TL;DR: The Suisun City cyberattack disrupted 911 routing, dispatch, records, and city operations, but essential response continued through alternate systems and regional support. Bay Area businesses should take the same lesson seriously: prevention matters, but tested continuity plans, isolated backups, clear authority, and alternate communications determine whether an incident becomes a prolonged shutdown.

Suisun City’s Cyberattack Turned an IT Problem Into an Operations Problem

The Suisun City cyberattack is a local example of a basic cybersecurity truth: when an organization depends on connected systems, a technical compromise can quickly become an operational crisis.

According to Suisun City’s official incident page, malicious software infected municipal IT systems at roughly 5:45 a.m. on August 7, 2026. The incident affected 911 routing, police and fire dispatch, records, and other city services. Officials shut down the entire IT network to contain the threat and preserve evidence, activated the Emergency Operations Center, and began working with federal, state, and regional agencies.

Emergency services continued. Dispatchers took calls through the Solano County dispatch center while police and fire personnel kept responding. KQED independently reported that officials said emergency calls were answered without interruption. That distinction matters. The network was unavailable, but the mission continued because alternate arrangements existed.

As of August 16, the latest dated update on the city’s public incident page remained August 11. The page continued to describe the investigation as ongoing, public-safety response as active, and some city services as limited while systems were restored. Officials had not publicly identified the malware family, disclosed the initial access method, confirmed whether data was taken, or called the incident ransomware. It would therefore be premature to claim a particular cause or attack type.

Did you know? Verizon’s 2026 Data Breach Investigations Report says 48% of analyzed breaches involved ransomware. It also reports that exploitation of software vulnerabilities became the leading initial access route, accounting for 31% of breaches. Read the Verizon 2026 DBIR.

What Does the Suisun City Cyberattack Mean for a Small Business?

It means a security incident should be planned for as a business interruption, not only as a data-protection problem. A law firm may lose access to case files and deadlines. A construction company may be unable to reach project documents, schedules, or payment records. A medical or professional office may lose phones, email, calendars, or line-of-business software at the same time.

The important question is not simply, “Can an attacker get in?” No organization can reduce that probability to zero. The more useful question is, “Which services must continue if our main network, identity system, or cloud environment becomes unavailable?” That answer should drive the recovery plan.

For another nearby example and a practical comparison of continuity and recovery, read Foster City Ransomware Attack: What Bay Area Businesses Should Learn.

Five Practical Lessons for Bay Area Businesses

1. Define the Minimum Viable Business

Identify the few functions that must operate during the first four, 24, and 72 hours of an outage. Include customer communications, payroll, scheduling, safety, billing, and access to critical records. Assign an owner and a manual workaround to each function. A continuity document that only says “restore the server” is not a business continuity plan.

Good recovery depends on knowing what exists and who owns it. Review IT Documentation for Small Business for the records every company should maintain.

2. Test Backups as a Recovery Process

A successful backup notification does not prove that the business can recover. CISA recommends offline, encrypted backups and regular testing of their availability and integrity. At least one backup copy should be isolated from the production environment so an attacker cannot encrypt or delete it through the same credentials.

Run a restore test that measures how long it takes to recover a representative server, cloud workload, or data set. Compare the result with the downtime the business can tolerate. If the numbers do not match, the recovery design needs work.

PCC’s Disaster Recovery Plan guide explains how recovery priorities, responsibilities, and testing fit together.

3. Prepare Communications That Do Not Depend on the Affected Network

If email, chat, phones, and the contact directory share the same identity or network dependency, one incident may disable every normal communication channel. Maintain an offline call tree, current vendor contacts, an approved customer message, and a separate way for the response team to coordinate. Store the plan where leaders can reach it without logging into the compromised environment.

4. Limit the Blast Radius

Network segmentation, least-privilege access, multifactor authentication, endpoint detection, rapid patching, and separate administrative accounts can limit how far an intrusion travels. These controls do not guarantee prevention. They create friction for the attacker and give defenders more opportunities to detect, isolate, and contain the activity.

Because many intrusions begin with deception or stolen credentials, pair technical controls with the guidance in Social Engineering Attacks: How Businesses Can Recognize and Stop Them.

5. Practice Decision-Making Before the Crisis

An incident response plan should state who can disconnect systems, hire forensic help, notify legal counsel and insurers, communicate with customers, and authorize recovery priorities. A short tabletop exercise exposes unclear authority and missing information before those gaps add hours to a real event.

