When your flight hits turbulence, the last thing you want to hear from the pilot is "Give me a minute. I've never handled this before."

Flying feels safe not because problems never happen but because pilots spend thousands of hours preparing for situations they hope they'll never face. When something goes wrong, their response is already built. All they have to do is execute it.

The same principle holds across every profession where mistakes are costly, whether that's medicine, emergency response or manufacturing. The emergency is the time to execute the plan, not build it.

Many businesses haven't made that distinction yet.

The business emergencies nobody practices for

Disruptions rarely announce themselves. They show up during normal operations and force immediate decisions under pressure, usually affecting several parts of the business at once. Systems fail, files disappear, internet outages interrupt workflows, cyber incidents block access and critical applications go dark without warning.

Most business owners understand these scenarios and invest in backups, security tools and software to reduce risk. But preparation often stops at setup instead of extending into how the team responds in the moment.

That gap stays invisible until something breaks. Then, all at once, questions that should be easy to answer become complicated:

  • Who takes charge?
  • What gets restored first?
  • How long will this take?
  • What do we tell customers?

Teams often work through those answers during the disruption itself, which slows decisions, stalls the response and adds confusion right where there should be clarity.

This isn't hypothetical. Ask 22 Texas towns.

In the early morning hours of August 16, 2019, ransomware hit 22 local governments across Texas at the same time. The attackers didn't break into 22 city halls one by one. They compromised a single IT service provider in Rockwall that all 22 entities shared, then used that provider's own remote management tools to push ransomware to every client at once. The collective demand was $2.5 million.

The damage was immediate and very public. Towns like Borger in the Panhandle and Keene, right here in Johnson County, couldn't take utility payments or issue birth and death certificates. Keene's mayor told NPR the town had outsourced its IT entirely and the attackers simply came in through the software provider. For small cities with no in-house IT staff and no response plan of their own, recovery took days and in some cases weeks.

Here's the part worth studying. Lubbock County was hit in the same attack, spotted it on a single computer and isolated it within about an hour. County officials credited one thing: they already had a disaster recovery plan and knew how to execute it. Same attacker, same morning, same ransomware. Completely different outcome.

The state's response tells the same story from the other direction. The Texas Department of Information Resources had a statewide incident response plan built long before that morning. The State Operations Center activated the same day, response teams deployed to all 22 entities and within a week more than half were back to normal operations. Not one of them paid the ransom. That attack is now studied internationally as a model for coordinated response, and every bit of it traces back to a plan that existed before anyone needed it.

The cost of not having one

Two months after the Texas attack, ransomware hit The Heritage Company, a telemarketing firm in Sherwood, Arkansas that had been in business for more than 60 years. The attack locked up the company's accounting systems and mail center, so it couldn't process payments coming in or send statements going out. The company paid the ransom and still couldn't restore its systems.

With no recovery path and no way to make payroll, the CEO gathered roughly 300 employees a few days before Christmas and told them the company was suspending operations. It never came back. The technology failure lasted weeks. The absence of a recovery plan ended the business.

Around the same time, a two-physician medical practice in Michigan closed for the same reason after ransomware encrypted patient records with no usable backups to restore.

None of these organizations were careless, and we'd never suggest they were. In our experience, most leadership teams don't ignore continuity planning because they don't care. They ignore it because other operational problems feel louder, right up until the day a disruption interrupts the business.

The hidden cost of learning during the crisis

When a business is figuring things out during the disruption, the impact spreads quickly because every step requires a decision nobody has thought through. Leaders pause to evaluate options instead of acting, teams wait for direction and progress slows as each action depends on the last decision.

Employees lose time waiting for access or guidance, work stalls across departments and customers feel it next. Response times stretch, communication turns inconsistent and confidence erodes when the business can't operate at its usual pace. Recovery itself takes longer because teams are forced to prioritize while restoring systems at the same time.

The contrast shows up the moment something breaks. One organization moves through defined steps with clear ownership and keeps customers informed. The other builds its response as it goes, and every decision triggers three more questions until a minor disruption becomes something closer to a disaster. Texas already ran that experiment in 2019. Lubbock County was the first organization. Too many small towns were the second.

The difference between disruption and disaster is almost always preparation.

The value of being ready

No passenger expects the pilot to improvise procedure during turbulence. No patient expects the surgeon to make it up mid-operation. The expectation across every high-stakes profession is the same. Preparation happens before anything goes wrong, so when something does, the response is already there.

Businesses that operate this way respond faster, assign ownership clearly and move through recovery without hesitation. Teams don't stop to figure out the next step. They simply take it. Customers experience less disruption because the business doesn't have to stop operating to figure out how to keep operating.

One more lesson from the Texas attack that leadership teams shouldn't skip past: the attackers got in through the towns' own IT provider. Outsourcing your technology doesn't outsource your accountability. Leadership still needs to know who has remote access to your systems, whether your backups are separated from your network and tested, and whether a response plan exists that doesn't depend entirely on any single vendor staying intact. Those are fair questions to ask any provider, ours included, and a provider worth keeping will welcome them.

We've seen what happens when businesses are ready and when they aren't. We've worked with organizations across Dallas-Fort Worth through system failures, ransomware incidents and outages that could have caused serious damage. The ones that came through with their operations and reputations intact weren't necessarily the ones with the most sophisticated technology. They were the ones who had a plan and a partner who knew how to carry it out.

Know where you stand

When a disruption happens, will your business execute a plan or be forced to create one in real time? If you're not sure, that's the answer, and it's a fixable one. The best time to find out where you stand is any day the systems are still running. If you'd like help getting that answer, our First Look process gives leadership a clear read on exactly these questions, from backup separation to vendor access, with no pressure and no jargon attached.

Sources

NPR, "22 Texas Towns Hit With Ransomware Attack In 'New Front' Of Cyberassault" (Aug. 20, 2019)

Texas Department of Information Resources, "Update on the August 2019 Texas Cyber Incident" (Aug. 20, 2019)

The Texas Tribune, "23 Texas cities were targeted in a 'coordinated ransomware attack'" (Aug. 19, 2019)

ProPublica, "The New Target That Enables Ransomware Hackers to Paralyze Dozens of Towns and Businesses at Once" (Sept. 12, 2019)

BleepingComputer, "Hackers Want $2.5 Million Ransom for Texas Ransomware Attacks" (Aug. 22, 2019)

StateScoop, "More identified in Texas ransomware attack as feds urge coordinated response" (Aug. 23, 2019)

NATO CCDCOE Cyber Law Toolkit, "Texas Municipality ransomware attack (2019)"

Trend Micro, "Texas Municipalities Hit by REvil/Sodinokibi Paid No Ransom, Over Half Resume Operations" (Sept. 10, 2019)

Infosecurity Magazine, "US Biz Closes Doors After Ransomware Attack" (Dec. 30, 2019)

KATV, "Shuttering telemarketing company hit by 'cyber attack' wishes employees 'Happy New Year'" (Dec. 2019)

Graham Cluley, "Company held hostage by ransomware shuts down, tells 300 employees to find new jobs" (Jan. 2020)