Twenty-five years after September 11, 2001, the American fire service will appropriately pause to remember. We will remember the 343 members of the FDNY who died that day, those who subsequently died from World Trade Center-related illnesses, and the thousands of civilians and members of other public safety agencies who were lost. We should remember the extraordinary courage demonstrated that morning.
Remembrance should also compel us to ask a difficult question: What have we learned about preparing for the event we cannot predict?
September 11 changed the American fire service. It influenced incident command, interoperability, intelligence sharing, communications, high-rise operations, terrorism preparedness, regional coordination, mutual aid and the development of the National Incident Management System. However, one of its most enduring lessons may be considerably broader: Catastrophic incidents rarely unfold according to our plans.
The next incident capable of fundamentally challenging the American fire and emergency medical services may not begin with an aircraft striking a building. It may not even begin with a 911 call. It could begin with a keyboard.
A different kind of alarm
In April 2026, the U.S. Environmental Protection Agency (EPA), FBI, Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) issued a joint warning concerning an urgent and ongoing Iranian-affiliated cyberthreat against U.S. organizations, including drinking water and wastewater systems. Federal officials reported exploitation and, in some instances, disruption of operational technology used by these critical infrastructure systems. This was not a hypothetical exercise. It was real, and it was not the first time.
Beginning in late 2023, Iranian Islamic Revolutionary Guard Corps-affiliated cyber actors targeted programmable logic controllers used throughout U.S. critical infrastructure. CISA reported that at least 75 devices were compromised in the United States, including at least 34 devices within the water and wastewater sector. The affected technology is not unique to water utilities; similar programmable logic controllers and industrial control systems are used within energy, transportation, healthcare, manufacturing and other critical infrastructure sectors.
The vulnerability extends well beyond a single campaign or adversary. In 2024, the EPA Office of Inspector General evaluated cybersecurity exposure among 1,062 drinking water systems serving more than 193 million Americans. Ninety-seven systems, collectively serving approximately 26.6 million people, were identified as having critical or high-risk cybersecurity vulnerabilities.
The EPA has also reported that cyberattacks against community water systems are increasing in both frequency and severity. The operational consequences are significant. A successful intrusion may disrupt water treatment, distribution or storage; damage pumps and valves; interfere with operational technology; or potentially manipulate chemical treatment processes.
For a fire chief, emergency manager or operations commander, this is not simply an IT problem. It is an operational readiness problem.
When someone else’s cyberattack becomes our emergency
Consider the operational implications of a significant cyberattack against a metropolitan water system. What happens when companies arrive at a working structure fire and discover inadequate hydrant pressure because portions of the water distribution system have been disrupted? What happens when the same cyber event affects traffic control systems and apparatus response times increase? What happens when hospitals are simultaneously experiencing network disruptions and emergency departments revert to contingency procedures. Now remove or degrade CAD. Then cellular communications. Then portions of the electrical grid.
At some point, what began as a cyber incident becomes an expanding, complex emergency requiring the involvement of fire suppression, EMS, hazardous materials, law enforcement, emergency management, public works, public health, utilities, hospitals, state agencies, federal partners and private-sector infrastructure owners. That is the environment for which the fire service should be preparing.
The future threat is convergence
For much of our history, the fire service has approached risk categorically. We develop procedures and operational doctrine for structure fires, hazmat incidents, active violence, technical rescue, mass-casualty incidents, natural disasters, high-rise fires and terrorism. The emerging operational environment (the future battlespace) is increasingly less accommodating.
The next major incident may combine several hazards simultaneously: a cyberattack, communications disruption, infrastructure failure, unmanned aircraft activity, fire, hazardous materials release, mass casualties, hospital disruption and significant public-information demands. In other words, the future threat may not be one hazard. It may be a complex coordinated attack that quickly overwhelms numerous geographic response areas.
The water sector illustrates the problem particularly well because water is a lifeline infrastructure. Fire suppression depends upon it. Hospitals depend upon it. Communities depend upon it. Industry depends upon it. Other critical infrastructure depends upon it. The same interdependency exists with electrical power, telecommunications, transportation, healthcare, fuel distribution and information technology. A failure in one system can create cascading effects across several others, resulting in far-reaching and dramatic consequences. This should fundamentally influence how fire departments think about catastrophic-incident preparedness.
Technology: Capability and dependency
The fire service of 2026 possesses technological capabilities that would have been almost unimaginable to an incident commander in 2001. Modern operations may rely upon computer-aided dispatch, automatic vehicle location, mobile data terminals, geographic information systems, electronic accountability systems, digital radio networks, electronic patient-care reporting, hospital-status systems, building intelligence, drones, automated staffing systems and real-time operational data. Each provides tremendous capability.
Collectively, however, they also create dependency. That raises an uncomfortable but necessary question for fire service leaders and city or county administrators: Have we become more capable or more dependent?
Technology should enhance command. It cannot become a prerequisite for command.
- If CAD fails, can companies still navigate and respond?
- If MDTs become unavailable, can personnel operate from radio dispatch information?
- If automated accountability systems fail, can an incident management team rapidly transition to a manual accountability process?
- If electronic hospital information systems become unavailable, does EMS have an established regional contingency process?
