9.3 TDoS, Ransomware & Cyber Incident Response Planning

Key Takeaways

  • Telephony Denial of Service (TDoS) attacks saturate emergency trunks and administrative phone lines with automated, spoofed robocalls to extort agencies, distract dispatchers during violent crimes (swatting/diversion), or exhaust call-taking capacity.
  • Mitigating TDoS requires carrier-level scrubbing, administrative IVR filtering, dynamic overflow routing to partner PSAPs, and deployment of the STIR/SHAKEN cryptographic call authentication framework (Attestation levels A, B, and C).
  • Ransomware attacks against public safety deploy double extortion—simultaneously encrypting CAD/RMS servers and exfiltrating sensitive citizen and personnel data for public leak extortion.
  • Defending against ransomware requires Zero Trust principles, strict network micro-segmentation, and the 3-2-1 backup rule featuring immutable Write-Once-Read-Many (WORM) air-gapped repositories with regular bare-metal recovery drills.
  • NIST SP 800-61 Rev. 2 describes a four-phase incident response lifecycle (Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity), and Rev. 3 (2025) organizes the guidance around NIST CSF 2.0; containment favors isolating systems from the network while preserving evidence, backed by COOP manual fallback workflows.
Last updated: September 2026

9.3 TDoS, Ransomware & Cyber Incident Response Planning

Quick Answer: Modern Emergency Communications Centers (ECCs) face acute cyber threat vectors including Telephony Denial of Service (TDoS) flooding voice trunks with automated robocalls, double-extortion ransomware targeting Computer Aided Dispatch (CAD) and Records Management Systems (RMS), and application-layer DDoS against Next Gen Core Services. Mitigating TDoS requires carrier scrubbing, administrative IVR filtering, dynamic overflow routing, and STIR/SHAKEN call authentication. Defending against ransomware demands Zero Trust segmentation and immutable 3-2-1 backups. When an incident occurs, agencies must execute a Computer Security Incident Response Plan (CSIRP) based on NIST SP 800-61: preparation; detection and analysis; containment, eradication, and recovery (isolating affected systems from the network while preserving volatile evidence where practical); and post-incident lessons learned, backed by robust Continuity of Operations (COOP) manual fallback workflows.


1. Telephony Denial of Service (TDoS) Attacks & Multi-Tiered Mitigation

A Telephony Denial of Service (TDoS) attack is a malicious campaign aimed directly at voice telecommunications infrastructure. Unlike traditional data DDoS attacks that target network bandwidth, TDoS attacks target voice circuits, trunk groups, Session Border Controllers, and human call-taking capacity.

                         ┌──────────────────────────────────────────────┐
                         │         TDoS ATTACK ARCHITECTURE             │
                         └──────────────────────┬───────────────────────┘
                                                │
                 ┌──────────────────────────────┴──────────────────────────────┐
                 ▼                                                             ▼
     [VoIP Botnet / Auto-Dialers]                                  [Spoofed Inbound SIP Calls]
     - 1,000s of automated calls / min                             - Falsified caller ID (ANI)
     - Dead air, prerecorded audio, DTMF                           - Targets 9-1-1 & admin lines
                 │                                                             │
                 └──────────────────────────────┬──────────────────────────────┘
                                                │
                                                ▼
                         [Carrier / Edge Ingress Scrubbing (STIR/SHAKEN)]
                                                │
                       ┌────────────────────────┴────────────────────────┐
                       ▼                                                 ▼
           [Clean Emergency Traffic]                         [Unauthenticated / Floods]
           - Delivered to PSAP CPE                           - Rate-limited / scrubbed
           - Telecommunicators answer                        - Administrative IVR challenge
           - Genuine calls connect                           - Rerouted to overflow PSAP

The Mechanics & Motivations of TDoS

Attackers utilize automated predictive dialers, SIP trunking providers, and global VoIP botnets to bombard a PSAP's emergency 9-1-1 trunks or 10-digit administrative lines with thousands of simultaneous calls. The calls routinely present falsified, spoofed Automatic Number Identification (ANI) to bypass call-blocking filters. When call-takers answer, the calls present dead air, continuous DTMF tone screeching, synthetic automated speech, or prerecorded verbal harassment.

