Cyber Readiness After Adoption: Protecting the Value of New 9-1-1 Technology
A new 9-1-1 capability becomes dependable when leaders clarify its dependencies, access, reporting paths, escalation steps, degraded operations, and recovery plan before disruption tests them.
Hypothetical operational moment: A 9-1-1 center has gone live with a vendor-supported capability. The launch was successful. Staff are using the system. Then an unexpected issue appears during daily operations.
The issue may not clearly be a cyber incident. It may look like a support problem, a configuration problem, an access problem, or a technology failure. Operations needs to know whether service is affected. IT needs to know what changed. The vendor may need access. Leadership needs to know who can approve action.
No one is trying to avoid responsibility. But the authority is unclear.
That is the problem cyber readiness after adoption has to solve.
The governance work comes down to removing ambiguity before pressure exposes it.
For 9-1-1 leaders, that is the work after a new capability becomes part of the operating environment. The value of the technology depends on whether the organization can protect it, operate it, escalate issues, and recover service when something does not work as expected.
Five Ambiguities Deserve Attention After Adoption
1. What does the new capability depend on?
Leaders need a plain-language dependency map.
That map should show where information is stored, how it moves, what systems the capability connects to, what vendors or third parties support it, and which parts of the environment the agency still controls directly.
This matters because 9-1-1 technology does not operate in isolation. A new capability may depend on network paths, hosted services, vendor tools, user accounts, integrations, and partner systems. If leaders do not understand those dependencies, they may not know where to look when service degrades or a cyber concern appears.
Without that view, delay follows. A center can lose time figuring out whether the problem sits with the agency, a vendor, a network path, a connected system, or a partner process.
CISA's guidance on cyber disruptions in an evolving 911 environment warns that increased interconnection can create new cyber threat paths and points emergency communications centers toward continuity planning with partners.
After go-live, ask the implementation team and vendor to produce a simple dependency view that operations, IT, and leadership can all understand.
2. Who can see, access, or change it?
Leaders need clear access and change authority before an issue occurs.
Leaders should know who can see system information, including the agency, the primary vendor, and any third parties the vendor uses. They should apply the same review to system access. They should also know what vendors can touch or change, when they can change it, what permission they need, and what responsibility the client keeps.
Support or disruption can stall when authority is unclear. If a vendor can make a change but no one knows who approves it, the organization may wait. If the agency assumes the vendor owns a control that the agency retained, the gap may not show up until pressure is high.
This is a cyber issue because access and change authority shape the security of the environment. It is also an operations issue because unclear authority slows decisions.
Put these authorities in writing: who can view, access, change, approve, disable, or restore each important part of the capability. Keep that document usable, not buried in contract language.
3. Who reports, and who acts?
Every role needs to know what to report and where to send it.
Cyber is not just an IT problem. In a 9-1-1 environment, cyber readiness depends on shared awareness and clear handoffs across the whole organization.
Each role still has a different job. Each role can also notice something different. A frontline staff member may see unusual workstation behavior. A supervisor may see a process failure. IT may see an access concern. Leadership may need to decide whether an issue affects continuity or requires vendor escalation.
When staff stay silent or send concerns to the wrong place, the organization can lose early warning time. That is especially true when people are unsure whether to report something or fear blame for a mistake.
CISA's phishing guidance supports a simple baseline: staff should recognize and report suspicious links, attachments, messages, or calls. In 9-1-1, that reporting culture needs to fit the reality of shift work, dispatch pressure, supervision, and urgent operations.
Create a short reporting path for suspicious activity, unusual workstation behavior, mistaken clicks, access concerns, and service-impacting technology issues. Then train staff to use it without blame.
4. What happens if normal operations degrade?
The organization should know how it will operate when the new capability is impaired.
Not every service-impacting issue is a cyber incident. A vendor issue, configuration change, network problem, implementation defect, or broader outage can also degrade operations. The center still needs a plan for who decides, who escalates, and how staff continue service.
If degraded operations have never been practiced, staff may have to learn a backup workflow while they are already dealing with a technology problem.
Practicing the transition before an incident helps staff understand the delay, the friction, and the operational impact. It also makes the backup workflow less unfamiliar if it is ever needed.
NIST SP 800-61r3 supports this broader view of incident response by tying response roles to leadership, technical teams, incident handlers, and third parties.
Run a short degraded-operations exercise after adoption. Include operations, IT, leadership, and vendor escalation. The goal is not a perfect drill. The goal is to find unclear handoffs before they matter.
5. What does recovery actually restore?
Backup existence is not the same as recovery readiness.
A common assumption is that backups are naturally good to go.
A 9-1-1 leader does not need to manage the technical recovery process personally. But leadership should know whether recovery has been tested, what systems matter most, who starts the recovery process, and what operational priority guides the order of restoration.
Backups can create false confidence when they have not been tested against operational need. An organization may believe it can recover because backups exist, only to learn during disruption that the backup is unavailable, incomplete, too old, untested, or not aligned with operational priorities.
CISA's StopRansomware Guide recommends maintaining offline encrypted backups and regularly testing backup availability and integrity in a recovery scenario.
Ask for recovery proof, not just backup confirmation. The useful question is whether the organization has tested availability and integrity in a scenario that reflects what 9-1-1 operations would need restored first.
The Leadership Work is Removing Ambiguity
Cyber readiness after adoption is not a separate technical project that sits outside operations. It is the leadership work of making the new environment understandable and governable.
That work connects naturally to OTM's Protect, Train, Test structure. Protect clarifies what must be visible and controlled. Train prepares people to recognize, report, and respond. Test validates whether assumptions hold before disruption forces the lesson.
The structure should stay grounded in the operating environment. In 9-1-1, a cyber issue is not only a security event. It can become a continuity issue, a staffing issue, a vendor issue, a leadership issue, and a public-trust issue.
This is also where the idea of "risk being underwritten" matters.
Risk underwriting means leaders are accepting responsibility for a certain level of risk, whether or not they have named it clearly. If a 9-1-1 organization adopts a new capability without clarifying dependencies, access, reporting, continuity, and recovery, it may be accepting more risk than leaders realize.
The point is not to slow every modernization effort. The point is to make the risk visible enough to manage.
Connecting the Conversation to NGCS
This article focuses on the cyber readiness side of adoption. The broader 9-1-1 technology conversation continues in the upcoming webinar, "From Adoption to Operational Value: What Next Generation Core Services Can Teach 911."
Caleb Branch will bring perspective from PSAP operations, deployment work, and statewide leadership. His conversation will look more broadly at how 9-1-1 evaluates new capabilities, manages implementation, governs change, and keeps focus on operational value.
Cyber readiness is one part of that larger picture. It is also one of the parts leaders can start clarifying now.
Continue the conversation during this upcoming webinar.
Sources and further reading
CISA, "Considerations for Cyber Disruptions in an Evolving 911 Environment"
Get practical cyber readiness updates
Receive OTM Cyber insights, relevant event invitations, and guidance for leaders who have to keep operations moving.
Continue the conversation.
Explore related services or talk with OTM Cyber about the cybersecurity pressures facing your environment.