For Greater Sacramento organizations, this is a nearby example rather than a distant case study. On August 7, malicious software was detected on the municipal network of Suisun City, roughly an hour from Sacramento in Solano County. To contain the threat and preserve evidence for investigators, the city shut down its entire IT network, rerouted 911 through Solano County dispatch, declared a state of emergency, and engaged the FBI, DHS, and California Office of Emergency Services. Weeks later, multiple departments were still dealing with service disruptions.
Suisun’s response is more instructive than the attack itself. The city kept emergency services running, contained the incident, and brought in federal and state resources. Even with early containment, the recovery can still stretch for weeks or months.
What the Public Record Shows
What the public record confirms: the city’s systems were compromised by malicious software, officials received demands from those responsible, and the FBI, DHS, and Cal OES all became involved. Suisun City has not publicly identified the malware family, the attacker, how the network was accessed, or what those demands were. City Manager Prebula has said they may never know why the city was targeted.
The documented sequence: malware detected at 5:45 a.m. on August 7; network shut down to contain the threat and preserve evidence; state of emergency declared August 8; City Council convened in emergency closed session on August 11, with Councilmember Princess Washington stating publicly, “Our records are hostage”; closures extended through August 14, then again on August 17 with no stated reopening date. Emergency services remained operational throughout, with 911 routed through Solano County dispatch and police and fire continuing to respond.
A note on scope: Vision Quest has no involvement in Suisun City’s investigation and no visibility into its internal security environment. The analysis in this article is based only on publicly reported operational impacts and established cybersecurity practices.
Containment Did Not Mean Rapid Recovery
Suisun City shut down its network, maintained emergency services through contingency arrangements, and brought in federal and state investigators. Significant operational disruption persisted across departments well after the initial containment response.
Containment was only the beginning of the recovery. A network shutdown limits further spread and preserves forensic evidence. It also takes systems, services, and workflows offline simultaneously. Without a tested recovery sequence, teams have to figure out restoration priorities while systems are already down and leadership is actively managing the incident.
Foster City, Pittsburg, Solano County’s library system, and NorthBay Health have all seen significant cyber incidents in the past two years, ranging from extended service outages to fraud and unauthorized network access. Verizon’s 2026 Data Breach Investigations Report found ransomware involved in 48% of breaches analyzed, up from 44% the prior year.
The gap worth closing: Recovery sequencing should be worked out before systems go down.
What Goes Offline When the Network Does
A network shutdown can take accounting, authentication, phones, ERP access, and line-of-business systems with it. For a manufacturer, that may mean receiving and shipping. For a medical practice, patient records. For a law firm, access to case files. Backup systems deserve their own honest assessment: not just whether they exist, but whether they can actually rebuild production from a point before the attacker first had access. Which of those functions could your organization operate without, and for how long?
The August 18 reopening of Suisun City’s water counter is a useful illustration. In-person payments resumed, but only by cash or check, because card processing remained unavailable. Systems come back at different times, often with manual workarounds filling the gaps in between. Degraded-mode operations need to be planned in advance. Otherwise they get improvised, and how well they hold depends on decisions that weren’t made under pressure.
These scenarios apply across the Greater Sacramento commercial base: medical practices, legal offices, manufacturers, construction companies, nonprofits, accounting firms, and professional services firms. For organizations holding patient records, financial data, or client files, a network outage creates a second layer of pressure alongside the recovery effort: notification obligations, regulatory timelines, and the exposure of failing to deliver services clients depend on.
Cyber insurance plays an active role in incident response through forensic support, vendor networks, and legal coordination, and it shapes which financial options are available during recovery. Practically, that means knowing before an incident who makes the first calls: to legal counsel, to the insurer, to key vendors, to clients. Those conversations happen under pressure, and their quality reflects decisions made well beforehand.
Worth testing before you need to know: Decisions made in the first hours of an incident are much harder when preparation for them starts on day one of the recovery.
What to Evaluate Before You Find Out the Hard Way
- You have not mapped which systems, workflows, and communications functions would be unavailable in the first 24 hours of a full network shutdown, or which could continue through contingency arrangements.
- No one in your organization has documented who contacts legal counsel, insurance, key vendors, and clients in the first hours of an incident.
- Your organization has fewer than five IT staff and no dedicated security function or external monitoring.
- Critical systems including ERP, accounting, patient records, email, shared files, and line-of-business applications run on a flat network without segmentation between departments or functions.
- You have not tested a full backup restoration in the past 12 months, or you are uncertain whether your backup retention is sufficient to restore from a clean pre-intrusion state.
- Your most recent security assessment is more than 18 months old, has never been performed, or has not included an independent review of whether existing controls are functioning as intended.
- Vendor or contractor access to internal systems is not regularly reviewed, scoped, or revoked when engagements end.
- You carry cyber insurance but have not reviewed current coverage terms, exclusions, or response obligations in the past year.
The Suisun City Incident, in Context
The Suisun City incident is relevant to Greater Sacramento organizations because of what its public record actually shows. A city that contained the incident, maintained emergency response, and brought in federal and state help is still working through a recovery that city officials have said could extend for months. The useful lesson is in what recovery actually looks like: partial reopening, cash-only counters, and departments still limited weeks later. The incident itself is only the starting point.
For organizations with fewer resources or no tested recovery plan, the same scenario would be harder to absorb. The operational exposure visible in Suisun’s public record is not unique to cities. Medical practices, legal offices, manufacturers, construction companies, nonprofits, and professional services firms throughout Greater Sacramento often share the same network dependencies without having mapped what an extended outage would actually look like.
Assess Your Exposure Before the Incident Arrives
Vision Quest helps Greater Sacramento organizations understand where a serious cyber incident would disrupt operations, how current controls would respond, and what should be addressed before recovery is happening under pressure.
Request a Security Assessment

