Cybersecurity for Small-Department Communications Systems

The radio has always been the lifeline of a fire or EMS agency, but the modern radio is no longer just a radio. It sits on a network, talks to dispatch software, feeds a records system, and reaches back to a vendor over the internet. That connection is what makes the whole thing work, and it is also why a small department now has to think about cybersecurity even if no one on the roster has ever held that title. This guide is written for the radio administrator or chief who is not a security expert and does not want to become one, but who does want a plain list of things to do to keep the lights on.

In this guide
  1. Why communications systems are now cyber-relevant
  2. Why small agencies are targets, and why they are under-resourced
  3. Accounts, passwords, and multi-factor authentication
  4. Keeping systems patched and current
  5. Remote access and network segmentation
  6. Backups, phishing awareness, and your people
  7. Vendor coordination and incident preparedness
  8. A starting checklist

Why communications systems are now cyber-relevant

Twenty years ago the communications side of a small department was mostly hardware you could touch. A base station, some mobiles, a repeater on a hill, and a paper log. If something broke, you drove to it. The systems in service today still do all of that, but they are wrapped in software and connected to networks in ways that are easy to forget once the install is finished.

Walk through a typical small agency and you will find several places where the communications and IT worlds now overlap:

None of this is a bad thing. These connections are why a two-person overnight crew can be alerted in seconds and why a records request can be answered without digging through a filing cabinet. But every connection is also something that has to be protected. The goal of this article is not to scare you off the technology. It is to help you keep the benefits while closing the doors that should be closed.

Why small agencies are targets, and why they are under-resourced

A common and dangerous assumption in a small department is that no one would bother with us. We are too small, too rural, too boring. In practice the opposite tends to be true. Much of the trouble that reaches small public-safety agencies is not aimed at them by name. It is automated and opportunistic, sweeping across the internet looking for any system that is easy to reach, out of date, or protected by a weak password. A small agency is not too small for that net. It is exactly the kind of thing that net is built to catch.

At the same time, small departments carry a few things that make an interruption especially costly:

The resource gap is the hard part. Large agencies have dedicated security staff. A small department often has one person who does IT alongside three other jobs, or a friendly local contractor who set things up years ago and has not been back since. That reality is not a reason to give up. It is a reason to focus. The practices below are chosen because they give a small budget the most protection for the least effort, and because a non-specialist can carry them out or clearly hand them to someone who can.

A note on framing

Everything in this guide is defensive. It describes what to strengthen, not how anything is broken into. If a step here raises a question you cannot answer, that question is worth taking to your vendor or a trusted IT resource. Not knowing is normal. Leaving it unexamined is the risk.

Accounts, passwords, and multi-factor authentication

The single most common way trouble gets into a small agency is not exotic. It is a login. Someone reuses the same password everywhere, that password turns up in a list gathered from an unrelated website, and suddenly a stranger can sign in as if they belonged there. The fixes here are cheap, and they matter more than almost anything else you can do.

Start with the accounts themselves:

Then add multi-factor authentication, often shortened to MFA, wherever the system offers it. MFA means that a password alone is not enough. Signing in also requires a second proof, usually a code from an app on a phone or a physical key. This one step turns a stolen password from a crisis into a nuisance, because the password by itself no longer opens the door. Turn it on for email first, since email is the account used to reset all the others, and then for remote access, dispatch software, and records systems in that order.

Finally, keep a simple record of who has access to what, and review it when someone leaves or changes roles. A departed member whose login still works months later is a loose end that costs nothing to tie off and quite a lot to ignore.

Keeping systems patched and current

Software is never finished. The companies that make your dispatch software, your servers, your radios, and your office computers keep finding and fixing weaknesses, and they release those fixes as updates or patches. An update you have not installed is a known problem left standing. Much of the automated trouble on the internet is looking for exactly that, systems running versions whose weaknesses are already publicly documented and already repaired by the vendor for anyone who bothered to apply the fix.

Staying current does not require you to become an engineer. It requires a habit and a little coordination:

The theme here is simple. Someone should be able to answer the question, for every system we depend on, when was it last updated and who is responsible for the next one. If no one can answer that, the answer is probably longer ago than anyone would like.

Remote access and network segmentation

Remote access is a genuine convenience. It lets a vendor fix a problem without a service call and lets an administrator check a system from home. It is also, by definition, a way in from the outside, so it deserves more care than almost anything else on this list. The goal is not to eliminate remote access. It is to make sure it is deliberate, limited, and watched.

A few practical principles keep remote access from becoming an open invitation:

Network segmentation is the companion idea, and at the concept level it is intuitive. Not everything on your network needs to talk to everything else. The computers used for email and web browsing do not need a direct path to the radio core. A public guest wireless network in the lobby does not need to touch the dispatch server. Segmentation means keeping those worlds in separate rooms, with a controlled door between them, so a problem that starts on an office laptop does not have a clear run straight into your operational heart. You do not have to design this yourself. You do have to ask your IT resource whether it has been done, because a flat network where every device shares one open space is a design choice that quietly raises the stakes of every other risk on this list.

Backups, phishing awareness, and your people

Two of the most valuable protections a small department has cost almost nothing but attention. The first is a good backup. The second is a workforce that recognizes a trick when it sees one.

Backups are what turn a catastrophe into an inconvenience. If your records, configurations, and important files exist in a safe copy, then losing the originals is a bad day rather than the end of the story. A backup only counts if it meets a few conditions:

The human side is phishing and social engineering, which is the polite name for tricking a person into opening a door that no software would have opened on its own. It usually arrives as an email or message that looks legitimate and asks the reader to click a link, open an attachment, hand over a password, or approve something urgently. It works because it targets helpfulness and hurry, two traits every good responder has in abundance.

You do not need a training budget to build resistance. You need a short, repeated conversation:

The report-fast culture is the goal

Almost every avoidable disaster gets worse in the gap between when someone noticed something felt off and when they told anyone. A small department that has made it normal and blameless to raise a hand early has bought itself the most valuable thing in any incident, which is time.

Vendor coordination and incident preparedness

Radio infrastructure is the one area where a small department almost never goes it alone, and that is appropriate. Radio cores, consoles, and station alerting are specialized systems, and the companies that supply them carry a large share of the responsibility for keeping them secure. Your job is not to out-engineer them. Your job is to be an informed, engaged customer who asks the right questions and keeps the relationship active.

Good vendor coordination looks like this:

Incident preparedness is the other half. The worst time to figure out what to do is while it is happening. A small department does not need a thick binder. It needs a short, current plan that answers a few questions any tired crew member could follow in the middle of the night:

Getting help does not have to break a small budget. Many regions have shared resources for public agencies, mutual-aid relationships that can extend to technical support, and partnerships through county or state offices that exist precisely because small agencies cannot each afford a full security staff. Ask your neighboring departments what they use. Ask your regional or state emergency management contacts what is available to agencies your size. A great deal of practical help is free or low cost to those who simply ask, and the asking is the part only you can do.

A starting checklist

None of this has to happen at once. Work down the list at whatever pace you can sustain, and mark real progress rather than chasing perfection.

You will not finish this in a week, and you do not need to. Each item you complete makes the next problem smaller and the next bad day shorter. That steady, unglamorous progress is what good security actually looks like in a small department, and it is well within reach of an agency that decides to start.

Keep your records and procedures organized and secure with RunBoard

Strong security depends on knowing what you have, who has access, and where your plans live. RunBoard helps a small department keep its records, contact lists, procedures, and operational data organized in one place, with individual logins and clear access, so the groundwork this guide describes is easier to maintain than to remember. When your information is orderly, protecting it gets a great deal simpler.