kras99 - stock.adobe.com

Cyber recovery plans must cover lost access, not just data

Cyberattacks on Springfield Public Schools and Everett City Hall show what it takes to keep operating when an intrusion cuts off access to core systems.

In early September, an outside group gained access to the network of Springfield Public Schools, the second-largest school district in Massachusetts, and cut staff off from online platforms the district depends on to run its schools. Among them was the system that tells nurses which children need medication or have documented allergies; and without it, Superintendent Sonia Dinnall canceled classes for four days, calling the decision a matter of student safety.

On the day Springfield's closure began, the city of Everett, on the opposite side of the state, closed City Hall to the public after discovering a separate cybersecurity incident on its internal network two days earlier. Police, fire, public works and the city's school kept operating. Essential staff moved to another city building to maintain basic services, while residents continued to pay bills online through third-party systems that remained available.

Whether the school district or the city lost data remains under investigation. What both lost, immediately and visibly, was the ability to operate normally. Cybersecurity planning tends to center on keeping attackers out and keeping data in, yet the damage that closed Springfield's schools came from lost access. The functions each kept running relied on measures already in place, from separate networks to alternate ways of reaching families.

The public sector is often where these disruptions are most visible. What Springfield and Everett illustrate about prevention, operational priorities and recovery planning applies to any organization that relies on networked systems and third-party platforms to do its core work.

What the response revealed

The details worth studying concern what each organization could still do once the attack was discovered.

Springfield's IT team activated the district's cyberincident response plan as soon as it identified malicious traffic on the network. At a Sept. 8 news conference, CIO Robert St. Lawrence said the team's primary work was identifying, containing and eradicating the threats, with restoration of services to follow once that was confirmed. The district told staff to stay off its network and students to stop using school laptops to prevent the malware from spreading, and officials said classroom instruction would return, even if it had to be conducted on paper.

Everett kept essential services running while its IT staff, police department and outside cybersecurity specialists worked to restore the city's internal network. The city had appointed a new CIO in August as part of Mayor Robert Van Campen's push to modernize City Hall's technology, so that investment was already underway when the incident occurred.

Officials have given no indication that the two incidents are connected, and that makes the timing more instructive: two separate organizations lost the use of core systems in the same week, adding to a string of similar incidents across Massachusetts over the past several years. For any enterprise, the useful question is whether it could keep operating through the same kind of disruption.

Limit what an attacker can reach

Keeping attackers out is the first layer of security, and these incidents show why it won't be the last: once an intruder is inside, the damage depends on how much of the organization the intruder can reach.

Everett's school district shows the safety effects of limiting reach. In a statement, Everett Public Schools Superintendent William D. Hart said the breach did not affect the school district, which runs on networks separate from the city's. Confining an intrusion to the environment where it started is the purpose of network segmentation, and Everett's schools, on their own networks, kept operating throughout.

Segmentation works best alongside measures that make it harder for an intruder to move once inside, including multifactor authentication, disciplined access controls and tight limits on administrative privileges. Christopher Smith, director of legislative and external affairs at Massachusetts' Executive Office of Technology Services and Security, said the state leads with those measures in its guidance to municipalities. This is baseline work. The steady run of incidents across Massachusetts suggests it is not yet in place as widely as it needs to be.

Spend against the right failure

Every organization carries more risk than it has budget to address, and the instinct is often to spread resources broadly. A more effective approach is to concentrate on the exposures that would do the most operational damage if exploited.

That starts with knowing what assets the organization has. An inventory is simple, but without one, there is no way to assess which systems are most exposed or which data matters most to daily operations. Springfield's closure hinged on student medical records, with transportation and food data also out of reach of outsiders, and an organization that has mapped its dependencies knows where that single point of failure sits before an incident exposes it.

From there, the order of work is clear: assess where the highest-risk vulnerabilities sit, fix those first and resist the pressure to patch everything evenly. Smith said the state advises municipalities to "prioritize their most critical findings rather than trying to solve everything at once," and the same logic holds for enterprises.

Everett's appointment of a new CIO about a month before the incident illustrates a priority that often loses out at budget time. Investment in the people who do this work is harder to justify in a funding cycle than a new one, and harder to make up for once it has been deferred too long.

Plan for operating without core systems

Recovery is where the gap between planning and reality tends to be widest. In a 2026 survey of 600 senior security decision-makers by incident response firm Sygnia, 99% said their organizations had a formal incident response plan, yet 73% said they would not be fully ready to execute it under real-world attack conditions.

Springfield is a useful example because the district got the fundamentals right. It had a plan and activated it as soon as the threat was clear, and when email systems went down, staff kept families informed through text messages and social media channels. "We have highly skilled educators and teachers who are able to instruct without technology," Dinnall said at the Sept. 8 news conference. That is what functioning continuity looks like under pressure, and every enterprise should ask whether its own team could make the same transition.

Beyond these two cases, a less visible recovery risk sits in the backup environment. When an attacker has reached the network, backups tied to the same credentials or infrastructure may already be exposed.

In a 2024 Sophos-commissioned survey of 2,974 IT and cybersecurity professionals at organizations hit by ransomware, 94% said attackers had tried to compromise their backups, and 57% of those attempts succeeded. Where they did, median recovery costs reached $3 million, eight times the $375,000 at organizations whose backups were unaffected, and just 26% of those organizations fully recovered within a week, compared with 46% of those whose backups held.

Smith said the state emphasizes continually testing and refining incident response plans through simulation exercises and after-action reviews. Rehearsal is what shows whether a plan still holds when the network is down, the phones are offline, and the team is making decisions under pressure.

Three priorities belong at the top of any organization's recovery preparation. The first is testing the plan under conditions that resemble a real attack, including the loss of email and phones. The second is verifying that backups are isolated from the credentials and infrastructure that an intruder is most likely to reach, and the third is deciding in advance how the organization will communicate internally and externally when its normal channels are compromised.

The real measure

Springfield set Sept. 14 as the date for students to return, with district staff first reviewing records on allergies, medications and transportation. In Everett, Van Campen has pledged to strengthen and secure the city's systems, building on modernization work his administration began before the incident. Both organizations responded with competence and adaptability under difficult circumstances.

The lessons from both cases follow a specific order. The first is knowing which systems and data the operation depends on, and the next is separating the most critical functions from the general network and directing limited resources toward the exposures that pose the greatest operational risk. The last is a recovery plan that assumes full compromise and has been tested before an incident occurs.

Prevention decides whether an attacker gets in. Preparation determines what the organization can still do while an attacker is inside. Recovery planning devices how quickly it gets back to normal once the attacker is out.

Scott Thompson is a site editor for TechTarget's Data Technologies group.

Dig Deeper on Data Backup