CISA’s Billy Bob Brown, Jr., shares the steps, tools and planning models every agency should be using.
Nicole McGinnis, APCO chief counsel and director of government relations, spoke with Billy Bob Brown, Jr., executive assistant director for emergency communications at the Cybersecurity and Infrastructure Security Agency (CISA) about evolving cyber threats and practical steps public safety communications professionals can take to strengthen network resilience.
CAN YOU TELL US A LITTLE ABOUT YOUR BACKGROUND AND THE EXPERIENCES THAT HAVE SHAPED YOUR VIEWS ON COMMUNICATIONS SECURITY?
In 2008, I joined the Department of Homeland Security after retiring from a distinguished career in the United States Marine Corps. Shortly after beginning work in CISA’s Emergency Communications Division, meetings with public safety communications stakeholders shaped my view on the vital need for a unified approach to communications security across state and local governments. Since then, it’s clear to me that if one is vulnerable, all are vulnerable.
WHAT SECURITY RISKS WARRANT MORE ATTENTION?
Ransomware makes headlines every day — criminals lock up systems and demand payment. But the real issue is our mindset. In public safety, too many still treat technology with a set-it-and-forget-it attitude, assuming equipment stays secure because it once was. That outdated thinking leaves the back door wide open, and nation-state adversaries count on exactly that. Modern threats demand modern vigilance. It’s time we update both our tools and our mindset.
WE SEE A LOT OF ATTENTION ON CYBERSECURITY AND EMERGING TECHNOLOGIES, BUT WHAT RISKS DO LEGACY TECHNOLOGIES PRESENT?
Many older systems still in use today were never built for internet-connected add-ons like remote access or downloaded drivers. Every new connection is like poking a tiny hole in a sailboat — it may seem small, but it creates real risk. That’s why public safety and cybersecurity professionals need to work closely together.
WHAT STEPS CAN PUBLIC SAFETY PROFESSIONALS TAKE TO REDUCE OR MITIGATE THESE RISKS AND STRENGTHEN THE RESILIENCY OF THEIR COMMUNICATIONS NETWORKS?
To mitigate the risks of threats, CISA strongly promotes using complex passwords, enabling multi-factor authentication, avoiding unknown links and keeping software updated. Through our partnership with SAFECOM, we support emergency communications practitioners with resilience planning grounded in the PACE model: Primary, Alternate, Contingency and Emergency. It reinforces a simple best practice: build redundancy and avoid putting all your eggs in one basket.
WHAT IS THE RELATIONSHIP BETWEEN INTEROPERABILITY AND CYBERSECURITY, AND HOW DO YOU SEE IT EVOLVING AS WE TRANSITION TO NEXT GENERATION 9-1-1 (NG9-1-1)?
When we lose operability — the basic ability to move information — we lose interoperability. Cybersecurity is a foundational part of keeping information flowing. As NG9-1-1 rolls out and more public safety communications depend on internet protocol (IP)-based systems, our exposure to cyber adversaries grows. That means cybersecurity isn’t someone else’s job — it’s everyone’s job. We are all cyber defenders.
HOW SHOULD PUBLIC SAFETY PROFESSIONALS CONSIDER THE RELATIONSHIP BETWEEN PHYSICAL SECURITY AND CYBERSECURITY?
Physical access to critical components of a system is the first thing cyber adversaries look for — it’s their “easy button.” Public safety professionals need to recognize how tightly physical security and cybersecurity are linked. Not every adversary is seeking a cyber effect; sometimes the goal is a physical one. Something as simple as manipulating a thermostat can overheat equipment and cause a shutdown or worse. The cyber-physical nexus is real, and we must be cautious about what we connect for convenience.
WHAT ARE YOUR MOST IMPORTANT PRIORITIES FOR CISA FOR THE REMAINDER OF THE YEAR, AND HOW MIGHT OUR MEMBERS SUPPORT THESE EFFORTS?
Aligning how all of public safety sees government — as a whole-of-nation enterprise — is essential. Local, county, state, territorial, tribal, and federal partners must work together with a shared focus on resilience and PACE planning. Together, we can evolve to the new technologies ahead, even with the challenges they bring. The safety of our citizens requires it, and the safety of public safety officers demands it.
CAN YOU SHARE A LITTLE ABOUT THE KINDS OF RESOURCES CISA HAS FOR PUBLIC SAFETY COMMUNICATIONS PROFESSIONALS?
CISA partners closely with public safety through multiple practitioner-driven forums where responders help shape best practices, guidance and tools. Our public-facing website hosts a wide range of resources — from cybersecurity toolkits to emergency communications guidance — that support public safety communications professionals across the nation.
Public safety professionals can explore resources such as the SAFECOM library, the National Council of Statewide Interoperability Coordinators (NCSWIC) reports archive and the Emergency Services Sector resilience webinar series.
IF YOU COULD SHARE ONE PIECE OF ACTIONABLE ADVICE WITH PUBLIC SAFETY PROFESSIONALS, BASED ON YOUR EXPERIENCE, WHAT WOULD IT BE?
CISA has Emergency Communications Coordinators located across the country, ready to support your critical mission and complex challenges in public safety each day. Reach out to the coordinator closest to your area to help strengthen resilience.
([email protected]) is Chief Counsel and Director of Government Relations for APCO International.
