The Containment Era is here. →Explore

Executive Summary

In June 2024, Crisis24 confirmed that its OnSolve CodeRED platform—used by state and local governments, police, and firefighting agencies—suffered a cyberattack disrupting emergency notification systems nationwide. Attackers gained unauthorized access to critical infrastructure, resulting in outages that hindered the timely dissemination of emergency alerts and public safety updates. While the investigation is ongoing, the breach demonstrates significant operational risks associated with service provider platforms in the public safety sector, impacting communities’ emergency preparedness and response effectiveness.

This incident underscores growing threats targeting third-party vendors in critical sectors, where cyberattacks exploit platform dependencies to cause widespread and immediate disruption. With increasing regulatory scrutiny and a surge in ransomware and extortion campaigns against essential services, organizations must reassess supply chain, segmentation, and incident response controls to maintain operational and compliance resilience.

Why This Matters Now

The attack on OnSolve CodeRED reveals the vulnerability of emergency communication infrastructure to cyber threats, exposing gaps in supplier risk and operational continuity. As attackers target the digital backbone of public safety, organizations must urgently strengthen third-party security controls and ensure robust segmentation and monitoring to protect essential services.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exposed weaknesses in third-party risk management and segmentation, suggesting insufficient network, data, and identity controls required for frameworks like NIST, HIPAA, and PCI DSS.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix CNSF controls—such as Zero Trust Segmentation, East-West Traffic Security, Egress Security & Policy Enforcement, Encrypted Traffic, Inline IPS, and real-time threat detection—would have materially curtailed attacker movement, prevented unmonitored outbound channels, and isolated critical workloads to limit disruption. These controls enable proactive detection of anomalous access, enforce least-privilege access, and allow rapid response to threatening behaviors.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocks unauthorized inbound access to sensitive cloud applications.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevents privilege escalation from leading to access of sensitive segments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detects and blocks unauthorized internal traffic lateralization.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Disrupts or blocks outbound connections to non-sanctioned control servers.

Exfiltration

Control: Encrypted Traffic (HPE) & Inline IPS (Suricata)

Mitigation: Detects and inspects encrypted traffic for signs of data exfiltration.

Impact (Mitigations)

Rapid detection and response to sudden anomalous activity reduce downtime and system impact.

Impact at a Glance

Affected Business Functions

  • Emergency Alert Notifications
  • Public Safety Communications
Operational Disruption

Estimated downtime: 30 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Personal information of CodeRED users, including names, addresses, email addresses, phone numbers, and passwords, was accessed by unauthorized parties.

Recommended Actions

  • Implement Zero Trust Segmentation to strictly isolate critical workloads and emergency response systems.
  • Deploy Cloud Firewall and East-West Traffic Security for continuous inspection and blocking of lateral movement between cloud resources.
  • Enforce granular egress policies and FQDN filtering to prevent unauthorized outbound traffic, command and control, or shadow AI activity.
  • Utilize Inline IPS and encrypted traffic inspection to detect exploits and unauthorized data exfiltration—even in encrypted channels.
  • Enable comprehensive, real-time visibility and threat detection across all cloud accounts and workloads to accelerate incident response and reduce disruption.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image