Public safety agencies face three primary attacker motivations:

  1. Financial Extortion: Criminal syndicates launch call floods that saturate emergency trunks, rendering the PSAP inaccessible to the community. The attackers then transmit extortion demands (via email, fax, or phone) demanding ransom payments in cryptocurrency to cease the flood.
  2. Tactical Diversion / Swatting: Attackers flood a communications center with automated calls immediately prior to executing an armed bank robbery, high-value commercial burglary, or violent felony. The flood ties up call takers and saturates radio dispatch channels, delaying citizens from reporting the real in-progress crime and slowing law enforcement response.
  3. Harassment & Retaliation: Hacktivists or disgruntled individuals target specific municipal jurisdictions following high-profile police incidents or controversial civic policies.

Operational Consequences

TDoS creates an immediate life-safety crisis:

  • All Trunks Busy (ATB): Sinks inbound CAMA trunks, ISDN-PRI circuits, or SIP bandwidth, resulting in immediate trunk busy signals for citizens experiencing heart attacks, house fires, or active violence.
  • SBC Resource Exhaustion: Floods Session Border Controllers with connection state requests, degrading processing speeds and delaying call setup times for authentic emergency traffic.
  • Human Fatigue & Cognitive Overload: Telecommunicators become overwhelmed by answering dozens of dead-air calls in rapid succession, increasing error rates and stress.

Multi-Tiered TDoS Mitigation Strategies

Because no single tool can defeat spoofed voice floods, public safety agencies implement a multi-layered defense:

  • Carrier-Level Traffic Scrubbing & Rate Limiting: Establishing service level agreements (SLAs) with telecommunications carriers to automatically detect call spikes, rate-limit abnormal SIP call setup rates, and drop known malicious traffic before it reaches the PSAP demarcation.
  • Interactive Voice Response (IVR) Auto-Attendants on Admin Lines: Routing all inbound 10-digit non-emergency administrative lines through an automated IVR attendant requiring the caller to press a specific telephone keypad digit (e.g., "Press 1 for Dispatch, Press 2 for Records"). Automated autodialers cannot navigate DTMF interactive prompts and drop off, preserving call takers for emergency traffic.
  • Dynamic Overflow & Policy-Based Routing: Configuring NG911 Policy Routing Functions (PRF) and selective routers to automatically redirect overflow traffic to pre-designated partner PSAPs or regional backup centers when incoming queue thresholds are exceeded.
  • STIR/SHAKEN Cryptographic Call Authentication: The deployment of STIR (Secure Telephone Identity Revisited, IETF) and SHAKEN (Signature-based Handling of Asserted information using toKENs, ATIS). STIR/SHAKEN embeds a cryptographically signed digital certificate (a SIP Identity header containing a PASSporT token) into the call signaling to verify that the calling number has not been spoofed.
STIR/SHAKEN Attestation LevelTechnical Verification StandardTrust Level & PSAP Impact
Full Attestation (A)Carrier authenticated the customer AND verified their legitimate right to use the specific telephone number displayed on caller IDHighest Trust: Legitimate subscriber; highly unlikely to be a spoofed robocall
Partial Attestation (B)Carrier authenticated the customer placing the call, but cannot verify if the customer is authorized to use the specific calling numberMedium Trust: PBX enterprise systems; requires monitored handling
Gateway Attestation (C)Carrier originated the call from an unverified international gateway or third-party transit network with no caller verificationLowest Trust: High risk of spoofing; prime target for automated filtering

2. Ransomware in Public Safety & Double Extortion

Ransomware is the most catastrophic cyber threat facing modern public safety operations. Highly organized transnational cybercriminal groups (e.g., LockBit, BlackCat/ALPHV, Royal) specifically target local government and emergency services because the life-safety imperative creates massive pressure to restore systems rapidly.

                         ┌──────────────────────────────────────────────┐
                         │      RANSOMWARE ATTACK PROGRESSION           │
                         └──────────────────────┬───────────────────────┘
                                                │
  1. Initial Compromise   ──► Phishing Email / Exposed RDP / Unpatched VPN Gateway
                                                │
  2. Dwell Time & Spread  ──► Dwells days/weeks; Mimikatz harvests Domain Admin creds;
                              maps network shares; discovers CAD & backup repos
                                                │
  3. Data Exfiltration    ──► Silently steals gigabytes of CJI, CAD audio, juvenile
                              records, and undercover rosters (DOUBLE EXTORTION)
                                                │
  4. Payload Detonation   ──► Destroys local shadow copies; executes bulk encryption;
                              locks CAD database, GIS map services, and RMS servers
                                                │
  5. Extortion Demand     ──► Demands multi-million dollar cryptocurrency payment
                              to provide decryption key and prevent public dark-web leak

The Double Extortion Model

Historically, ransomware simply encrypted local files. Modern threat actors execute double extortion:

