Guest Column

Arms: The Blind Spot in Your Emergency Operation Center

Posted

Here's an honest question: your traffic signals go dark citywide. Your water utility loses visibility into flow and pressure data across the distribution system. A ransomware note is sitting on every workstation in every city department. It's 2 a.m. Who's in your Emergency Operations Center, and do they know what to do?

The Structural Problem

For most mid-size and small jurisdictions, the answer is uncomfortable. The person who understands the attack — your IT Director — isn't part of the command staff. They're a phone call away, if they're reachable at all. If they're on vacation, out sick, or already fighting the fire on the technical side, the Incident Commander is making decisions about a cyber incident with no cyber expertise in the room. That is not a hypothetical gap. It's the default state of emergency management in most of the country today, and it's becoming a more dangerous one every month.

This Isn't Theoretical Anymore

In November 2023, an Iran-affiliated group calling itself CyberAv3ngers broke into a Unitronics programmable logic controller at the Municipal Water Authority of Aliquippa, Pennsylvania, forcing operators to switch a pressure-regulating pump station to manual control. CISA and the FBI issued advisory AA23-335A in response. It wasn't an isolated event. By 2026, the same threat actors had expanded their targeting to Schneider Electric and Siemens equipment alongside the original Rockwell Automation systems, and a coordinated attack hit roughly 30 water systems in Minnesota — prompting CISA to update its advisory (AA26-097A) with expanded detection guidance. The pattern across every one of these incidents is the same: small and mid-size utilities running internet-connected industrial control systems, often with weak or default credentials, are the softest targets in the country.

Energy isn't exempt either. In September 2026, CenterPoint Energy, the utility serving roughly 7 million customers across Texas, Indiana, Minnesota, and Ohio, including Houston has disclosed in an SEC filing that an unauthorized party had accessed customer data through one of its external-facing systems. To be precise about what happened: this was a data breach, not an operational shutdown, and CenterPoint says electric and gas delivery were not disrupted. But it puts a Fortune 500 utility with mature security resources on the list of organizations breached in 2026, and it should end any assumption that "someone else" is handling this. If a company with CenterPoint's resources can be compromised, the water district or public works department running on a fifteen-year-old SCADA system and one overworked IT employee is not in a stronger position.

Untested Plans and the AI Factor

Most jurisdictions never built a cyber annex into their Emergency Operations Plan. Many that did write it once, filed it, and haven't touched it since. Untested annexes have unassigned roles, outdated contact lists, and no clear answer to basic questions: Who declares a cyber incident? Who talks to the public, and when? At what point does a cyber event trigger activation of the EOC at all? A plan that's never been exercised is a plan that will fail exactly when it's needed.

Layered on top of that is artificial intelligence, which is quietly changing the threat on both sides of the fight. Threat actors are already using AI to accelerate reconnaissance, generate more convincing phishing content, and speed up exploit development — lowering the skill and time required to hit a target. Emergency managers and IT leaders need to understand that shift, not because AI itself is the emergency, but because it's compressing the time between "vulnerability discovered" and "systems compromised." A cyber annex written five years ago wasn't built with that pace of attack in mind.

Fixing the Comms Gap Between EM and IT

The fix starts with a structural change: a cyber subject matter expert belongs on the command staff, not as an afterthought consulted after activation, but as someone with a defined role in the Incident Command structure before an incident ever happens. That means emergency managers and IT leadership need to be in the same room well before 2

a.m. - building relationships, agreeing on triggers and terminology, and understanding each other's constraints.

If your jurisdiction doesn't have a cyber annex, start one today. You don't have to build it alone. Two state agencies offer a slate of no-cost courses built specially for this, funded through the National Cybersecurity Preparedness Consortium. Texas A&M Engineering Extension Service (TEEX) and University of Texas – San Antonio (CIAS) offer a slate of no-cost courses built specifically for this gap, funded through DHS/FEMA and delivered through the National Cybersecurity Preparedness Consortium:

·       AWR366-W (CISA), Developing a Cybersecurity Annex for Incident Response — walks a jurisdiction through building a cyber annex from scratch.

·       MGT362 (CISA/TEEX), Community-Level Cybersecurity Planning and Training Gap Analysis — a two-day, instructor-led session for identifying exactly where your plans and training fall short.

·       MGT384 (TEEX), Preparing for Cyber Attacks and Incidents — brings emergency responders, SLTT government staff, and critical infrastructure operators together to work through cascading impacts.

·       MGT456 (TEEX), Integration of Cybersecurity Personnel into the EOC for Cyber Incidents — a scenario-based course built to get IT and emergency response personnel practicing together, which is precisely the muscle memory most jurisdictions lack.

·       PER371 (TEEX), Cybersecurity Incident Response and Management — a hands-on, in-residence course using NIST 800-61r2 and integrating the Incident Command System into cyber response.

None of these courses cost your jurisdiction anything beyond staff time. You can always host a class if you don’t see one on the schedule in your area.

If you already have an annex, the next step is simple and non-negotiable: host a tabletop exercise. Test your cyber hygiene, test your annex, and find the gaps while the stakes are a conference room discussion instead of a real outage. Do it annually, not once.

Know Who to Call

In Texas, the Texas Cyber Command (TXCC) is your state-level partner. Established by House Bill 150 in the 89th Legislature and codified in Government Code Chapter 2063, TXCC consolidated the state's cybersecurity functions — incident response coordination, digital forensics support, a 24/7 threat intelligence center, and a cybersecurity hotline — into a single authority for state and local governments. It isn't optional to ignore: under Government Code Section 2063.103, state and local government employees and officials with access to government information resources are required to complete a certified cybersecurity training program annually.

At the federal level, the Cybersecurity and Infrastructure Security Agency (CISA) remains the front door for threat intelligence, advisories, and incident response support for critical infrastructure of every size.

Build Mutual Aid Now, Not During the Incident

Fire departments and police agencies have relied on mutual aid compacts for decades because no single jurisdiction can carry every resource it might need. Cybersecurity should be no different. Cyber professionals and emergency management leaders should be negotiating mutual aid agreements today, before an incident, not during one - so that a small jurisdiction whose only IT resource is unavailable has somewhere to turn immediately. Leverage your local school district technology team or large corporations operating in your area.

The attack surface is growing. The adversaries are patient, well-resourced, and increasingly assisted by AI. The gap between IT and emergency management is well documented and, in most places, still unaddressed. This is not a distant risk. It's already hit water utilities, it's already hit a major Texas energy provider, and CISA has issued the advisories to prove it.

So, ask yourself the honest question again: if it happens tonight, are you ready? If the answer is no, or you're not sure, the training is free, the annex needs writing, and the phone call to your cyber counterpart hasn't been made yet. Today is the day to make it.

Editor’s Note: The above guest column was penned by Jason Arms, a consultant to public and private entities on emergency and cybersecurity readiness. The column appears in the Rio Grande Guardian with the permission of the author.

About Jason Arms

Jason Arms brings 25-plus years of experience spanning information technology, law enforcement, radio communications, fire service, and emergency management. He has deployed across Texas, serving in emergency management coordination roles for city and county jurisdictions, as a police sergeant, and as deputy manager for large-scale interoperable radio communications systems supporting thousands of public-safety users across a multi-agency region. He has also led municipal IT, emergency management, and communications operations in Texas.

Arms is a member of the National Emergency Management & Response IMT, and actively consults with public and private entities on emergency and cybersecurity readiness. He is also an active member of a statewide amateur radio emergency communications team organized by the Texas Division of Emergency Management (TDEM).