Key takeaways
For police and public safety organizations that deliver essential services, cyber incidents are no longer rare events or technical anomalies. They are foreseeable operational risks that can arise from malicious attacks, inadvertent system outages, or even basic human error. The Government of Canada's most recent National Cyber Threat Assessment notes that the past two years have seen a sharp rise in both the number and severity of cyber incidents, many targeting essential services.1
Police and public safety organizations should be ready for an incident, capable of responding effectively when one occurs, and equipped to recover quickly and efficiently afterward. Building a resilient and well-prepared organization demands ongoing investment in cybersecurity capabilities and a comprehensive approach that emphasizes readiness, response, and recovery at every stage of the incident lifecycle.
The question leaders should be asking is: can we continue delivering critical public safety services if core systems become unavailable?
Public safety organizations rely on interconnected systems, including 911 computer-aided dispatch (CAD), records management systems (RMS), the Canadian Police Information Centre (CPIC), digital evidence platforms, and related operational technologies. These systems support time-sensitive decisions where service disruption has real-world consequences.
Deloitte's Global Future of Cyber Survey (4th edition) found that 40% of organizations publicly reported six to 10 breaches in the past year.2
Threat actors deliberately target organizations whose disruption creates urgency, public impact, and leadership pressure. For public safety agencies, the risks are significant:
Police and public safety leaders should understand and prioritize the time-critical services, processes, and technology dependencies required to maintain a minimum acceptable level of operations during a cyber incident and prepare to sustain them under degraded conditions.3
Cyber resilience is a command responsibility, not a technical one. Public safety leaders should define their critical systems (911 dispatch, RMS, CAD, digital evidence) and rehearse minimum viable operations without IT support. The real operational risk is the inability to respond to emergencies, investigate crimes, gather evidence, and maintain public confidence.
Why this matters:
When an incident hits, the crown jewels at risk are essential operational systems. Outages directly affect emergency response, investigations, court timelines, officer safety, and public trust. These processes and actions must continue even if the systems are compromised, so organizations must find a way to make them work. Not responding is not an option.
The first hour of a cyber incident is not the time to sort out roles, escalation paths, or decision-making authority. Public safety organizations need a documented Incident Response Plan that assigns clear ownership across leadership, operations, legal, communications, and technology, and defines how decisions get made under pressure.
Leaders should rehearse it through regular tabletop exercises and maintain standing relationships with external response partners, so that when an incident hits, the response is muscle memory rather than improvisation.
Why this matters:
Delays to containment, unclear decision-making, and uncoordinated communications can significantly increase operational disruption and recovery timelines. The first hour is where reputational and operational damage compounds fastest.
Designate a single “quarterback” decision-maker with authority across functions. Establish one incident command structure, one operating picture, and one timeline so frontline operations, legal disclosure, media response, and technical containment move in sync.
Why this matters:
Without integrated command, conflicting messages and decisions multiply harm in the first 24 to 72 hours. Technical teams contain while operations continue using compromised systems. Legal holds back on disclosing details while communications teams are already briefing the public. The result is confusion, and misalignment among teams becomes an avoidable driver of further damage.
Map crown-jewel dependencies, define recovery tiers, test restoration times under load, and pre-authorize restore-versus-rebuild decision paths. Backups need to go beyond simply being scheduled, to be tested, segregated, and immutable.
Why this matters:
Backups are frequently untested, incomplete, or exposed to the same compromise as production systems. Hidden dependencies (for example, identity, DNS, or vendor APIs) surface late in recovery, when time and options are running short.
Fund a 90-day post-incident improvement plan with named owners, board-visible metrics, and a closed-loop reporting cycle. Use every incident and tabletop exercise to drive permanent improvement.
Why this matters:
Without this discipline, findings sit in unfunded reports and the next incident repeats the same weaknesses at higher stakes. The threat landscape is only growing. The Canadian Centre for Cyber Security forecasts ransomware growing approximately 26% annually through 2027 and identifies it as the top cybercrime threat to Canadian critical infrastructure, including public safety.4
An experienced external partner can act as a central coordinator, bringing an objective perspective and proven incident-management practices while leadership remains focused on protecting critical services. Deloitte offers support over the full lifecycle of incident management:
Our approach brings structure, experience, and clarity, so agencies can protect their people, their operations, and their reputation when it matters most.
Here’s a snapshot of what that looks like at each stage:
Public confidence depends on an agency’s ability to continue delivering critical services during periods of disruption. Cyber resilience is now a core leadership responsibility, shared across the organization rather than owned by IT or cybersecurity teams alone.
Agencies that define their minimum viable operations, rehearse the first hour, align decision-making across functions, and continuously improve recovery capabilities will be better positioned to protect both operations and public trust.
Connect with our leaders to pressure-test your readiness, define your minimum viable operations, and strengthen resilience before the next incident tests it for you.