The cyberattack that forced Suisun City, California, to shut down its entire computer network and declare a state of emergency demonstrates how cybersecurity failures in local government can quickly move beyond ordinary IT disruption and begin affecting essential public services. Malicious software infected the city's information technology systems early on August 7, disrupting 911 routing, police and fire dispatch, records systems and other municipal services. Suisun City responded by shutting down its network, activating its emergency operations center and shifting emergency call handling through the Solano County dispatch center so police and fire departments could continue responding. The incident shows why municipal cybersecurity must increasingly be considered part of emergency preparedness: when the affected systems coordinate public safety, a cyber incident is no longer merely a problem for the IT department. 

The decision to take the entire city network offline was operationally disruptive but potentially necessary. Once malicious software is discovered inside an environment and investigators do not yet understand how broadly it has spread, keeping systems online can provide attackers with additional opportunities to move laterally, steal information or destroy evidence. Network isolation can interrupt legitimate services, but it also limits attacker communication and preserves forensic information needed to determine how the intrusion occurred. For a municipality, this creates a difficult trade-off because the same infrastructure that must be isolated may support dispatch, records, permitting, payments, employee communications and other services residents expect to remain continuously available.

Public safety communications are particularly sensitive because delays can have immediate physical consequences. Modern 911 environments depend on interconnected systems for call routing, computer-aided dispatch, police and fire records, location information and communication between dispatchers and first responders. A cyberattack affecting even one component can force operators to use alternate procedures, slower manual workflows or support from neighboring jurisdictions. Suisun City's ability to redirect dispatch operations through Solano County illustrates why regional contingency arrangements should exist before an emergency rather than being negotiated while systems are already unavailable.

The incident also demonstrates the importance of operational redundancy outside the compromised technology environment. Cyber resilience should not mean merely having backups of servers. Municipalities need alternative methods for receiving emergency calls, dispatching responders, communicating with staff and maintaining critical records when the primary network is unavailable. These procedures should be tested periodically because a plan that exists only in an emergency binder may prove unusable when employees actually need to operate without normal applications, email, network drives or authentication systems.

The declaration of a state of emergency is significant because cyber incidents increasingly require many of the same coordination mechanisms used for natural disasters and other emergencies. Such declarations can accelerate procurement, bring in external technical resources, support coordination with state and federal agencies and allow governments to recover eligible response and restoration costs. Cyber recovery can involve forensic specialists, new hardware, emergency communications systems, legal counsel, notification services and extensive overtime, expenses that can quickly exceed the normal technology budget of a small or medium-sized city.

Suisun City's response also shows why municipal governments need established relationships with federal and state cybersecurity organizations before an incident occurs. The city is working with the FBI, Department of Homeland Security and California Office of Emergency Services during the investigation and restoration process. Having predetermined escalation procedures, points of contact and evidence-preservation protocols can reduce delays during the first hours of an attack, when technical decisions may influence both operational recovery and the ability of law enforcement to investigate the attackers.

The city has described the incident as malicious software but has not publicly identified the malware family, initial access method or responsible threat actor. There is currently no basis for assuming that the incident was ransomware simply because other municipalities have experienced ransomware attacks. Attackers can disrupt municipal networks through ransomware, destructive malware, compromised administrative tools or other forms of intrusion, and attribution should follow forensic evidence rather than the tendency to apply the most familiar label to every government outage.

Investigators will need to determine how the attackers gained their initial foothold. Local governments face the same common attack paths as commercial organizations, including phishing, stolen credentials, vulnerable internet-facing services, remote-access infrastructure and compromised third parties. Municipal environments can be especially challenging because they frequently contain a mixture of modern cloud services, older line-of-business applications and specialized public-safety systems that have been accumulated over many years. One forgotten remote-access service or unsupported server can undermine security investments elsewhere in the network.

Identity security should therefore form a central part of municipal cybersecurity. Administrative, remote-access and public-safety accounts should use strong multi-factor authentication, preferably phishing-resistant authentication for high-privilege users. Privileged administrators should maintain separate accounts for ordinary email and administrative tasks so compromising a browser session or mailbox does not automatically provide system-management authority. Service accounts should use narrowly scoped permissions and managed credentials rather than permanent passwords reused across numerous systems.

