has tightened significantly.

Insurers in 2026 are asking for multi-factor authentication across all accounts with documented evidence of deployment, managed detection and response with genuine 24/7 coverage rather than an endpoint agent that merely alerts, backups that are isolated, monitored and tested, a written incident response plan with evidence it has been exercised, and centralized logging with defined retention.

The important shift is from self-attestation to verification. Insurers now run outside-in scans and ask for third-party validation. Missing MFA is among the most documented grounds for claim denial, and a mismatch between what a renewal form claims and what is actually deployed can be treated as material misrepresentation.

The failure mode here is specific and worth naming: an organization believes it is insured, has been paying premiums for years, gets hit, files a claim — and discovers that a control it attested to on a form was never fully deployed.

If nobody in your organization can say with certainty what your policy requires and demonstrate that each control is actually in place, you do not yet know whether you are covered.

What to actually do

In rough order of how much risk each removes per dollar spent:

1

Write down what happens to dispatch if your systems go dark

Not a conversation someone remembers having — a written, agreed continuity plan with the neighboring PSAP, and at least one test. The California city's dispatchers ended up at the county center regardless. The only question any agency gets to answer in advance is whether that transition is rehearsed or improvised.

2

Get everything off end-of-support software

Unpatched and out-of-support systems are the single largest entry category. Inventory what you run, find what is past support or approaching it, and build the replacement into the next budget cycle rather than the next emergency.

3

Multi-factor authentication on everything, remote access first

Especially VPN, remote desktop and every administrative account. This is the control most likely to stop an attack outright and the one most likely to void your insurance claim by its absence.

4

Managed EDR across the whole fleet, not part of it

Partial deployment is common and nearly worthless — attackers find the machine without the agent. “Managed” is the operative word: software that generates alerts nobody reads is not a security control.

5

Backups that are isolated, and restores that have been tested

A backup job reporting success is not a tested restore. Ransomware operators specifically target backup infrastructure, so backups reachable from the production network should be assumed compromised in any serious incident.

6

Segment public safety from everything else

There is no reason a compromise in the tag office should be able to reach dispatch. Network segmentation is inexpensive, mostly a matter of configuration, and it turns a countywide outage into a contained one.

7

Reconcile your insurance application against reality

Pull your policy, list every control it requires, and verify each one is deployed and documented. Do this before renewal, not after an incident.

The part worth remembering

Rerouting 911 to a neighboring center is not a failure. It is a sound, sensible continuity measure, and a well-run agency should be able to do it.

The question is never whether your systems can fail. It is whether the day they do is a Tuesday you picked, with a plan, a vendor on site and a tested path back — or an August morning you did not pick, with federal investigators on the way and a council meeting on a Saturday to declare an emergency.

Both of those days involve the same phone call to the county. Only one of them is a story you tell afterward with any satisfaction.

If you're not sure where your agency stands

We work with county and city governments, 911 centers, sheriff's offices, fire and EMS agencies, and school systems across South Georgia. If you want a straight answer about your out-of-support systems, your backup posture, or whether you'd actually clear your insurer's requirements, that's a conversation worth having before you need it.

Talk to us about your agency's setup