  • Prior to encrypting a single server, attackers establish prolonged dwell time (often days to weeks) inside the public safety network. They map network topology, harvest administrative passwords using tools like Mimikatz, and identify database clusters.
  • Attackers silently exfiltrate hundreds of gigabytes of sensitive operational data—including confidential Criminal Justice Information (CJI), child abuse investigation logs, undercover officer rosters, and recorded 9-1-1 audio calls.
  • Attackers then detonate the ransomware payload, encrypting CAD databases, records management systems (RMS), and mobile data servers simultaneously.
  • If the agency refuses to pay because it has reliable backups, the criminal syndicate threatens to publish the exfiltrated CJI on public dark-web leak sites, creating massive public embarrassment, statutory privacy liability, and civil lawsuits.

Multi-Layered Ransomware Defense Architecture

Defending public safety infrastructure requires eliminating single points of failure through Zero Trust engineering:

  • Network Micro-Segmentation: Isolate the CAD/dispatch network from municipal city hall servers, court records, and public Wi-Fi. An infected workstation in the public library or water billing department must never have a routable network path to the 9-1-1 CAD server.
  • Behavioral Endpoint Detection & Response (EDR): Deploy EDR agents across all dispatch consoles that actively monitor for malicious process injection, memory scraping, and unauthorized volume shadow copy deletions (vssadmin delete shadows), terminating malicious processes instantly.
  • Strict Privilege Management: Strip local administrative rights from telecommunicator accounts. Enforce Named Administrative Accounts with Multi-Factor Authentication for all IT maintenance.

The 3-2-1 Backup Rule with Immutability

Public safety agencies cannot survive a ransomware detonation without a resilient, unassailable backup architecture. The gold standard is the 3-2-1 Backup Rule:

  • 3 Copies: Maintain at least three complete copies of all critical data (production data plus two separate backup copies).
  • 2 Media Types: Utilize at least two distinct storage media technologies (e.g., high-speed local disk array and secure cloud repository).
  • 1 Off-Site & Immutable: Keep at least one copy completely off-site and cryptographically immutable.
                   THE 3-2-1 IMMUTABLE BACKUP ARCHITECTURE

       [ Production CAD Server ] ──► (Primary Live Database Operations)
                   │
         ┌─────────┴─────────┐
         ▼                   ▼
  [ Backup Copy 1 ]   [ Backup Copy 2 ]
  Local High-Speed    Off-Site Cloud / Secondary Data Center
  Storage Area Net    ───────────────────────────────────────
  (Rapid RTO)         IMMUTABLE / WORM STORAGE (Write-Once-Read-Many)
                      - Air-gapped logical separation
                      - Cryptographic write-lock (30-day minimum retention)
                      - CANNOT be deleted, encrypted, or modified by
                        compromised Domain Admin credentials or ransomware

Why Immutability Matters: Sophisticated ransomware actively hunts down and purges online network-attached backups (NAS/SAN) before detonating. Immutable storage (Write-Once-Read-Many / WORM) utilizes hardware and cloud cryptographic locks that prevent any user—even a compromised domain administrator—from altering, overwriting, or deleting backup snapshots until a pre-configured retention timer expires. Agencies must perform quarterly automated bare-metal restore drills to verify that CAD databases can be recovered within established Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).


3. Computer Security Incident Response Plan (CSIRP) & The NIST SP 800-61 Lifecycle

When a cyber attack penetrates an emergency communications center, there is no time to improvise. The agency must execute a pre-approved, thoroughly tested Computer Security Incident Response Plan (CSIRP) structured upon the industry-standard lifecycle defined in NIST Special Publication 800-61 (Computer Security Incident Handling Guide).

  ┌────────────────────────────────────────────────────────────────────────┐
  │ 1. PREPARATION: CSIRT, Out-of-Band Comms, Forensics Retainer, Backups  │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │
  ┌───────────────────────────────────▼────────────────────────────────────┐
  │ 2. DETECTION & ANALYSIS: EDR/SIEM Alerts, Triage, Scope & Severity     │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │
  ┌───────────────────────────────────▼────────────────────────────────────┐
  │ 3. CONTAINMENT, ERADICATION & RECOVERY: Isolate, Clean, Restore        │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │
  ┌───────────────────────────────────▼────────────────────────────────────┐
  │ 4. POST-INCIDENT ACTIVITY: Lessons Learned, SOP Updates, Reporting     │
  └────────────────────────────────────────────────────────────────────────┘

