Step 10 · Data, Integrations, and Cybersecurity

Before going live, understand what information the system collects, where it goes, what other systems it connects to, who owns the data, who can access it, and what happens when something fails.

Full guide planned · 12 min read
Step 10 · Data, Integrations, and Cybersecurity

The short version

Every new system adds data somewhere, a connection to something, and another account to manage. Ask these questions before go-live, while you still have leverage, rather than after an incident when you are asking them under pressure. This is the operational edge of cybersecurity rather than the whole subject — the Cybersecurity for Fire & EMS Leaders track carries the rest.

See it applied

Go deeper

Questions to ask your vendor

  1. What data does the system collect?
  2. Who owns it?
  3. Where is it stored?
  4. How can we export it?
  5. What systems does it connect to?
  6. Is there a documented API?
  7. Who has administrative access?
  8. Does it support MFA?
  9. What happens if the vendor experiences an outage?
  10. What happens if our network is unavailable?
  11. What happens if the vendor is compromised?
  12. How will we retrieve our data if we leave?

This is a reading list, not a guide

Everything above was published by someone else, and is here because it is the clearest treatment of the subject we could find and verify. The Hub’s own guide to this topic is still being written. If you know a better source than the ones listed, that is worth telling us before it is.

Send a note