Cybersecurity and Disaster Preparedness: Planning for the Day Both Crises Hit at Once
Most organizations prepare for cyber incidents and physical disasters as separate risks. Information technology teams may conduct ransomware drills, while emergency managers plan for severe weather, power outages, fires, or facility damage.
The more difficult scenario is when both events occur at once.
A major storm may damage facilities while a ransomware attack disables email, phones, access-control systems, or critical applications. A power outage may interrupt network equipment at the same time that malicious activity compromises cloud services. A campus evacuation may begin just as staff lose access to student records, building systems, or emergency notification tools.
This convergence scenario changes the planning problem. It is no longer only an IT emergency or a facilities emergency. It is an organizational continuity event that requires coordinated action across leadership, emergency management, technology, facilities, communications, legal, human resources, and business operations.
Effective cybersecurity and disaster preparedness planning must assume that technology may be unavailable when the organization needs it most.
Why Cybersecurity Is a Disaster-Preparedness Problem
Cybersecurity is often treated as a technical function focused on protecting networks, devices, and data. That work is essential, but the consequences of a cyber incident extend well beyond the IT department.
Most organizations rely on networked systems to deliver essential services. Universities may depend on cloud-based learning platforms, identity systems, electronic access controls, student information systems, and emergency notification tools. Corporate organizations may rely on cloud applications, voice communications, building management systems, payroll platforms, customer portals, and logistics systems. Health authorities may depend on electronic health records, scheduling platforms, communications systems, and connected medical equipment.
When these systems become unavailable, normal operations can quickly become an emergency-management concern.
FEMA and CISA’s Planning Considerations for Cyber Incidents emphasizes that emergency managers should understand the potential effects of cyber incidents on critical services and emergency operations. The guidance also recommends identifying system dependencies, assigning responsibilities, planning alternative communications, and exercising cyber incident plans.
The key question is not simply, “How do we stop the attack?”
It is also:
“How do we maintain essential services if our normal systems cannot be trusted or accessed?”
The Convergence Scenario: When Two Disruptions Reinforce Each Other
A physical disaster and a cyber incident can interact in several ways:
A storm damages a facility where network equipment is located.
A power interruption takes servers, access-control systems, or communications equipment offline.
A ransomware attack disables systems needed to coordinate evacuation or shelter operations.
A flood or fire forces an organization to relocate while identity and remote-access systems are compromised.
A physical disruption distracts staff and creates an opportunity for a phishing or ransomware campaign.
A third-party cloud, telecommunications, or managed-service provider experiences an outage during a local emergency.
The result may be more serious than either event alone. A damaged facility can slow cyber recovery. A cyber incident can make it harder to understand the physical situation. Staff may be unable to access plans, contact lists, maps, work orders, medical records, or other information needed for response.
This is why cybersecurity and disaster preparedness should be integrated into the same continuity conversation.
Identify Single Points of Failure Before an Incident
Organizations often have more dependencies than they realize. A system may appear redundant because information is stored in the cloud or because a vendor manages the infrastructure. However, redundancy is only meaningful if the organization can still access the service, authenticate users, communicate with the provider, and operate when the surrounding environment is disrupted.
Planning teams should examine systems such as:
Cloud platforms
Cloud services may support email, document storage, learning management, human resources, finance, customer service, and collaboration. If identity management or authentication is unavailable, users may lose access to multiple cloud applications at once.
Ask:
Which essential functions depend on this platform?
Can authorized staff access the service if the primary identity system is down?
Are critical procedures available offline?
How will the organization contact the provider without relying on the affected platform?
Voice over Internet Protocol
VoIP systems are convenient but may depend on power, internet connectivity, local network equipment, and cloud-based administration. If the network is unavailable, the organization may lose internal extensions, call routing, voicemail, and emergency contact capabilities.
A continuity plan should identify alternate methods such as mobile phones, radios, printed call trees, or other approved out-of-band channels.
Badge and access-control systems
Electronic badge systems may control entrances, restricted areas, laboratories, residence halls, clinics, and emergency operations facilities. A cyber incident or power failure could prevent authorized access, or create uncertainty about whether access records are reliable.
Plans should address manual access procedures, physical keys, guard posts, visitor controls, and methods for securing facilities when electronic systems are unavailable.
Electronic health records and other critical applications
Where applicable, electronic health records and related systems may be essential to patient care, scheduling, medication processes, or public health operations. A disruption may require carefully designed downtime procedures, approved manual documentation, and a process for reconciling records after restoration.
The objective is not to create a list of every technology asset. It is to identify the systems whose loss would prevent the organization from performing essential functions.