The NIST SP 800-61 Lifecycle Applied to 9-1-1

NIST SP 800-61 Rev. 2 groups incident response into four phases: (1) Preparation; (2) Detection and Analysis; (3) Containment, Eradication, and Recovery; and (4) Post-Incident Activity. The six-step "PICERL" list (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) is the SANS model, not the NIST structure. Rev. 3 (April 2025) reorganizes the guidance around the NIST CSF 2.0 functions. The steps below walk through the Rev. 2 phases, with phase 3 broken into its parts:

  1. Preparation: Establishing the Computer Security Incident Response Team (CSIRT) comprising the PSAP Director, IT Director/Local Agency Security Officer (LASO), Operations Supervisor, Municipal Legal Counsel, and Public Information Officer (PIO). Contracts must include an emergency digital forensics retainer. Crucially, the team must establish out-of-band communications (satellite phones, dedicated non-networked copper landlines, or tactical radio channels) because internal VoIP and agency email must be assumed compromised during a breach.
  2. Detection & Analysis: Identifying abnormal behaviors via SIEM log correlation, EDR alerts, or user reports (e.g., dispatchers noting ransom notes on desktop screens). The CSIRT assesses the attack vector, determines the scope of infected systems, and classifies incident severity.
  3. Containment (CRITICAL INCIDENT DOCTRINE): Halting the spread of the attack while preserving digital evidence:
    • The Network Sever Rule: Immediately disconnect physical Ethernet cables or disable virtual network adapters (NICs) on all affected CAD servers and workstations to stop lateral movement.
    • Avoid Powering Down or Rebooting: Unless the incident response plan or forensic lead directs otherwise, personnel should not power down or reboot compromised machines. Powering down flushes the volatile random-access memory (RAM), permanently destroying running malware processes, unencrypted cryptographic keys, and ephemeral network connection artifacts essential for criminal forensics.
  4. Eradication: Identifying and eliminating the root cause of the intrusion. This involves wiping infected drives to bare metal, applying security patches to close exploited vulnerabilities, and executing enterprise-wide password and cryptographic key resets.
  5. Recovery: Restoring CAD, RMS, and telephony systems to operational production from clean, immutable backups. Systems are reintroduced to the network in controlled, isolated phases while being subjected to intensive telemetry monitoring.
  6. Post-Incident Activity (Lessons Learned): Conducting an After-Action Review (AAR) within 14 to 30 days. The CSIRT documents the root cause, evaluates operational response effectiveness, updates SOPs, and implements corrective security controls.

4. Regulatory Reporting & Interagency Notification Workflows

A cyber incident at a 9-1-1 facility triggers mandatory legal and regulatory reporting obligations that must be initiated concurrently with technical containment:

  • Cybersecurity & Infrastructure Security Agency (CISA): CISA encourages voluntary incident reporting now. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) will require covered entities to report substantial cyber incidents within 72 hours and ransom payments within 24 hours, but those duties begin only when CISA's final rule takes effect, so agencies should confirm the current status and any state reporting laws.
  • FBI Cyber Division & IC3: Report the attack immediately to the local FBI Field Office Cyber Squad and the Internet Crime Complaint Center (IC3) to open a federal criminal investigation.
  • State CJIS Systems Agency (CSA) & Fusion Center: If Criminal Justice Information (CJI) is potentially accessed, exfiltrated, or corrupted, the agency must notify the state CSA and CJIS Systems Officer (CSO) immediately to comply with CJIS Policy Area 3.
  • Municipal Leadership & Cyber Insurance Carrier: Immediate notification to city/county executive management and the agency's cyber liability insurance carrier to activate contracted incident response forensics and legal breach-counsel teams.
  • Media & Public Messaging (PIO Coordination): All communications must flow exclusively through the designated Public Information Officer (PIO). Staff must be strictly prohibited from posting about network failures on personal social media accounts. Public messaging must reassure the community that 9-1-1 call-answering and physical emergency dispatch remain operational through manual backup protocols.

5. Continuity of Operations (COOP): Manual Fallback Workflows

When sophisticated ransomware, severe malware, or network failures completely disable CAD servers, mobile data networks, and electronic mapping, emergency response cannot cease. The agency must immediately activate its Continuity of Operations (COOP) manual fallback protocols.

