Trending Topics

Building a layered cybersecurity strategy for fire and EMS

As mobile devices become more embedded in emergency operations, departments must protect sensitive data across procurement, deployment and daily field use

Building a layered cybersecurity strategy for fire and EMS.jpg

Chat/AI

By Fire Commissioner (ret.) Jerry Napolitano

Cybersecurity threats are becoming more advanced, persistent and difficult for resource-constrained public safety agencies to stop. Fire and EMS organizations can no longer rely on a basic antivirus program, a firewall or the assumption that a device is secure simply because it is connected to a trusted network.

A recent 2026 Global Threat Landscape Report found that exploited high- and critical-severity vulnerabilities more than doubled year over year, increasing 105% from 71 in 2024 to 146 in 2025. Attackers are looking far beyond the software. They are targeting weaknesses in software, firmware, hardware and the supply chain before devices ever reach an IT department.

| READ NEXT: Cybersecurity for fire departments on a budget

For fire and rescue departments responsible for protecting sensitive patient, personnel, investigative and operational data, the stakes are especially high. Every connected device, from laptops and tablets to in-vehicle systems, can become a potential entry point for a breach.

As fire and EMS agencies rely more heavily on laptops, tablets and other mobile devices in the field, leaders must consider both operational value and cybersecurity risk. These devices may support rig checks, reporting, situational awareness and communication with dispatch, hospitals and command staff, but they also expand the agency’s attack surface. Once technology moves across apparatus, stations, hospitals, public venues and incident scenes, cybersecurity has to be built into operations from procurement through daily use.

No department is immune to cyber threats

The risk of a cybersecurity breach affects every first responder organization that deploys digital devices, whether it serves a large urban center, a small rural community or a suburban area. When firefighters, paramedics, investigators and other first responders carry smartphones, tablets, laptops or connected endpoints into the field, those devices are exposed to an expanding range of threats beyond traditional malware and phishing.

Attackers are increasingly targeting lower layers of technology, including firmware and embedded systems within endpoints, network equipment and connected devices. These attacks are especially concerning because they can persist after a device reset or software reinstallation, bypass traditional endpoint security tools, and leave agencies with limited visibility into whether the device can still be trusted.

Supply chain attacks add another layer of risk. In these scenarios, software updates, hardware components, device images or third-party vendors may be compromised before deployment. In 2024, 30% of all data breaches involved a third-party application or supply chain component, underscoring how significant this attack surface has become. Fire and EMS agencies should view supply chain security not as a one-time procurement checkpoint, but as an ongoing lifecycle responsibility that spans acquisition, configuration, deployment, monitoring, maintenance and eventual disposal.

Many fire and rescue departments lack dedicated IT personnel or operate with only a small IT team, which makes it difficult for leadership to continuously monitor devices for threats. Despite being the third most-targeted sector by ransomware in 2023, more than 80% of state, local, tribal and territorial governments operated with fewer than five employees dedicated to cybersecurity. A 2026 analysis of state and local government cybersecurity programs similarly found that many agencies operate without specialized security staff, leaving little capacity for continuous monitoring of endpoints and mobile devices. For agencies already balancing staffing shortages, budget constraints and rising call volumes, security strategies must be practical, scalable and built into the technology from the beginning.

Understanding the security standards that matter

To address these risks, departments must align their technology decisions with established security frameworks. Three of the most important standards for fire and EMS agencies are National Institute of Standards and Technology (NIST), the Health Insurance Portability and Accountability Act (HIPAA) guidance and the Criminal Justice Information Services (CJIS) Security Policy.

  • NIST provides cybersecurity frameworks and technical guidance that help agencies manage risk across identity, access control, encryption, endpoint security, system integrity and incident response.
  • HIPAA establishes requirements for protecting patient information, including electronic protected health information created, received, maintained or transmitted during EMS operations.
  • CJIS establishes security requirements for agencies that access, process, store or transmit criminal justice information, which may apply to fire marshals, arson investigators and public safety personnel working with law enforcement partners.

In practice, these frameworks increasingly point agencies toward the same operational priorities: verifying user identity, protecting sensitive data, hardening endpoints, monitoring system integrity and managing risk across the full device lifecycle. Multifactor authentication is one example. Rather than trusting a device simply because it is on a network, agencies must verify who is accessing systems using stronger authentication methods, such as a PIN combined with a smart card, fingerprint, facial recognition or another approved factor.

