Endpoint Security Is Not Enough: Why CAD Resilience Has to Start with Architecture

Computer-Aided Dispatch (CAD) systems sit at the center of public safety operations. When a call comes in, CAD helps dispatchers coordinate law enforcement , fire , EMS , field units, locations, priorities, and response activity in real time. That makes CAD more than an application. It is operational infrastructure.
Kevin Ruef
June 9, 2026

Computer-Aided Dispatch (CAD) systems sit at the center of public safety operations. When a call comes in, CAD helps dispatchers coordinate law enforcement, fire, EMS, field units, locations, priorities, and response activity in real time. That makes CAD more than an application. It is operational infrastructure.

As cyber threats against local government and critical infrastructure continue to grow, agencies are right to ask whether their CAD environments are secure. But the better question is broader: if an endpoint, credential, server, network segment, or connected system is compromised, can the agency continue operating?

Endpoint security matters. Workstations, mobile devices, browsers, and user credentials are common entry points for cyber incidents. But endpoint protection alone cannot determine whether a CAD environment can withstand disruption. For public safety agencies, resilience depends on the architecture beneath the system: how it is hosted, patched, backed up, segmented, monitored, isolated, and restored.

Ransomware Has Made Continuity a Public Safety Issue

Ransomware is no longer a theoretical concern for public agencies. Local governments, counties, public safety organizations, hospitals, utilities, and other critical infrastructure entities continue to face sustained cyber pressure. The FBI’s Internet Crime Complaint Center has identified thousands of ransomware incidents affecting U.S. critical infrastructure, and reported losses rarely capture the full operational cost of downtime, recovery, investigation, and service disruption.

For public safety agencies, those operational costs matter as much as the technical incident itself. A ransomware event may begin with one device or one compromised account, but the consequences can quickly expand into dispatch continuity, public-facing services, records access, administrative systems, and interagency coordination.

That is why CAD security should not be evaluated only by asking whether endpoint tools are installed. Agencies should also ask whether the CAD environment can contain an incident, preserve access to critical workflows, recover quickly, and avoid a single point of failure.

The Endpoint Is Often Where the Incident Begins

Endpoints remain a necessary part of public safety operations. Dispatchers use workstations. Supervisors access systems from approved devices. Field personnel may interact with CAD-connected tools through mobile environments. IT teams manage administrative access. Each of those endpoints creates potential exposure.

Endpoint detection and response, antivirus software, firewalls, multifactor authentication, device management, and user training all play important roles. Agencies should not treat these controls as optional.

But endpoint security tools are not the same as operational resilience. Endpoint tools can help detect, block, or isolate suspicious behavior at the device level. They do not, by themselves, guarantee that CAD data is protected, backups are recoverable, patches are current, failover is available, or dispatch operations can continue through a broader infrastructure disruption.

In public safety, the key question is not simply “Was the endpoint protected?” It is “What happens next if the endpoint is compromised?”

Why Legacy CAD Environments Can Increase Recovery Risk

Many legacy CAD environments were designed for a different era of technology operations. They often depend on local servers, locally managed backups, manual patching cycles, agency-owned infrastructure, and constrained internal IT capacity. Those environments can still function day to day, but they may introduce recovery risks when an incident occurs.

The issue is not that every on-premises environment is inherently insecure. The issue is that many agencies are being asked to maintain mission-critical systems under conditions that make resilience difficult: limited staff, aging infrastructure, complex dependencies, infrequent patch windows, and backup strategies that may depend on the same local network as the production environment.

When a CAD system relies heavily on a central on-premises server or locally managed infrastructure, a compromise can create cascading operational challenges. If backups are not isolated, they may be affected by the same incident. If recovery procedures are not tested, restoration can take longer than expected. If failover is limited, agencies may have few options besides manual workarounds.

For public safety, that level of uncertainty is a risk in itself.

A Careful Lesson from Winona County

Recent local government cyber incidents show how disruptive recovery can become, even when services are eventually restored.

Winona County, Minnesota, experienced cyberattacks that affected county network and public-facing systems. According to public reporting, the county restored systems after ransomware-related disruption, declared a local state of emergency, and received assistance from the Minnesota National Guard.

This example should be used thoughtfully. It is not a CAD-specific case study, and it should not be framed as proof that one technology platform would have prevented the incident. The more important lesson is broader: when local government systems are disrupted, recovery is an operational event, not just an IT task.

Public agencies need systems designed for continuity before an incident occurs. That includes clear recovery processes, resilient infrastructure, tested backups, segmented access, rapid isolation capabilities, and a realistic understanding of which systems must remain available during a disruption.

For CAD, those questions become especially urgent because dispatch cannot simply pause while systems are rebuilt.

