Key Takeaways
- A cybersecurity readiness consultant advises that cyber specialists should have defined command roles before municipal incidents occur.
- Water-system attacks and CenterPoint Energy’s breach show how cyber events can cross organizational boundaries.
- Cyber annexes, annual exercises and mutual-aid agreements can help smaller jurisdictions respond with limited staff.
A citywide cyberattack at 2 a.m. is not only an IT problem. If traffic signals stop working, water operators lose pressure data and ransomware disables municipal workstations, the consequences quickly become an emergency-management issue.
A cybersecurity readiness consultant is urging local governments to account for that reality by placing cyber expertise inside the Emergency Operations Center command structure. This argument targets a common organizational gap: the IT director may understand the intrusion, but that person is often outside the formal incident-command process.
That separation can slow decisions about shutting down systems, switching infrastructure to manual control, notifying residents and requesting outside assistance. It also creates a translation problem. Incident commanders think in terms of public safety, operational periods and resource assignments; technical teams focus on containment, evidence preservation and system restoration.
During an active threat, both groups may respond to the same emergency while using different operational playbooks.
Recent attacks illustrate the operational risks of physical equipment manipulation and prolonged service outages. In November 2023, CyberAv3ngers, an Iran-affiliated group, compromised a Unitronics programmable logic controller at the Municipal Water Authority of Aliquippa in Pennsylvania. Operators moved a pressure-regulating pump station to manual control. The Cybersecurity and Infrastructure Security Agency and the FBI subsequently issued advisory AA23-335A.
Threat actors subsequently expanded their targeting to Schneider Electric and Siemens equipment in addition to Rockwell Automation systems. A coordinated incident affected roughly 30 water systems in Minnesota, prompting CISA to issue updated detection guidance under advisory AA26-097A. Smaller utilities are particularly exposed when internet-connected industrial equipment retains weak or default credentials.
CenterPoint Energy’s data breach disclosure adds another dimension. The utility, which serves roughly 7 million customers across Texas, Indiana, Minnesota and Ohio, reported that an unauthorized party accessed customer data through an external-facing system. CenterPoint Energy said electric and gas delivery continued without disruption, so the event was a data breach rather than an operational shutdown. Even so, it demonstrates that substantial security resources do not eliminate exposure.
Investment in public safety operational decision support is driving more integrated command systems. Dataintelo valued the global Emergency Operations Center software market at $1.98 billion in 2024 and forecasts a 10.6% compound annual growth rate, reaching $5.35 billion by 2033. Cloud platforms represent 58.7% of deployments in the related incident-command software segment.
Products from Motorola Solutions, NICE Public Safety and Hexagon Safety & Infrastructure increasingly connect dispatch, field units and incident command. Yet software cannot decide who has authority during a cyber emergency. Nor can a dashboard repair an outdated contact list.
The consultant recommends developing a cyber annex that establishes activation triggers, communications responsibilities, decision authority and the cyber specialist’s command role. Texas A&M Engineering Extension Service (TEEX) and University of Texas, San Antonio (CIAS) provide no-cost courses through the National Cybersecurity Preparedness Consortium. Available programs cover annex development, planning-gap analysis, cascading impacts, EOC integration and incident response.
An annex sitting untouched in a binder offers limited operational value. Annual tabletop exercises can reveal whether officials know whom to contact, whether backup communications work and whether departments agree on when an incident warrants EOC activation. What happens if the jurisdiction’s only IT employee is unavailable?
Mutual aid can address part of that problem. Municipalities can establish agreements with neighboring governments, school-district technology teams and large local employers before an attack. Those agreements should clarify available personnel, access controls, liability, evidence handling and reimbursement rather than leaving those questions for the middle of an outage.
Texas jurisdictions also have a centralized state partner. The Texas Legislature established Texas Cyber Command through House Bill 150 and Government Code Chapter 2063. Texas Cyber Command consolidates incident-response coordination, digital forensics, a 24/7 threat-intelligence center and a cybersecurity hotline. Government Code Section 2063.103 also requires annual certified cybersecurity training for state and local employees and officials who can access government information resources.
AI adds urgency by helping threat actors accelerate reconnaissance, phishing and exploit development. For local leaders, the practical response is less exotic: define authority, train people together, test the plan and arrange outside support. The technology matters. At 2 a.m., however, the roster inside the Emergency Operations Center may matter just as much.
⬇️