Cybersecurity discussions often begin with firewalls, ransomware, encryption, and passwords.
For a police chief, perhaps they should begin with a different question:
If our computers stopped working this morning, could we still operate?
Imagine arriving at headquarters and discovering that officers cannot access the records management system. CAD is unavailable. Report-writing terminals are down. Network files cannot be opened. Email is inaccessible. Perhaps body-camera uploads, evidence systems, or other connected services are affected.
Calls for service, however, do not stop.
The public still expects someone to answer 911.
This is why cybersecurity should not be viewed solely as an information technology problem. It is an operational-readiness problem.
The Federal Bureau of Investigation’s Criminal Justice Information Services (CJIS) Security Policy recognizes this distinction. Its contingency-planning requirements call for agencies to develop documented policies, responsibilities, and procedures and to review them following security incidents and exercises (Federal Bureau of Investigation [FBI], 2024).
For small and midsize departments, this issue may matter most. Limited staffing can mean that the same technology failure affects dispatch, records, investigations, supervision, and patrol simultaneously.
The contrarian question, therefore, isn’t: “How sophisticated is our cybersecurity?”
It is: “How long can we police without our technology?”
Could dispatchers revert to an alternate process?
Can officers document calls manually?
Can supervisors maintain accountability?
How would officers access critical information?
Who decides which systems to restore first?
How would reports and evidence created during the outage later be reconciled with electronic systems?
The FBI’s cloud-security guidance specifically tells agencies to examine availability, backups, recovery, disaster recovery, and whether critical operations can resume during prolonged disruptions (FBI, n.d.).
Technology has made policing faster and more capable. But dependence creates its own vulnerability.
A resilient police department should therefore prepare for two realities simultaneously:
- Protect the technology.
- Prepare to operate without it.
That second responsibility deserves more attention.
A department’s cybersecurity plan should not be judged only by whether it can prevent an attack. No defense is perfect.
Perhaps the better test is this: If the technology failed at 8:00 tomorrow morning, would everyone know what to do at 8:01?
For a police chief, that may be the cybersecurity question that matters most.
–Klyvorek & OpenAI
KLYVOREK, a division of the American Academy of Advanced Thinking, LLC, is an AI-assisted law enforcement documentation platform that helps officers create clear, structured incident reports and draft search and arrest warrant applications, while keeping the officer in control of the final document.
___________________________________________________
References
Federal Bureau of Investigation. (2024). Criminal Justice Information Services (CJIS) security policy (Version 6.0). U.S. Department of Justice. FBI CJIS Security Policy.
Federal Bureau of Investigation. (n.d.). CJIS Security Policy Resource Center: Appendices. U.S. Department of Justice. FBI CJIS Security Policy Resource Center.