Why Security Tools Alone Do Not Solve the Problem

It is tempting to think of endpoint security as a stack of tools: antivirus, EDR, firewall, monitoring, logging, and response workflows. Those tools are important, but they are only one layer of the risk model.

CAD resilience is determined by the interaction between endpoint controls and system architecture. If a compromised workstation can reach critical systems too broadly, the environment is exposed. If backups are reachable from the same compromised network, recovery is exposed. If patching depends on manual intervention across aging infrastructure, vulnerabilities may remain open longer than necessary. If restoration requires rebuilding a local server before dispatch operations can fully resume, the agency carries avoidable continuity risk.

A more resilient approach starts by assuming that some incidents will get through. From there, the architecture should limit the blast radius, preserve system availability, and support faster recovery.

That is the distinction between security as a perimeter and resilience as a design principle.

How Cloud-Native Architecture Changes the Risk Model

Cloud-native CAD architecture can reduce several risks that have historically burdened local public safety IT environments. It can shift agencies away from maintaining critical infrastructure on local servers and toward environments designed for redundancy, backup, monitoring, and controlled restoration.

In a modern cloud environment, resilience can be built into the operating model through geographically distributed infrastructure, automated patching, controlled access, backup policies, centralized monitoring, and recovery capabilities. Network segmentation can limit lateral movement. Remote isolation can restrict a compromised endpoint or account without requiring physical intervention on site. Automated updates can reduce exposure windows when vulnerabilities are identified and patched.

For environments hosted on AWS GovCloud, AWS-native recovery capabilities are especially relevant to the discussion. AWS Backup supports continuous backups and point-in-time recovery for certain supported resources, allowing restoration to a selected point within supported retention limits. That does not mean every component of every system is automatically recoverable in the same way. It does mean that cloud-native architecture gives public safety technology providers access to recovery models that are difficult for many agencies to replicate with locally managed infrastructure alone.

The architectural advantage is not “cloud” as a buzzword. It is the ability to design for containment, continuity, and restoration from the beginning.

What Agencies Should Evaluate in a CAD System

When agencies evaluate CAD security, they should look beyond feature lists and endpoint tools. The most important questions are operational:

  • How quickly can the system be restored if an incident occurs?
  • How frequently are backups created, and where are they stored?
  • Are backups isolated from the production environment?
  • What is the expected recovery time objective?
  • What is the expected recovery point objective?
  • How does the system limit lateral movement if an endpoint is compromised?
  • Can access be restricted remotely?
  • How are patches applied?
  • How is infrastructure monitored?
  • What happens if a local server, workstation, network segment, or data center becomes unavailable?
  • How does the system support continuity of operations?

These questions help agencies evaluate whether a CAD platform is merely protected or truly resilient.

Where 10-8 Systems Fits

10-8 Systems approaches CAD security as an architecture and continuity challenge, not simply an endpoint protection challenge.

Because 10-8 Systems is hosted on AWS GovCloud, its CAD environment is built on cloud infrastructure designed for sensitive government workloads. That foundation allows 10-8 Systems to reduce reliance on agency-managed local servers, support resilient system design, and take advantage of cloud-native capabilities for backup, monitoring, redundancy, and recovery.

This matters because public safety agencies should not have to depend on a single local point of failure for mission-critical dispatch operations. A modern CAD environment should help distribute risk, support rapid restoration, and preserve continuity when individual endpoints or infrastructure components are disrupted.

10-8 Systems also supports a security model that can evolve over time. As threats change and compliance expectations mature, cloud-native architecture makes it easier to update, improve, and strengthen the environment without placing the full operational burden on local agency IT teams.

For agencies evaluating CAD modernization, the takeaway is not that endpoint security is unimportant. It is that endpoint security has to be part of a larger resilience strategy.

CAD Security Is Really a Continuity Conversation

Public safety agencies operate in environments where downtime has real consequences. Dispatchers need access to accurate information. Field units need coordination. Leaders need visibility. Communities need services to continue even when technology is under pressure.

That is why endpoint security for CAD cannot be treated as a device-level issue alone. The more strategic question is whether the CAD environment is designed to keep operating, contain disruption, and recover quickly.

The agencies best prepared for the next cyber incident will not be the ones with the longest list of tools. They will be the ones that have designed resilience into the architecture of their mission-critical systems.

For CAD, that is where the conversation should begin.

If your agency is evaluating CAD resilience, recovery readiness, or the risks created by aging infrastructure, 10-8 Systems can help you think through the right questions. Contact us to discuss how modern CAD architecture can support continuity, security, and operational readiness before disruption occurs.

Talk to 10-8 Systems

Kevin Ruef
Kevin Ruef is the co-founder of 10-8 Systems, where he focuses on building cloud-native CAD solutions that support real-world public safety operations. His work centers on helping agencies improve coordination, reliability, and outcomes across law enforcement, fire, and EMS.