Earlier this month, Suisun City, California, declared a state of emergency after a cyberattack forced the city to shut down portions of its IT network. The incident affected police and fire communications, including the routing of 911 calls. Public safety response continued, with dispatchers using the Solano County dispatch center as part of the city's contingency response.
That distinction matters.
The cyberattack did not stop at the IT department. It reached systems directly connected to the community's ability to communicate with police, fire, and emergency services.
It is another reminder that cybersecurity and physical safety can no longer be treated as separate problems.
The systems we rely on for safety are increasingly connected
Emergency communications, access control, video systems, building systems, mobile devices, mass notification platforms, dispatch systems, and location technologies increasingly depend on networks, cloud services, integrations, and shared infrastructure.
That connectivity creates tremendous opportunities to improve emergency response. It can also create dependencies.
If a network becomes unavailable, a server is compromised, an identity system cannot authenticate users, or a critical integration goes offline, the impact can quickly move beyond lost data or interrupted business operations.
It can affect the ability to protect people.
The question for public safety leaders, emergency managers, security teams, CIOs, and CISOs therefore cannot simply be:
How do we prevent a cyberattack?
It also has to be:
How do we continue responding to emergencies when part of our technology environment is unavailable?
Resilience means assuming something will eventually fail
No responsible technology provider can promise that a system will never be attacked or that infrastructure will never fail.
Resilience starts by acknowledging that possibility and designing around it.
For an emergency response platform, that means thinking about redundant communication paths, infrastructure availability, secure access, system and device readiness, monitoring, auditability, location context, and alternative ways to coordinate people when the primary path is disrupted.
The objective is not simply keeping an application online.
The objective is keeping the response chain intact.
An alert still needs to be received. The location still needs to be understood. Security and key personnel still need to know what is happening. Responders still need useful context. And organizations need the ability to coordinate the next action even when parts of their normal operating environment are under stress.
Why SOS Technologies pursued GovRAMP Authorization
For SOS Technologies, cybersecurity is not an adjacent feature to emergency response. It is part of the architecture.
SOS Technologies' cloud offering is GovRAMP Authorized at the Moderate impact level. GovRAMP Authorized is the program's highest level of verification and requires comprehensive security controls, independent assessment by an approved Third Party Assessment Organization, government review or approval, and ongoing continuous monitoring. GovRAMP's framework is aligned with NIST SP 800-53 security controls.
We pursued that level of authorization because organizations should not have to choose between improving physical safety and protecting their digital environment.
An emergency response platform may handle sensitive information about people, facilities, locations, incidents, devices, policies, and response activity. Customers should be able to ask hard questions about how that information is protected, who can access it, how activity is audited, how security controls are validated, and how those controls are maintained over time.
GovRAMP provides an independent framework for answering those questions.
It is important to be clear about what GovRAMP does not mean. Authorization does not mean a platform is immune from cyberattack. What it provides is independent validation that required security controls have been implemented, assessed, documented, reviewed, and continuously monitored.
For technology supporting emergency response, that accountability matters.
Why SOS Live runs in AWS GovCloud
We made a similar decision with the infrastructure underneath SOS Live.
SOS Live uses AWS GovCloud (US), isolated AWS Regions designed for U.S. government agencies and customers with sensitive workloads and stringent regulatory requirements. AWS GovCloud supports compliance requirements including FedRAMP High, DoD SRG Impact Levels 4 and 5, CJIS, and certain U.S. export control requirements. AWS also states that the GovCloud Regions are logically and physically administered exclusively by U.S. citizens.
Why put an emergency response platform there?
Because the infrastructure supporting a life safety platform should reflect the seriousness of the mission running on top of it.
AWS GovCloud gives SOS a strong cloud foundation designed for security sensitive and high accountability environments. SOS then layers its own security controls, application architecture, identity controls, encryption, audit capabilities, tenant separation, monitoring, and operational safeguards on top of that infrastructure.
GovCloud alone does not make SOS Live GovRAMP Authorized, nor does GovRAMP eliminate operational risk. They are complementary parts of a broader approach to building a platform organizations can depend on when conditions are anything but normal.
Cyber resilience has to include operational resilience
This is where cybersecurity strategy and emergency response strategy increasingly intersect.
Imagine an organization experiencing a serious physical incident at the same time part of its network environment is degraded.
Can the organization still determine where the emergency is occurring?
Can security see what systems and devices are available?
Can the appropriate staff be notified?
Can responders receive useful location and incident context?
Can the organization operate if a primary communication or integration path is unavailable?
Can administrators see the health of critical emergency technology before an incident occurs?
Can the organization reconstruct what happened afterward?
Those are not simply cybersecurity questions.
They are emergency preparedness questions.
SOS Live 2.0 is designed around that larger operational picture. The platform brings activation, location intelligence, device and system visibility, situational awareness, communications, secure connectivity, and coordinated response workflows together around the incident. Where configured, it can also support approved escalation and information delivery to public safety and first responder workflows.
The purpose is not to replace 911, security teams, dispatchers, IT departments, or first responders.
It is to give those teams better visibility and another layer of resilience when seconds matter.
The next emergency may begin digitally
The Suisun City incident is a useful reminder of how quickly the line between cybersecurity and public safety can disappear.
A cyberattack that disrupts a financial application is an IT problem.
A cyberattack that interferes with the systems people depend on to request help, understand an emergency, secure a facility, communicate with staff, or coordinate responders can become something much more serious.
It becomes a public safety problem.
Organizations should therefore evaluate emergency technology with the same questions they increasingly ask about the rest of their critical infrastructure: How is it secured? How is it monitored? What happens when something fails? What dependencies exist? What redundancy is available? And can the organization continue operating when its normal environment is disrupted?
Notification is only the start. Coordinated response is the goal.
Cyber resilience should help ensure that response remains possible even when the unexpected is not just a physical emergency, but a digital one as well.