A proactive provider should help maintain this readiness, not appear only after failure. See What to Expect from a Managed IT Provider.

What Should a Business Do This Week?

Start with one 60-minute continuity review. List the five systems the business cannot operate without, document their dependencies, confirm who can make emergency decisions, and verify the date of the last successful restore test. Then schedule a tabletop exercise around a simple scenario: email, identity services, and file access are unavailable on Monday morning.

This exercise will not solve every cybersecurity problem. It will reveal the highest-impact gaps quickly, which is more valuable than buying another security product without understanding the operational failure it is meant to prevent.

To connect downtime with lost productivity, revenue, and customer service, review The Hidden Cost of Downtime for SMBs.

How Can You Assess Your Readiness?

Start with PCC’s practical self-assessment, then move from identified gaps to documented plans and technical validation. Each resource answers a different question, so using them together is more useful than treating any one checklist as proof that the business is secure.

Identify Likely Gaps

Complete PCC’s Business IT & Cybersecurity Health Check to review 24 essential practices across leadership, access control, devices, networks, email, data protection, backups, continuity, employee readiness, and vendors. Treat every “Not Sure” response as a visibility gap that needs an owner.

This Health Check is a screening assessment. It can reveal missing controls and unclear responsibilities, but it does not scan systems, certify security, or prove that defenses work as intended.

Build the Prevention Baseline

Use The Small Business Guide to Cybersecurity to work through practical prevention measures such as multifactor authentication, endpoint detection and response, employee training, patch management, email protection, and tested backups. Assign an owner and target date to every missing safeguard.

Plan Continuity Before Systems Are Unavailable

Work through the Business Continuity Critical Systems Worksheet to identify essential services, acceptable downtime, data-loss limits, dependencies, recovery priorities, manual workarounds, and accountable owners. The worksheet turns a general concern about downtime into specific recovery requirements that can be tested.

Prepare for the First Hour of an Incident

Keep PCC’s Cyber Incident: First 60 Minutes Checklist with the incident response plan. It covers escalation, evidence preservation, proportionate containment, insurer and legal coordination, communications, and common mistakes that can make an incident worse.

Validate Technical Exposure

For technical validation, consider PCC Penetration Testing. A vulnerability scan identifies known weaknesses and misconfigurations. A penetration test goes further by safely attempting to exploit weaknesses and demonstrate realistic attack paths. Testing should be scoped and authorized, and the results should feed a prioritized remediation plan.

Start here: Not sure whether your business could withstand a similar disruption? Complete PCC’s Business IT & Cybersecurity Health Check to identify gaps in access security, patching, backups, continuity planning, and incident readiness. Then validate the highest-risk assumptions through documented restore tests, tabletop exercises, vulnerability scanning, or penetration testing.

Frequently Asked Questions

Was the Suisun City Incident Ransomware?

Public officials have described malicious software and an ongoing investigation. As of August 16, 2026, the official incident page had not publicly identified the malware or confirmed ransomware. Businesses should avoid treating an unconfirmed label as fact.

Did 911 Service Stop?

The incident affected 911 routing and dispatch systems, but the city said public-safety services remained active. Calls were handled through the Solano County dispatch center, and police and fire personnel continued responding.

What Is Business Continuity?

Business continuity is the ability to keep essential operations running during a disruption. It includes people, communications, alternate procedures, vendors, facilities, and technology recovery.

How Often Should a Small Business Test Incident Response?

Run a focused tabletop exercise at least annually and after major changes to systems, leadership, vendors, insurance, or regulatory obligations. Test critical restores more frequently based on how much downtime and data loss the business can tolerate.

Can an MSP Prevent Every Cyberattack?

No. A capable managed service provider can reduce risk, improve detection, limit damage, and make recovery more predictable. Any provider promising complete prevention is making a claim no responsible security professional can support.

About Professional Computer Concepts

Professional Computer Concepts (PCC) is a trusted Managed IT and Cybersecurity provider serving the Bay Area for over 20 years. We help small and midsize businesses simplify their IT, strengthen security, and modernize operations. Explore our Managed IT Services, Cybersecurity Services, and Cloud Solutions.

From PCC’s Desk

The local lesson is not that every incident can be prevented. It is that essential work must not depend on a single system staying available. Build the fallback, test the recovery, and make decision authority clear before the pressure arrives.

Begin with the Business IT & Cybersecurity Health Check. If you want help validating the results or building a practical remediation plan, let’s talk.

Sources