Blog
EMS Cybersecurity Insights & Resources
Cybersecurity Budgeting for a 10-Truck EMS Service
A realistic line-item budget for EMS cybersecurity covering MFA, EDR, backups, IR retainer, and training.
Ransomware-as-a-Service and Why Small Agencies Are Now Targets
RaaS has made ransomware a volume business. Small EMS agencies are targets not because they are rich, but because they are reachable.
Evaluating a vCISO Engagement Without Getting Sold Hours
I have sat through enough vCISO pitches to recognize the pattern. Here is how to evaluate based on what they produce, not hours billed.
Public-Safety Cyber Mutual Aid: The Idea Whose Time Has Come
How neighboring agencies can share incident response capacity the same way they share apparatus, with the legal and BAA structure that makes it work.
Apparatus Bay Wi-Fi Is Not Station Wi-Fi: A Network Segmentation Story
Why the network the trucks join when they park needs to be different from the office network the chief uses.
Working With an IT MSP That Doesn't Understand EMS
The operational realities your generalist MSP is missing, the contract addendum that closes the gap, and the boundary between IT and operations.
Wearables on Duty — Smartwatch PHI Risks and Agency Policy
Smartwatches and smart rings on first responders collect data in patient care zones. Agencies need a policy for BYOD wearables, whether issued or personal.
QR-Code Quishing at the Station — Attack Patterns and Practical Defenses
Quishing attacks target fire and EMS stations through fake QR codes on posters and stickers. Here is how they work and what to do about it.
Drone Footage at Fire Scenes: Chain of Custody, HIPAA, and the Cloud Security Default You Did Not Configure
Every fire department I work with has a drone now, maybe two. They bought it for thermal imaging on structure fires and scene overviews on MVCs, plus searc
42 CFR Part 2 in the Field: Substance-Use Disorder Confidentiality That HIPAA Doesn’t Cover
Most EMS agencies know HIPAA cold. They train on it at orientation, build their ePCR workflows around it, audit for it. And then 42 CFR Part 2 walks in thr