The following day, the City Council held a special meeting and voted unanimously to declare a local state of emergency, a move that unlocked emergency procurement authority, mutual aid and faster access to state and federal resources. The city took its entire network offline to contain the intrusion and preserve evidence, rerouted dispatch through the Solano County communications center and brought in the FBI and the Department of Homeland Security. Public safety response never stopped. It is one of several California and U.S. municipal and utility cyber attacks this year, and for the technology companies that sell into local government, it is also a preview of the moment they need to be ready for.
Rob Lloyd, a former CIO, CTO and deputy city manager who implemented new cybersecurity programs and served as an expert resource in cyber incidents for multiple midsize and major cities, says Suisun City's emergency declaration was the right call.
“It's very much the correct structure and a key step to activate their emergency powers as a cyber disaster,” he said.
What follows a declaration like that, he says, is not improvisation: “it is a structured, clear incident response sequence, with the CISO or CIO acting as unified incident commander, and everyone else — elected, appointed, police, fire and legal included— playing a disciplined role that supports response, effective recovery and prosecution."
That structure normally references NIST 800-61 for security incidents along with the Cybersecurity Framework and taps support from the Cybersecurity and Infrastructure Security Agency (CISA), the Multi-State Information Sharing and Analysis Center, and possibly a state's National Guard cybersecurity team. It layers with legal and insurance requirements specific to what the organization has in place.
Titles vary by org chart. For example, a CIO and CISO may be combined in some cities, contracted in others and municipal utilities often run additional security functions. A declared emergency puts everyone under unified command. Lloyd noted that the difference between cities that handle this well and cities that don’t "isn’t sophistication, it’s practice.”
In broad strokes, Lloyd’s playbook moves from verification and severity classification in the first hours to quickly activating available Security Operations Center and Managed Security Service Provider resources in alignment with the cyber insurance carrier’s approved panel of forensics and breach counsel firms, since many policies deny coverage for work done outside that panel.
It's also important to understand insurance priorities aren't always aligned with community priorities — liability is not necessarily the top concern throughout a cyber disaster, such as the decision to pay a ransom or not. Internal notification to legal, HR and department heads needs to occur in sequence, often over out-of-band channels because email and collaboration tools may themselves be compromised. Council and executive briefings, the possible disaster declaration and public communication come next, all reviewed by legal first because unconfirmed attribution or ransom detail in writing is discoverable. Law enforcement, plus state and federal resources such as CISA and the National Guard’s cyber elements, become engaged in parallel, along with sector-specific agencies if a utility’s operational technology or SCADA systems are involved. Remediation, evidence preservation and two after-action reports (one privileged, one public) close out the process, sometimes very slowly. Lloyd notes that one time an after-action report took almost a year at one city because impacted departments and resident boards couldn’t agree on details and language.
“A clear plan doesn’t always move like intended,” he said. "In that case, technical staff moved ahead with a version of the AAR to act on preventative investments while the politics played out."
For the industry partner community, the MSSPs, managed detection and response providers, forensics firms and backup and identity vendors selling into California cities and utilities that sequence also maps where help is welcome and where it isn’t. Lloyd’s experience points to a clear set of dos and don’ts.
DO
- Work through the channel that’s already been activated. When a carrier has a breach panel, engagement happens through that panel, not a general pitch to whoever answers the phone. Being on the panel before the incident is the actual sales cycle.
- Assume normal channels are down. If there’s a legitimate reason to reach a city mid-incident, use a phone call or another out-of-band channel. The attacker may control email and chat.
- Know the difference between IT and OT. A utility with SCADA or Industrial Control System exposure needs a vendor who specializes in that environment, isolated from the general IT response, not a generalist incident response firm relabeled for the occasion.
- Sell partnership and preparedness, not just response. The gap Lloyd keeps finding even in major cities is a missing or untested incident response plan. Tabletop exercises, multi-factor authentication rollouts, backup validation and IRP development are the offers that actually move the needle, and they land before the fire, not during it. Vendor partners that emerge ready to help in hard times, not for top dollar, also consistently look to add long-term strength. The best are built for mission.
- Expect a long tail. Recovery, insurance settlement and after-action work can run months past the headline. Relationships that hold through that stretch are worth more than the first purchase order.
DON'T
- Don’t cold-outreach a city in the first hours or days of a declared incident to sell hard. It reads as opportunistic, and it adds noise for a team that’s already stretched thin.
- Don’t go around the incident commander. Pitching a council member or city manager directly while the CISO is running unified command undermines the structure that’s supposed to be protecting the response.
- Don’t perform or offer forensics and remediation work outside the carrier’s approved panel. It can jeopardize the city’s coverage and its ability to recover costs — a mistake Lloyd has seen well-meaning partners make.
- Don’t ask for details legal hasn’t cleared. Attribution, ransom figures and root cause are often privileged for good reason; pushing for them mid-incident puts the city in a bad position. This also shows you know how to treat details and response as sensitive and urgent. Time and privacy matter as laws in each state differ. Real expertise shows in dramatic ways.
- Don’t mistake urgency for opportunity. A contract pushed through in the middle of chaos rarely reflects well later. Public-sector trust is built over budget cycles, not incident windows. Keep your eyes on the long-term help and relationship.
- How to best help Suisun City in the moment
- How to learn and help address the needs of state and local government as AI security speed and scale land
- How to create a "one house" and data-informed approach that builds toward fewer and smaller incidents
Editor's note: This story was drafted with help from generative AI and edited by humans. Have feedback? Send it to bmiller@erepublic.com.