top of page
Search

Cybersecurity and Disaster Preparedness: Planning for the Day Both Crises Hit at Once

2 days ago
7 min read

Most organizations prepare for cyber incidents and physical disasters as separate risks. Information technology teams may conduct ransomware drills, while emergency managers plan for severe weather, power outages, fires, or facility damage.

The more difficult scenario is when both events occur at once.

A major storm may damage facilities while a ransomware attack disables email, phones, access-control systems, or critical applications. A power outage may interrupt network equipment at the same time that malicious activity compromises cloud services. A campus evacuation may begin just as staff lose access to student records, building systems, or emergency notification tools.

This convergence scenario changes the planning problem. It is no longer only an IT emergency or a facilities emergency. It is an organizational continuity event that requires coordinated action across leadership, emergency management, technology, facilities, communications, legal, human resources, and business operations.

Effective cybersecurity and disaster preparedness planning must assume that technology may be unavailable when the organization needs it most.

Why Cybersecurity Is a Disaster-Preparedness Problem

Cybersecurity is often treated as a technical function focused on protecting networks, devices, and data. That work is essential, but the consequences of a cyber incident extend well beyond the IT department.

Most organizations rely on networked systems to deliver essential services. Universities may depend on cloud-based learning platforms, identity systems, electronic access controls, student information systems, and emergency notification tools. Corporate organizations may rely on cloud applications, voice communications, building management systems, payroll platforms, customer portals, and logistics systems. Health authorities may depend on electronic health records, scheduling platforms, communications systems, and connected medical equipment.

When these systems become unavailable, normal operations can quickly become an emergency-management concern.

FEMA and CISA’s Planning Considerations for Cyber Incidents emphasizes that emergency managers should understand the potential effects of cyber incidents on critical services and emergency operations. The guidance also recommends identifying system dependencies, assigning responsibilities, planning alternative communications, and exercising cyber incident plans.

The key question is not simply, “How do we stop the attack?”

It is also:

“How do we maintain essential services if our normal systems cannot be trusted or accessed?”

The Convergence Scenario: When Two Disruptions Reinforce Each Other

A physical disaster and a cyber incident can interact in several ways:

  • A storm damages a facility where network equipment is located.

  • A power interruption takes servers, access-control systems, or communications equipment offline.

  • A ransomware attack disables systems needed to coordinate evacuation or shelter operations.

  • A flood or fire forces an organization to relocate while identity and remote-access systems are compromised.

  • A physical disruption distracts staff and creates an opportunity for a phishing or ransomware campaign.

  • A third-party cloud, telecommunications, or managed-service provider experiences an outage during a local emergency.

The result may be more serious than either event alone. A damaged facility can slow cyber recovery. A cyber incident can make it harder to understand the physical situation. Staff may be unable to access plans, contact lists, maps, work orders, medical records, or other information needed for response.

This is why cybersecurity and disaster preparedness should be integrated into the same continuity conversation.

Identify Single Points of Failure Before an Incident

Organizations often have more dependencies than they realize. A system may appear redundant because information is stored in the cloud or because a vendor manages the infrastructure. However, redundancy is only meaningful if the organization can still access the service, authenticate users, communicate with the provider, and operate when the surrounding environment is disrupted.

Planning teams should examine systems such as:

Cloud platforms

Cloud services may support email, document storage, learning management, human resources, finance, customer service, and collaboration. If identity management or authentication is unavailable, users may lose access to multiple cloud applications at once.

Ask:

  • Which essential functions depend on this platform?

  • Can authorized staff access the service if the primary identity system is down?

  • Are critical procedures available offline?

  • How will the organization contact the provider without relying on the affected platform?

Voice over Internet Protocol

VoIP systems are convenient but may depend on power, internet connectivity, local network equipment, and cloud-based administration. If the network is unavailable, the organization may lose internal extensions, call routing, voicemail, and emergency contact capabilities.

A continuity plan should identify alternate methods such as mobile phones, radios, printed call trees, or other approved out-of-band channels.

Badge and access-control systems

Electronic badge systems may control entrances, restricted areas, laboratories, residence halls, clinics, and emergency operations facilities. A cyber incident or power failure could prevent authorized access, or create uncertainty about whether access records are reliable.

Plans should address manual access procedures, physical keys, guard posts, visitor controls, and methods for securing facilities when electronic systems are unavailable.

Electronic health records and other critical applications

Where applicable, electronic health records and related systems may be essential to patient care, scheduling, medication processes, or public health operations. A disruption may require carefully designed downtime procedures, approved manual documentation, and a process for reconciling records after restoration.

The objective is not to create a list of every technology asset. It is to identify the systems whose loss would prevent the organization from performing essential functions.

Connected cloud, VoIP, badge access, and health-record systems shown as interrupted infrastructure dependencies

How Ransomware Can Degrade Emergency Response

A ransomware event may affect more than files and applications. It can degrade the organization’s ability to coordinate, communicate, and make decisions.

Potential effects include:

  • Loss of access to emergency plans and contact information

  • Inability to use email or collaboration platforms

  • Disruption of public websites and notification systems

  • Reduced visibility into facilities, equipment, or personnel status

  • Delayed work orders and resource requests

  • Difficulty confirming whether data is accurate and trustworthy

  • Loss of access to scheduling, registration, payroll, or operational systems

  • Increased workload for staff who must switch to manual processes

  • Conflicting information caused by disconnected teams

During a physical disaster, these effects can complicate evacuation, sheltering, damage assessment, continuity of operations, and recovery coordination.

