Publication
National Preparedness Month: Resilience Is a Moving Target
September is National Preparedness Month, and this year the reminder feels especially timely. this year's FEMA theme —"Americans Stand Ready."
Technology is changing faster than most continuity plans.
Artificial intelligence is accelerating development, automation, decision-making, and even cyberattacks. New tools are being adopted quickly. Vendors are changing. Dependencies are shifting. The systems your organization relies on today may look very different by this time next year.
That means preparedness cannot be something we revisit only after an incident.
It should be a regular check-in on whether the organization can still operate when technology, people, facilities, vendors, or critical services are disrupted.
September is a good time to ask one simple question:
If a cyberattack disrupted our organization tomorrow, could we still perform our most important functions?
If You Lead IT or Cybersecurity
- Identify the systems the organization truly cannot operate without.
- Confirm backups can actually be restored, not just that they exist.
- Review how leadership will communicate if email, Teams, or other normal tools are unavailable.
- Understand what systems could be operated manually and what cannot.
If You Manage a Department
- Identify the work your team would still need to perform during a technology outage.
- Document any manual workarounds or alternate processes.
- Know which vendors, systems, and other departments your work depends on.
- Make sure employees understand where to go and who to contact when normal systems are unavailable.
If You Are an Emergency Manager, Business Continuity Lead, or Planner
- Make sure cyber incidents are included in continuity and emergency planning, not treated as a separate IT scenario.
- Identify cascading impacts across facilities, communications, vendors, utilities, staffing, and public-facing operations.
- Confirm that incident response, business continuity, disaster recovery, crisis communications, and emergency management plans actually connect.
- Exercise a scenario where several normal tools fail at the same time.
If You Lead the Organization
- Ask whether leadership knows who makes key decisions during a major cyber disruption.
- Understand which business functions have no realistic manual alternative.
- Identify the outside services and critical infrastructure your organization cannot operate without.
- Run a short leadership discussion around one question: What would stop us from operating if our technology suddenly disappeared?
Why "Having a Plan" Isn't the Same as Being Ready
One of the most common mistakes is assuming that a written plan means you're prepared. Preparedness is not about predicting exactly what the next cyberattack, AI-related disruption, vendor failure, or technology shift will look like. It is about building enough flexibility, redundancy, and confidence that the organization can continue its mission when something unexpected happens.
The technology will keep changing. Your resilience strategy has to be able to change with it.
And September is a pretty good month to find out whether it can.
How Ice Miller Can Help
Ice Miller's Tech, Privacy & Cyber Risk team helps organizations treat cyber resilience as a coordinated business program, connecting incident response, business continuity, disaster recovery, tabletop exercises, AI governance, and executive readiness planning. Contact our team.
This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.