- If cellular networks become unreliable, do command officers understand their alternate communications pathways?
- If the water system experiences significant degradation, do our operational plans address alternative water supply at the scale required for a major urban fire?
These questions belong in the operations chief’s office along with those in emergency preparedness.
The operations deputy chief’s perspective
From an operational perspective, organizational resilience is ultimately measured by the department’s ability to continue delivering essential services under degraded conditions. The fire service has historically been very good at developing tactical contingencies. We establish rapid intervention teams because firefighters may become trapped. We position backup hoselines in case the first line fails. We establish secondary water supplies. We provide redundant command personnel. We request additional alarms before resources are exhausted. Redundancy is embedded throughout fireground doctrine because experience has taught us that systems fail. We should apply that same philosophy organizationally.
A resilient and agile fire department should be able to function when technology, infrastructure, staffing, communications or external support systems become unreliable. That requires more than an emergency operations plan sitting on a server. It requires organizational alignment and operational capabilities that are developed, exercised, evaluated and reinforced at every level.
The federal government’s recommendations to critical infrastructure operators reinforce this approach. CISA, EPA and the FBI have recommended developing and exercising cybersecurity incident response and recovery plans, maintaining backups of operational and information technology systems, inventorying critical assets, reducing external exposure and conducting cybersecurity awareness training.
Fire departments should consider the operational equivalent:
- What systems are mission-critical?
- What happens when each becomes unavailable?
- What is the manual or alternate process?
- Who has authority to initiate that process?
- How long can the department sustain degraded operations?
Moreover — and perhaps most importantly — have we actually exercised these contingencies?
Preparing leaders, not just plans
There is another lesson from September 11 that deserves renewed attention. No plan can anticipate every circumstance encountered during a catastrophic event. The organization’s responsibility is therefore not simply to produce more plans, procedures or doctrine. It is to develop leaders who can function when the plan no longer adequately describes the problem.
Departments should increasingly incorporate degraded-system operations into command simulations, multiagency exercises and officer-development programs. Remove CAD during an exercise. Eliminate cellular communications. Degrade the municipal water supply. Introduce conflicting intelligence. Create simultaneous incidents. Make hospital capacity uncertain. Force the command team organization to prioritize scarce resources. Then evaluate not simply whether the correct tactical decision was made, but how leaders processed uncertainty.
- Did commanders establish priorities?
- Did they maintain situational awareness?
- Did they recognize cascading consequences?
- Did they communicate intent?
- Did subordinate commanders understand that intent well enough to operate independently?
- Did the organization maintain accountability?
- Did command anticipate the next operational problem?
Those are leadership competencies that will remain relevant regardless of what the threat environment looks like in 2051.
Building the resilient fire department
Preparing for the next unthinkable incident should focus less on predicting a specific threat and more on building resilient and agile organizations. That means maintaining redundant communications and operational systems. It means strengthening relationships with emergency management, law enforcement, hospitals, public works, utilities, public health, cybersecurity agencies and private-sector infrastructure partners before the emergency occurs. It means understanding community lifeline interdependencies and incorporating them into operational planning. It also means recognizing cybersecurity as part of operational preparedness.
Similarly, a fire chief does not need to understand the complicated programming architecture of a municipal water system. The chief does need to understand what happens to firefighting operations if that system becomes unavailable and how to confront the consequences of a complex, coordinated attack. That is an operational responsibility.
2001 — 2026 — 2051
In 2001, few fire officers could have envisioned the operational environment of 2026. Artificial intelligence, unmanned aircraft systems, electric vehicles, large-scale battery energy storage systems, autonomous technologies, interconnected infrastructure, cloud-based public safety systems, mobile nuclear power plants, and cyber threats against municipal infrastructure were not routine considerations at most firehouse kitchen tables.
It is equally unlikely that we can accurately predict the hazards firefighters will confront in 2051. Our responsibility, therefore, is not simply to identify the next threat. It is to build organizations and personnel that are capable of confronting whatever that threat becomes.
Twenty-five years after September 11, perhaps that is one of the most important ways we can honor those who responded that morning: ensuring that the next generation of firefighters and fire officers possesses the organizational resilience, leadership, training and adaptability necessary to confront an incident none of us has yet imagined. Preparedness is not simply a collection of plans. Preparedness is an organizational capability and a leadership responsibility.
In honor of those lost in the September 11 terrorist attacks. Never Forget means Never Forget.
References
- Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, & Federal Bureau of Investigation. (2024, February 21). Top cyber actions for securing water systems. U.S. Department of Homeland Security.
- DefendEdge. (2024, May 1). CISA and partners release fact sheet on defending OT operations against ongoing pro-Russia hacktivist activity.
- Environmental Protection Agency. (2024, May). Enforcement alert: Drinking water systems to address cybersecurity vulnerabilities.
- Environmental Protection Agency. (2026a, April 7). EPA, FBI, CISA, and NSA issue joint cybersecurity advisory to water systems regarding Iranian-affiliated cyberattacks.
- Environmental Protection Agency. (2026b, February 6). EPA actions help safeguard water systems from cyberattacks.
- Environmental Protection Agency, Office of Inspector General. (2024, November 13). Management implication report: Cybersecurity concerns related to drinking water systems (Report No. 25-N-0004).