A plan that assumes email, shared drives, electronic forms, and digital contact lists will always be available is not a complete plan. Critical information should be accessible through resilient, appropriately protected alternatives.

Build Communication Fallbacks Before Networks Go Down

Communication planning should use a layered approach. FEMA and CISA guidance discusses alternative communications and recommends developing a PACE structure:

  • Primary: the normal communication method, such as email, VoIP, or an emergency notification platform.

  • Alternate: a separate approved channel that can be used if the primary system fails.

  • Contingency: another method that supports essential coordination for a longer disruption.

  • Emergency: the last-resort method used when other channels are unavailable.

Potential fallback tools may include:

  • Printed contact rosters

  • Phone trees

  • Mobile phones on separate carriers, where practical

  • Two-way radios

  • In-person reporting points

  • Physical status boards

  • Pre-established meeting locations

  • Alternate websites or public information channels

  • Approved external communication methods

The specific tools will vary by organization. The important point is to document who uses each channel, when it is activated, what information may be shared, and how the method is tested.

Fallback communications should also account for accessibility. Instructions must be usable by people with different communication, mobility, sensory, cognitive, and technology needs. This is especially important for universities, public agencies, and organizations serving diverse populations.

Design Tabletop Exercises That Test Both Crises

A cybersecurity tabletop exercise that only involves IT leaders may not reveal how a ransomware event affects emergency operations. A severe-weather exercise that assumes all technology remains available may miss the most consequential dependencies.

A combined exercise should include representatives from:

  • Executive leadership

  • Emergency management and continuity

  • Information technology and cybersecurity

  • Facilities and physical security

  • Communications and public information

  • Legal, privacy, and compliance

  • Human resources and finance

  • Academic, clinical, production, or business operations

  • Key service owners and vendors, as appropriate

The scenario can begin with an approaching storm, wildfire, major power event, or facility disruption. As participants activate emergency procedures, injects can introduce suspicious activity, encrypted files, unavailable cloud services, compromised credentials, or a loss of network connectivity.

The exercise should force decisions such as:

  • Who activates the emergency operations or continuity structure?

  • Which services receive priority when resources are limited?

  • How do leaders communicate if email and VoIP are unavailable?

  • How do teams verify information when systems may be compromised?

  • Which manual procedures are activated?

  • How are students, employees, patients, customers, or community members informed?

  • What is the order for restoring facilities, networks, applications, and data?

  • When should external assistance, legal counsel, law enforcement, or regulators be engaged?

CISA Tabletop Exercise Packages include customizable scenarios and discussion questions covering ransomware, natural disasters, and cyber-physical convergence. The packages also include planning and after-action materials that organizations can adapt to their own missions.

Emergency operations team conducting a combined cyber outage and physical disaster tabletop exercise using printed plans and radios

Write Continuity Plans as If the Systems Are Gone

The strongest continuity plans do not begin with technology. They begin with essential functions.

For each critical function, identify:

  1. The minimum service that must continue

  2. The people responsible for delivering it

  3. The facilities, equipment, data, and vendors required

  4. The systems on which it depends

  5. The manual or alternate process if those systems are unavailable

  6. The information needed to make decisions

  7. The maximum tolerable disruption

  8. The conditions for returning to normal operations

This approach helps organizations distinguish between a system that is convenient and one that is mission-critical.

It also clarifies recovery priorities. The first system restored may not be the most visible system. It may be the identity service, network connection, communications platform, or application that enables several essential functions to operate.

Plans should be reviewed with the people who actually perform the work. A procedure that appears complete on paper may be impractical during a prolonged outage, staff shortage, evacuation, or loss of access to records.

Turn Preparedness Into Organizational Capability

Cybersecurity and disaster preparedness are most effective when treated as an ongoing organizational capability rather than a one-time document.

Organizations can strengthen that capability by:

  • Mapping dependencies across essential services

  • Maintaining offline or independently accessible emergency information

  • Establishing communication fallbacks and testing them

  • Training staff on manual workarounds

  • Conducting integrated cyber and physical disaster exercises

  • Capturing observations in an after-action report

  • Assigning improvement actions and responsible owners

  • Updating plans when systems, vendors, facilities, or staffing change

The goal is not to predict every possible event. It is to ensure that leadership and staff can make sound decisions when information is incomplete, systems are unavailable, and multiple priorities compete for attention.

Preparedness planning materials, emergency radio, and offline continuity resources arranged for a leadership team

Prepare for the Day Both Crises Hit at Once

A cyber incident can become a disaster-preparedness problem the moment it interrupts essential services. A physical disaster can become a cybersecurity problem when it damages technology, disrupts communications, or creates conditions for compromise.

Planning for these events together helps organizations move beyond isolated departmental plans and toward practical continuity.

Alpha Research Group provides customized emergency management training solutions for corporate and academic audiences, including cybersecurity and disaster preparedness education, crisis communications, continuity-focused learning, and exercise-based preparation. Visit Alpha Research Group to explore training options or contact the organization to discuss your preparedness objectives.

Further Reading

 
 
 

Comments


bottom of page