• Newsletters
  • Webinars
  • Podcast
  • Reports
  • About
    • Advertising
    • Contact us
    • Team
    • Contributors
  • News
  • Frontline
    • Prevention
    • Resilience
    • Response
    • Recovery
    • Learning
  • Leadership
    • Strategy
    • Government
    • Culture
    • Communication
  • People and skills
    • People moves
    • Training
    • Apprenticeships
    • Diversity and inclusion
    • Mental health and wellbeing
    • Life stages
  • Products
    • PPE
    • Vehicles
    • Medical
    • Training
    • Operational
    • Technology
  • Sustainability
    • Infrastructure
    • Transport
    • Built environment
    • Net zero
    • Climate change
  • Technology
    • Command and control
    • Data
    • Hardware
    • Software and apps
    • Digital transformation
    • Mapping and navigation
X (Twitter) LinkedIn Instagram
  • Newsletters
  • Webinars
  • Podcast
  • Reports
  • About
    • Advertising
    • Contact us
    • Team
    • Contributors
LinkedIn Instagram
Emergency Services Times
  • News
  • Frontline
  • Leadership
  • People and skills
  • Products
  • Sustainability
  • Technology
Emergency Services Times
Home > Technology > Humberside fire service learns about cyber incidents the hard way
Technology 7 March 2024

Humberside fire service learns about cyber incidents the hard way

Lanna Deamer7 March 2024Updated:7 March 2024No Comments4 Mins Read
Cyber security. Photo credit: Getty Images Signature
Cyber security. Photo credit: Getty Images Signature

Losing access to data and IT systems through a cyber-attack is every organisation’s worst nightmare but when it comes to the fire and rescue service, it can have a huge impact on public safety. Humberside Fire and Rescue Service shared at a recent event how it was able to deal with a ransomware attack and still keep its fire engines on the road.

ACFO Matthew Sutcliffe and Daniela Thorpe, Head of Digital Service at Humberside Fire and Rescue Service (HFRS) spoke about how this service found itself the victim of a cyber-attack in May 2023 and what they learned from the experience.

The service realised there was a problem when some staff couldn’t access one of the servers dedicated to home fire safety activity and after some investigation, they soon realised that the problem extended to multiple systems. Throughout the day, the impact extended to more and more parts of the organisation..

“The challenge was not just technical but also meant isolating the incident from the organisation’s command and control systems.”

Daniela Thorpe, Head of Digital Services at HFRS.

In terms of damage limitation, the initial focus was on maintaining responsiveness to emergency calls, ensuring that public-facing activity continued functioning despite the incident.

With a workforce of over 1000 staff, one challenge was how to effectively communicate the unusual situation to the teams. Crafting a clear and concise message became paramount. Initially labeled as an ICT incident before transitioning to the more specific term of a cyber incident, the HFRS team avoided explicitly terming it a cyber-attack in its communications. Matthew and Daniela both stressed how effective communication was crucial to the damage limitation process.

The organisation faced the loss of crucial data and the challenge of rebuilding systems. This prompted a re-evaluation of its ICT strategy. Part of this was the decision to adopt a cloud-first approach and that turned out to be a pivotal move to modernise the service’s technology strategy. Daniela acknowledged that while there are higher costs associated with this approach, the trade-off lies in offloading the management burden to the supplier, alleviating the operational stresses they encountered in 2023 and anticipated facing in the future.

“Traditionally, we haven’t prioritised ICT investments effectively, largely due to the fact that such investments are secondary to frontline services. This mindset stems from external directives urging investment in areas perceived as more immediate and tangible.

“The incident serves as a poignant reminder that virtually everything we undertake as an organisation is intricately tied to ICT. From the initial fire call to the subsequent communication with the fire engine upon its return, every step involves information and communications technology.”

Matthew Sutcliffe, Assistant Chief Fire Officer at HFRS.

Matt and Daniela acknowledged that human factors remain a significant vulnerability and emphasised the importance of equipping staff with the knowledge and skills necessary to identify and mitigate potential cyber risks. Recognising the importance of cyber resilience education, HFRS has made substantial investments in training programmes for all staff. Learning from past experiences, the service is committed to reducing the chances of the same issues happening again.

Lessons for the future

HFRS’s journey underscores the need for continuous improvement and adaptability in the face of evolving cyber security threats. The importance of cyber security drills, clear communication, and a forward-thinking approach to ICT investments are essential components for building resilience. Matt encouraged all fire and and rescue services to revisit their business continuity plans, scrutinise the resilience of ICT teams including their capacity to rally support, initiate solutions, and engage in mature conversations.

“My key takeaway from this experience is the realisation that as leaders within organisations, especially in the context of ICT teams, it is crucial to acknowledge and credit their hard work. Behind the scenes, the intricate web of servers and domain controllers is not something that can be simply pulled in at a moment’s notice, there is a lot more to it.”

Matthew Sutcliffe, Assistant Chief Fire Officer at HFRS.

Reflecting on the aftermath, Matt added that it quickly became evident that while the incident was initially perceived as the worst possible scenario, it ultimately became a catalyst for positive change for the service.

The key learnings for the service include recognising the importance of robust business continuity plans, conducting Data Protection Impact Assessments (DPIAs) and establishing clear data retention schedules. By delineating responsibilities and emphasising that data management is a shared responsibility, departments gained a deeper understanding of their role in ensuring operational continuity.

To read similar articles, check out our Technology channel.

Cyber security Fire Fire and Rescue Services Humberside Fire and Rescue Service Ransomware
Share. LinkedIn Twitter Facebook Email
Lanna Deamer

Lanna Deamer

  • View LinkedIn profile

Lanna is Deputy Editor of Emergency Services Times, covering news, interviews and features across the emergency services sector. She also supports the team’s coverage of The Emergency Services Show and The Emergency Tech Show.

All articles by Lanna >

Stay informed

Sign up for our weekly newsletter with news, views and more.

Published by
Ninteen
Quick links
  • Privacy Policy
  • Cookie policy
  • About
  • Back issues
  • Contributors
  • Contact
In assocation with
The Emergency Services Show
The Emergency Tech Show
Certifications
The Emergency Tech Show
LinkedIn Instagram
  • Privacy Policy
  • Cookie policy
  • About
  • Back issues
  • Contributors
  • Contact
© 2026 Emergency Services Times.

Type above and press Enter to search. Press Esc to cancel.

Login