The overlap between NIST, HIPAA and CJIS is especially important for fire and EMS. EMS agencies must protect patient data under HIPAA, while fire prevention or investigative units may also handle criminal justice information subject to CJIS requirements. NIST guidance provides a practical foundation for both environments by helping agencies build consistent controls for authentication, encryption, configuration management, firmware protection, supply chain risk management and incident response.

Building a layered security strategy from the ground up

How can fire and EMS leaders protect their teams from rising cybersecurity threats, align devices with applicable security standards and still deploy technology that meets the realities of field operations? The answer is a layered security strategy that begins at procurement and continues through the full device lifecycle.

Technology selection is one part of that strategy, but it should be paired with clear policies, device management, training and lifecycle planning. Agencies should evaluate whether devices can meet both field-use demands and security requirements over their full lifecycle. This includes support for strong authentication, hardware-backed encryption, secure boot processes, trusted platform modules, BIOS and firmware controls, centralized device management, remote-wipe capabilities and standardized system images.

But hardware alone is not enough. Fire and EMS agencies need protection across every layer of the environment: the user, device, operating system, firmware, applications, connectivity, deployment process and supply chain. Each layer should reinforce the others so that no single point of failure can compromise sensitive data or disrupt emergency operations.

A practical layered model should include three key phases:

  1. Track inventory: Agencies need visibility into the devices, operating systems, firmware, applications, peripherals and connectivity tools used across the fleet.
  2. Harden: Devices should be configured with strong security baselines before they reach the field, including encryption, secure boot, MFA, BIOS or firmware protections, approved system images, patching standards, and access controls aligned with HIPAA, NIST and CJIS requirements.
  3. Detect and respond: Agencies need the ability to monitor for compromise, verify device integrity, and respond quickly when a device is lost, stolen, damaged or suspected of tampering.

This approach is especially important because fire and EMS devices operate in unpredictable environments. They may be left in apparatus, carried into hospitals, used at incident scenes, transferred between shifts or exposed to public spaces where physical-access risks are higher. A layered strategy helps protect sensitive data while allowing crews to stay focused on patient care, incident response and community safety.

Secure in the field

Modern fire and EMS operations depend on mobile technology. Laptops, tablets and connected in-vehicle systems help crews complete reports faster, access patient and incident information, communicate with dispatch and hospitals, maintain situational awareness and keep apparatus ready for the next call. These capabilities can support daily operations, but they also require a security model that reflects how and where the devices are used.

By aligning with HIPAA, NIST and CJIS, agencies can move beyond checkbox compliance and build a more resilient cybersecurity posture. Multifactor authentication helps ensure that only authorized users access sensitive systems. Firmware and supply chain protections help preserve trust in the device itself. Encryption and secure configuration protect data if a device is lost or stolen. Centralized management and lifecycle support help agencies keep controls current as threats and requirements change.

The goal is not to add complexity for first responders. The goal is to make secure operations the default so firefighters, EMTs, paramedics, investigators and command staff can use mobile technology confidently in the field. With a layered security defense model in place, fire and EMS personnel can spend less time worrying about whether their devices are protected and more time delivering timely care and service to the communities they protect.

Fire departments must look beyond local risks and build systems capable of anticipating threats and mobilizing resources nationwide

ABOUT THE AUTHOR

Jerry Napolitano is a strategic accounts manager at Panasonic Connect North America. Prior to his current role, Napolitano was a strategic account executive at Microsoft. Additionally, he previously served as the fire commissioner for the New York Eastchester Fire District, where he oversaw the budget, developed policies and managed the personnel of the fire departments within the Eastchester District. Napolitano earned a bachelor’s degree in electrical engineering from the New York Institute of Technology and is a volunteer for the National Fallen Firefighters Foundation (NFFF).

FireRescue1 contributors include fire service professionals, trainers and thought leaders who share their expertise to address critical issues facing today’s firefighters. From tactics and training to leadership and innovation, these guest authors bring valuable insights to inspire and support the fire service community.

Interested in expert-driven resources delivered for free directly to your inbox? Subscribe for free to any of our newsletters.

You can also connect with us on YouTube, Instagram, X, Facebook and LinkedIn.