Network segmentation becomes equally important because a city network supports departments with very different risk and availability requirements. Ordinary administrative workstations should not share unrestricted connectivity with police systems, fire dispatch, financial applications and critical infrastructure. Segmentation can prevent an attacker who compromises an employee through phishing from moving directly into public-safety systems and can allow one portion of the network to be isolated without shutting down every municipal service simultaneously.

Public-safety environments deserve especially strong boundaries. Computer-aided dispatch, police records and emergency communications should operate within restricted security zones with carefully controlled access from administrative networks. Integration may still be necessary, but those connections should pass through monitored gateways rather than broad network trust. If a finance workstation becomes infected with malware, it should not be capable of communicating directly with a 911 dispatch server merely because both machines belong to the same city.

Municipalities should also examine outbound network access. Servers and specialized public-safety systems generally require communication with a relatively limited set of services, yet many environments allow unrestricted internet connectivity by default. Malware relies heavily on outbound communication to receive commands, download additional tools and exfiltrate information. Restricting egress according to business need can therefore disrupt an intrusion even when attackers successfully gain initial execution.

Endpoint monitoring is essential but should extend beyond traditional antivirus. Modern attackers frequently use PowerShell, remote-management applications, scripting tools and legitimate administrative utilities rather than dropping malware that conventional signature scanning easily recognizes. Security teams need visibility into unusual process execution, privilege escalation, remote access and credential activity. For municipalities with limited internal security resources, managed detection and response services can provide continuous monitoring that a small local IT team may be unable to maintain independently.

Centralized logging is particularly important during incidents like the Suisun City attack. Authentication events, endpoint telemetry, firewall activity, VPN connections and administrative changes should be forwarded to systems separate from the normal production environment. Attackers with administrator access may delete or alter logs stored locally, while centrally collected records can provide investigators with a more reliable timeline. Log retention should also be long enough to support retrospective analysis because attackers may be present for days or weeks before obvious disruption occurs.

Backups remain one of the most important recovery controls, but they need to be designed specifically to survive hostile activity. An attacker who obtains administrative access may deliberately delete or encrypt backups before disrupting production systems. Municipalities should therefore maintain offline or immutable recovery copies protected by credentials separate from normal domain administration. Restoration procedures should be tested periodically so administrators know how long it actually takes to rebuild dispatch, records and administrative services from clean infrastructure.

Recovery should also distinguish between restoring availability and restoring trust. Bringing a server back online quickly is useful only if investigators are confident the attacker no longer controls it. Systems rebuilt from compromised backups or restored while stolen credentials remain active can be reinfected immediately. High-value infrastructure may need to be rebuilt from known-clean images, while passwords, tokens and service credentials should be rotated after malicious persistence has been removed.

Data theft must also be investigated even when service disruption is the most visible impact. Municipal systems may contain employee records, law-enforcement information, resident contact information, financial records, utility accounts and documents submitted through permitting or licensing processes. Attackers increasingly steal information before triggering disruption because the data can later be used for extortion or sold independently. The absence of a public statement about stolen information should therefore be understood as an unanswered investigative question rather than confirmation that confidentiality was unaffected.

If personal information was accessed, residents may face follow-on phishing and impersonation attacks. Criminals possessing genuine municipal information can create messages appearing to concern taxes, permits, utility bills, court matters or city services. Residents should be cautious about unexpected payment requests or messages asking them to verify credentials, especially after public disclosure of a government cyber incident. Municipalities should communicate clearly about which channels residents can trust during recovery so attackers cannot easily exploit service disruptions with fake replacement portals.

The incident also exposes the operational challenges faced by smaller municipal governments. Cities do not always have the budgets or security teams available to major corporations, yet they must maintain services with significant public-safety and privacy consequences. Attackers understand this imbalance. A city network may contain decades of technology, limited redundancy and a small IT staff responsible for everything from desktop support to cybersecurity, making municipalities attractive targets even when attackers are not pursuing sophisticated national-security objectives.

Regional cooperation can partially address this problem. Cities and counties can establish mutual assistance arrangements for emergency dispatch, cybersecurity expertise and recovery infrastructure just as they do for fires, floods and other disasters. Suisun City's use of Solano County dispatch demonstrates how shared capacity can maintain essential services during a local technology failure. Similar arrangements can be developed for secure communications, forensic assistance and temporary infrastructure.

