Skip to main content

Cyber incidents are operational crises, not IT events

Police and public safety leaders must regularly rehearse command, containment, and recovery activities to protect critical services and maintain public trust. Here, we explore public safety’s unique cyber challenges and five insights to help Canadian agencies prepare.

Key takeaways

  • Cyber resilience starts with service continuity. Public safety leaders must plan how emergency response, investigations, and critical operations will continue when core systems fail.
  • Preparation determines performance under pressure. Agencies that define roles, establish unified command, and rehearse cyber scenarios can respond faster and reduce operational disruption.
  • Recovery must be proven, not presumed. Organizations build resilience by testing restoration capabilities, exposing weaknesses, and turning lessons learned into measurable improvements.  

Chat with our leaders

For police and public safety organizations that deliver essential services, cyber incidents are no longer rare events or technical anomalies. They are foreseeable operational risks that can arise from malicious attacks, inadvertent system outages, or even basic human error. The Government of Canada's most recent National Cyber Threat Assessment notes that the past two years have seen a sharp rise in both the number and severity of cyber incidents, many targeting essential services.1

Police and public safety organizations should be ready for an incident, capable of responding effectively when one occurs, and equipped to recover quickly and efficiently afterward. Building a resilient and well-prepared organization demands ongoing investment in cybersecurity capabilities and a comprehensive approach that emphasizes readiness, response, and recovery at every stage of the incident lifecycle.

The question leaders should be asking is: can we continue delivering critical public safety services if core systems become unavailable?

Public safety’s unique cyber challenges

Public safety organizations rely on interconnected systems, including 911 computer-aided dispatch (CAD), records management systems (RMS), the Canadian Police Information Centre (CPIC), digital evidence platforms, and related operational technologies. These systems support time-sensitive decisions where service disruption has real-world consequences.

Deloitte's Global Future of Cyber Survey (4th edition) found that 40% of organizations publicly reported six to 10 breaches in the past year.2

Threat actors deliberately target organizations whose disruption creates urgency, public impact, and leadership pressure. For public safety agencies, the risks are significant:

  • Impaired 911 and emergency response
  • Breaches of sensitive and confidential information
  • Threats to criminal trials and evidentiary integrity
  • Loss of public trust and reputational damage
  • Financial loss

Police and public safety leaders should understand and prioritize the time-critical services, processes, and technology dependencies required to maintain a minimum acceptable level of operations during a cyber incident and prepare to sustain them under degraded conditions.3

Five cyber insights for Canadian public safety organizations

1. Treat cyber risk as operating risk, not an IT issue

Cyber resilience is a command responsibility, not a technical one. Public safety leaders should define their critical systems (911 dispatch, RMS, CAD, digital evidence) and rehearse minimum viable operations without IT support. The real operational risk is the inability to respond to emergencies, investigate crimes, gather evidence, and maintain public confidence.

Why this matters:
When an incident hits, the crown jewels at risk are essential operational systems. Outages directly affect emergency response, investigations, court timelines, officer safety, and public trust. These processes and actions must continue even if the systems are compromised, so organizations must find a way to make them work. Not responding is not an option.

2. Define and rehearse the first hour

The first hour of a cyber incident is not the time to sort out roles, escalation paths, or decision-making authority. Public safety organizations need a documented Incident Response Plan that assigns clear ownership across leadership, operations, legal, communications, and technology, and defines how decisions get made under pressure.

Leaders should rehearse it through regular tabletop exercises and maintain standing relationships with external response partners, so that when an incident hits, the response is muscle memory rather than improvisation.

Why this matters:
Delays to containment, unclear decision-making, and uncoordinated communications can significantly increase operational disruption and recovery timelines. The first hour is where reputational and operational damage compounds fastest.

3. Align decision-making across technology, operations, legal, and communications

Designate a single “quarterback” decision-maker with authority across functions. Establish one incident command structure, one operating picture, and one timeline so frontline operations, legal disclosure, media response, and technical containment move in sync.

Why this matters:
Without integrated command, conflicting messages and decisions multiply harm in the first 24 to 72 hours. Technical teams contain while operations continue using compromised systems. Legal holds back on disclosing details while communications teams are already briefing the public. The result is confusion, and misalignment among teams becomes an avoidable driver of further damage.

4. Prove recovery, don’t assume it

Map crown-jewel dependencies, define recovery tiers, test restoration times under load, and pre-authorize restore-versus-rebuild decision paths. Backups need to go beyond simply being scheduled, to be tested, segregated, and immutable.

Why this matters:
Backups are frequently untested, incomplete, or exposed to the same compromise as production systems. Hidden dependencies (for example, identity, DNS, or vendor APIs) surface late in recovery, when time and options are running short.

5. Convert incidents into measurable resilience

Fund a 90-day post-incident improvement plan with named owners, board-visible metrics, and a closed-loop reporting cycle. Use every incident and tabletop exercise to drive permanent improvement.

Why this matters:
Without this discipline, findings sit in unfunded reports and the next incident repeats the same weaknesses at higher stakes. The threat landscape is only growing. The Canadian Centre for Cyber Security forecasts ransomware growing approximately 26% annually through 2027 and identifies it as the top cybercrime threat to Canadian critical infrastructure, including public safety.4

How Deloitte supports you at every stage

An experienced external partner can act as a central coordinator, bringing an objective perspective and proven incident-management practices while leadership remains focused on protecting critical services. Deloitte offers support over the full lifecycle of incident management:

  1. Pre-incident. We strengthen readiness before an event by clarifying roles, testing plans, and building practical, business-aligned response capabilities.
  2. Active incident support. We provide rapid, coordinated technical and strategic support to contain the threat, protect critical services, and guide leaders through high-pressure decisions.
  3. Post-incident support. We help restore systems safely, document what occurred, and turn lessons learned into targeted improvements that build long-term resilience.

Our approach brings structure, experience, and clarity, so agencies can protect their people, their operations, and their reputation when it matters most.

Here’s a snapshot of what that looks like at each stage:  

Your next steps

Public confidence depends on an agency’s ability to continue delivering critical services during periods of disruption. Cyber resilience is now a core leadership responsibility, shared across the organization rather than owned by IT or cybersecurity teams alone.

Agencies that define their minimum viable operations, rehearse the first hour, align decision-making across functions, and continuously improve recovery capabilities will be better positioned to protect both operations and public trust.

Connect with our leaders to pressure-test your readiness, define your minimum viable operations, and strengthen resilience before the next incident tests it for you.  

  1. Government of Canada, “National Cyber Threat Assessment 2025-2026,” accessed July 7, 2026.
  2. Deloitte, “Global Future of Cyber Survey, 4th Edition,” accessed July 7, 2026.
  3. Deloitte, “Minimum Viable Organisation: Maximise Resilience in uncertain times,” accessed July 7, 2026.
  4. Government of Canada, “Ransomware Threat Outlook 2025-2027,” published January 28, 2026.  

Did you find this useful?

Thanks for your feedback