                 CATASTROPHE: CAD & NETWORK COMPLETELY OFFLINE
                                      │
                                      ▼
                  [ACTIVATE COOP MANUAL DISPATCH PROTOCOLS]
                                      │
         ┌────────────────────────────┼────────────────────────────┐
         ▼                            ▼                            ▼
[COLOR-CODED PAPER CARDS]   [STATUS TRACKING BOARD]      [OFFLINE RADIO DISPATCH]
- Blue: Law Enforcement     - Magnetic / Peg Board       - Manual stopwatches for timers
- Red: Fire / Rescue        - Visual apparatus tags      - Verbal status broadcasts
- Green: Emergency Medical  - Tracks on-duty units       - Physical runner conveys cards
- White/Yellow: Admin Svc   - Real-time sector awareness - Dedicated air channels

1. Pre-Printed Color-Coded Paper CAD Cards

Every PSAP must maintain physical caches of pre-printed, multi-part carbon-copy or color-coded incident cards stored at every console position:

  • Blue Cards: Law Enforcement incidents (burglary, robbery, assault, traffic stops).
  • Red Cards: Fire & Rescue incidents (structure fires, brush fires, hazmat, extrication).
  • Green Cards: Emergency Medical Services (cardiac arrest, stroke, trauma).
  • White / Yellow Cards: General municipal service requests, public works, or administrative calls.

Information Logging: The call taker manually writes the reporting party name, call-back number, exact civic address/cross streets, chief complaint, hazard notes (e.g., weapons, hazards), and timestamps (time received, time dispatched) using manual time-stamp machines or synchronized wall clocks.

2. Manual Unit Status Tracking Boards

In the absence of electronic CAD status monitors, dispatchers track field units using physical status boards mounted on the dispatch floor:

  • Magnetic or Peg Tracking Boards: Feature dedicated columns for each beat, sector, battalion, or response district. Physical magnetic tags or color-coded pegs representing specific apparatus (e.g., Engine 1, Medic 4, Patrol Unit 102) are moved across operational status columns:
    • Available in Quarters (AIQ)
    • Available on Air (AOA)
    • Dispatched (DISP)
    • En Route (ENRT)
    • On Scene (SCN)
    • Transporting to Hospital (TRN)
  • Situational Awareness: Provides immediate, visual, whole-room awareness of available emergency resources without electronic dependencies.

3. Offline Voice Radio Dispatch Protocols & Manual Timers

  • Physical Runners: In larger communications centers, designated personnel act as physical "runners," transferring handwritten paper cards from call-taking positions to the appropriate radio dispatch consoles.
  • Manual Safety Timers: The automated unit status timers built into CAD (which flash warning alerts when an officer on a traffic stop or a fire crew inside a burning building has not checked in within 5 or 10 minutes) disappear during a CAD outage. Radio dispatchers must deploy mechanical stopwatches, rotary kitchen timers, or manual paper timer logs to rigorously track unit check-in intervals (every 3 to 5 minutes on violent calls/traffic stops, every 10 to 15 minutes on structure fires).

6. Operational Traps & ENP Exam Watch

  • DO NOT Reboot or Power Down: During an active malware or ransomware incident, the correct containment procedure is to disconnect network cables or disable network adapters while keeping machines powered ON. Powering down wipes volatile RAM memory, destroying running processes, injected code, and encryption keys vital for criminal forensics.
  • TDoS Targets Voice Trunks, Not Bandwidth: TDoS attacks exhaust voice channels, trunks (All Trunks Busy), and telecommunicator answering capacity. Do not confuse TDoS with data-layer volumetric DDoS attacks targeting web bandwidth.
  • STIR/SHAKEN Attestation Levels: Memorize the three tiers: Attestation A (Full) verifies both caller identity and authorization to use the number; Attestation B (Partial) verifies caller identity but not number authorization; Attestation C (Gateway) represents unverified gateway transit.
  • The 3-2-1 Backup Strategy: 3 copies of data, on 2 different media types, with 1 copy stored off-site and made immutable (WORM). Standard online snapshot replication is vulnerable to ransomware and does not substitute for immutable storage.
  • Out-of-Band Communications: Never coordinate incident response or transmit forensic details over agency email or VoIP phones during an active cyber intrusion. Use satellite phones, offline landlines, or tactical radio channels.
Test Your Knowledge

During an active malware outbreak where CAD dispatch workstations show unauthorized file encryption, which immediate containment action best follows NIST SP 800-61 incident response guidance?

A
B
C
D
Test Your Knowledge

Under the STIR/SHAKEN call authentication framework designed to combat telephony spoofing and TDoS attacks, what does "Full Attestation" (Attestation A) signify?

A
B
C
D
Test Your Knowledge

When a catastrophic cyber incident disables the Computer Aided Dispatch (CAD) system and local mapping servers, which manual fallback mechanism ensures telecommunicators maintain accurate status tracking and officer safety timers?

A
B
C
D