Cybersecurity exercises should include operational personnel rather than only IT staff. Dispatch supervisors, police leadership, fire departments, finance teams and city administrators need to understand how their functions will operate when digital systems fail. Exercises should assume that email, shared drives and normal phone systems may all be unavailable simultaneously, because relying on one compromised network to coordinate recovery from the compromise is a poor emergency design.

Cities should maintain independent emergency communication methods, printed contact lists and documented manual procedures. Critical telephone numbers and recovery instructions should not exist only inside systems that may become inaccessible during an attack. Administrators should also ensure that credentials and encryption keys required for recovery are stored securely but remain available during network outages.

Third-party vendors deserve close scrutiny because municipal environments depend heavily on external providers for specialized applications, public-safety technology, financial systems and remote support. Vendor access should be limited to the systems required, monitored continuously and disabled when no longer necessary. Permanent remote-support accounts with broad network permissions create convenient maintenance pathways but can become equally convenient attack pathways when vendor credentials are stolen.

Incident response plans should identify who has authority to disconnect systems, declare an emergency and engage external specialists. Delays caused by uncertainty over procurement or decision-making can give attackers additional time inside the environment. The Suisun City Council's emergency declaration helps remove some administrative barriers to response, but ideally technical response authority should already be documented before the city reaches the stage of formally declaring an emergency.

The incident follows other serious cyberattacks against Bay Area municipalities during 2026, reinforcing that attacks on local governments are not isolated anomalies. Earlier incidents affected Foster City and Pittsburg, with Foster City experiencing ransomware-related service disruption and Pittsburg losing nearly $1 million through a phishing-related fraud before recovering more than half of the funds. The techniques and impacts differ, but all demonstrate how cyber incidents can create direct financial and operational consequences for local government.

These cases should encourage municipalities to think in terms of resilience rather than attempting to predict one specific attack technique. A city may be hit by ransomware, phishing, business email compromise or exploitation of an internet-facing vulnerability. The precise initial attack will change, but the controls limiting damage remain familiar: strong identity security, network segmentation, rapid detection, secure backups and rehearsed continuity procedures.

Public transparency is also important during municipal cyber incidents. Residents need to know whether emergency services remain available, which online services are unavailable and what alternatives they should use. Suisun City appropriately emphasized that police and fire services continued operating despite the IT shutdown. Clear communication can prevent unnecessary panic while allowing officials to avoid releasing technical details that could interfere with the investigation.

The city will eventually need to explain more about the scope of compromise once forensic work permits it. Residents and employees will reasonably want to know whether personal information was accessed, which systems were affected and what measures are being implemented to prevent recurrence. Meaningful post-incident disclosure should address those questions rather than stopping at the statement that systems have been restored.

The broader cybersecurity lesson is that a city computer network has effectively become part of civic infrastructure. Residents may think of 911 dispatch, police response and city services as physical government functions, but increasingly they depend on software, databases and network connectivity. When those systems fail, cybersecurity becomes visible in the form of delayed services and emergency workarounds.

Local governments should therefore treat cyber resilience with the same seriousness applied to continuity planning for earthquakes, storms, fires and power failures. The objective is not merely preventing malware from reaching a Windows server. It is ensuring that emergency services, government operations and public communications continue functioning when prevention eventually fails.

Suisun City's decision to shut down its network, preserve evidence, activate emergency operations and rely on regional dispatch support shows how containment and continuity can operate together. The effectiveness of the response will ultimately depend on whether investigators can identify the entry point, remove persistence and restore systems without allowing the attacker back into the environment.

For other municipalities, the most useful lesson is to ask how essential services would function if the city network had to be disconnected immediately. If the answer depends on systems connected to that same network, the continuity plan contains a weakness that should be corrected before an attacker discovers it.

Cybersecurity for local government is ultimately about keeping public services trustworthy and available. Once a cyberattack can interfere with 911 routing and emergency dispatch, patching servers and resetting passwords remain important, but the real security objective is considerably larger: ensuring that residents can still receive help when they call for it.


The North Bay city says a “malicious software” infected its systems on Friday morning, impacting public safety and other city services.

Source: Suisun City Declares State of Emergency After Cyberattack | KQED via kqed.org.