Blog
EMS Cybersecurity Insights & Resources
Evaluating a vCISO Engagement Without Getting Sold Hours
I have sat through enough vCISO pitches to recognize the pattern. Here is how to evaluate based on what they produce, not hours billed.
Wearables on Duty — Smartwatch PHI Risks and Agency Policy
Smartwatches and smart rings on first responders collect data in patient care zones. Agencies need a policy for BYOD wearables, whether issued or personal.
Drone Footage at Fire Scenes: Chain of Custody, HIPAA, and the Cloud Security Default You Did Not Configure
Every fire department I work with has a drone now, maybe two. They bought it for thermal imaging on structure fires and scene overviews on MVCs, plus searc
Pre-Plan Security: The PHI-Adjacent Data Most Fire Departments Leave Unlocked
Alarm codes, Knox box combinations, occupant medical conditions, and hazmat locations live in your pre-plan system with weaker access controls than your ePCR. Here is the fix.
The cPanel Bug That Compromised Thousands of Sites and Why Your Agency Should Care
CVE-2026-41940 in cPanel has compromised thousands of servers. Here is why your fire or EMS agency needs to check its hosting provider and what to ask.