How Ransomware Can Degrade Emergency Response
A ransomware event may affect more than files and applications. It can degrade the organization’s ability to coordinate, communicate, and make decisions.
Potential effects include:
Loss of access to emergency plans and contact information
Inability to use email or collaboration platforms
Disruption of public websites and notification systems
Reduced visibility into facilities, equipment, or personnel status
Delayed work orders and resource requests
Difficulty confirming whether data is accurate and trustworthy
Loss of access to scheduling, registration, payroll, or operational systems
Increased workload for staff who must switch to manual processes
Conflicting information caused by disconnected teams
During a physical disaster, these effects can complicate evacuation, sheltering, damage assessment, continuity of operations, and recovery coordination.
A plan that assumes email, shared drives, electronic forms, and digital contact lists will always be available is not a complete plan. Critical information should be accessible through resilient, appropriately protected alternatives.
Build Communication Fallbacks Before Networks Go Down
Communication planning should use a layered approach. FEMA and CISA guidance discusses alternative communications and recommends developing a PACE structure:
Primary: the normal communication method, such as email, VoIP, or an emergency notification platform.
Alternate: a separate approved channel that can be used if the primary system fails.
Contingency: another method that supports essential coordination for a longer disruption.
Emergency: the last-resort method used when other channels are unavailable.
Potential fallback tools may include:
Printed contact rosters
Phone trees
Mobile phones on separate carriers, where practical
Two-way radios
In-person reporting points
Physical status boards
Pre-established meeting locations
Alternate websites or public information channels
Approved external communication methods
The specific tools will vary by organization. The important point is to document who uses each channel, when it is activated, what information may be shared, and how the method is tested.
Fallback communications should also account for accessibility. Instructions must be usable by people with different communication, mobility, sensory, cognitive, and technology needs. This is especially important for universities, public agencies, and organizations serving diverse populations.
Design Tabletop Exercises That Test Both Crises
A cybersecurity tabletop exercise that only involves IT leaders may not reveal how a ransomware event affects emergency operations. A severe-weather exercise that assumes all technology remains available may miss the most consequential dependencies.
A combined exercise should include representatives from:
Executive leadership
Emergency management and continuity
Information technology and cybersecurity
Facilities and physical security
Communications and public information
Legal, privacy, and compliance
Human resources and finance
Academic, clinical, production, or business operations
Key service owners and vendors, as appropriate
The scenario can begin with an approaching storm, wildfire, major power event, or facility disruption. As participants activate emergency procedures, injects can introduce suspicious activity, encrypted files, unavailable cloud services, compromised credentials, or a loss of network connectivity.
The exercise should force decisions such as:
Who activates the emergency operations or continuity structure?
Which services receive priority when resources are limited?
How do leaders communicate if email and VoIP are unavailable?
How do teams verify information when systems may be compromised?
Which manual procedures are activated?
How are students, employees, patients, customers, or community members informed?
What is the order for restoring facilities, networks, applications, and data?
When should external assistance, legal counsel, law enforcement, or regulators be engaged?
CISA Tabletop Exercise Packages include customizable scenarios and discussion questions covering ransomware, natural disasters, and cyber-physical convergence. The packages also include planning and after-action materials that organizations can adapt to their own missions.

Write Continuity Plans as If the Systems Are Gone
The strongest continuity plans do not begin with technology. They begin with essential functions.
For each critical function, identify:
The minimum service that must continue
The people responsible for delivering it
The facilities, equipment, data, and vendors required
The systems on which it depends
The manual or alternate process if those systems are unavailable
The information needed to make decisions
The maximum tolerable disruption
The conditions for returning to normal operations
This approach helps organizations distinguish between a system that is convenient and one that is mission-critical.
It also clarifies recovery priorities. The first system restored may not be the most visible system. It may be the identity service, network connection, communications platform, or application that enables several essential functions to operate.
Plans should be reviewed with the people who actually perform the work. A procedure that appears complete on paper may be impractical during a prolonged outage, staff shortage, evacuation, or loss of access to records.
Turn Preparedness Into Organizational Capability
Cybersecurity and disaster preparedness are most effective when treated as an ongoing organizational capability rather than a one-time document.
Organizations can strengthen that capability by:
Mapping dependencies across essential services
Maintaining offline or independently accessible emergency information
Establishing communication fallbacks and testing them
Training staff on manual workarounds
Conducting integrated cyber and physical disaster exercises
Capturing observations in an after-action report
Assigning improvement actions and responsible owners
Updating plans when systems, vendors, facilities, or staffing change
The goal is not to predict every possible event. It is to ensure that leadership and staff can make sound decisions when information is incomplete, systems are unavailable, and multiple priorities compete for attention.

Prepare for the Day Both Crises Hit at Once
A cyber incident can become a disaster-preparedness problem the moment it interrupts essential services. A physical disaster can become a cybersecurity problem when it damages technology, disrupts communications, or creates conditions for compromise.
Planning for these events together helps organizations move beyond isolated departmental plans and toward practical continuity.
Alpha Research Group provides customized emergency management training solutions for corporate and academic audiences, including cybersecurity and disaster preparedness education, crisis communications, continuity-focused learning, and exercise-based preparation. Visit Alpha Research Group to explore training options or contact the organization to discuss your preparedness objectives.
Further Reading

Comments