By Angelis Pseftis A cyberattack does not have to knock out 911 to put officers and the public at risk. Phones and radios may still work while computer-aided dispatch (CAD), records, warrant checks, jail systems or digital evidence disappear. At that point, the question for command staff is no longer, “Is this really a cyber incident?” It is, “What must keep working right now, and who has the authority to make that happen?” That is why a serious network disruption belongs in the incident command conversation from the first hour. The chief or sheriff may have to activate manual procedures, move personnel, isolate systems, preserve evidence, request help and brief the public before anyone can say whether the cause is ransomware, equipment failure or a vendor outage. The central mistake is treating the event only as an information technology (IT) recovery job. For a police agency, it is also a problem of keeping essential services running, preserving evidence, supporting a criminal investigation and maintaining public trust. The radio can work while the rest of policing goes dark The FBI received more than 3,600 ransomware complaints in 2025 and identified government facilities among the sectors most affected by the 10 most frequently reported types of ransomware. Those figures are reports, not a census. The FBI also cautions that its loss total generally excludes downtime, lost files and equipment, recovery work by outside vendors and incidents reported only to field offices. For police leaders, those uncounted operational costs are often the part that matters most. Curry County, Oregon, shows the difference. An official account from the Cybersecurity and Infrastructure Security Agency (CISA) says that during the county’s 2023 ransomware attack, the 911 center could still take calls and communicate by radio, but CAD, warrant and license-plate queries, jail records, juvenile records and