Public safety
The agency cannot go offline. Neither can the investigation.
Fire districts, EMS agencies, police and sheriff's departments, and dispatch centers run on systems that were never allowed to be down. CAD, RMS, ePCR, scheduling, payroll, and a dozen SaaS tools nobody has inventoried since the vendor demo. Most of it is administered by one IT person, a shared county resource, or an MSP whose contract predates the threat.
We work in that environment specifically. Not enterprise security advice with the serial numbers filed off.
What makes this different
01Four constraints that change every decision.
Uptime is not negotiable.
Your business network can be down for a day. Dispatch, response, and patient care cannot. That single constraint changes how you scope containment, when you reimage, whether you can force a password reset mid-shift, and what you tell mutual aid partners. We plan around it instead of discovering it during an incident.
CJIS is not SOC 2.
Advanced authentication, personnel screening, audit logging, and incident reporting obligations apply to systems most agencies do not realize are in scope. We have carried CJIS compliance from the vendor side, which means we know what your software provider is actually doing and what they are letting you assume.
Your ePCR holds protected health information.
Which means a compromised account is potentially a HIPAA notification event, and the clock on that starts whether or not anyone has told your chief yet.
You answer to a board.
Findings that cannot be explained in a public meeting, in eight minutes, without jargon, do not get funded. We write for that room because we have sat in it.
Five places this usually starts.
Incident response and forensics.
Business email compromise, payroll and ACH fraud, ransomware, and account takeover. We work the artifacts directly and produce a record that satisfies your board, your insurer, and law enforcement at the same time.
CJIS readiness.
An honest assessment of where you actually stand, what your vendors are responsible for, and what has to be closed before your next audit.
Vendor and contract review.
Your CAD, RMS, and ePCR providers hold your most sensitive data. We read what they committed to, tell you where the gaps are, and give you language to fix it at renewal.
Cyber insurance readiness.
Carriers now require MFA, EDR, backup verification, and email authentication before they will bind or renew. We tell you where you fall short before the questionnaire does.
Board and governance support.
Security posture reporting a board can act on, and the funding case to go with it.
Funding
Most agencies pay for this with grant money.
Most agencies fund this work through grants rather than operating budgets. We are comfortable structuring engagements around AFG, SAFER, the State and Local Cybersecurity Grant Program, and Homeland Security Grant Program cycles, including producing the scope and cost documentation those applications require.