September Is National Preparedness Month: What Are You Waiting For?
- Michael Sage
- 17 hours ago
- 5 min read
Imagine walking into work tomorrow morning and discovering that something your organization depends on simply isn’t available. Maybe your network is down. A cyber incident has locked employees out of critical systems. Your building is inaccessible. A key vendor is offline. Several critical employees are unexpectedly unavailable. Or perhaps nothing dramatic has happened at all, but a technology system you’ve known needs replacing finally gives up.

What happens next?
September is National Preparedness Month, making now a good time to ask that question. But preparedness isn't only about emergency management or having a Continuity of Operations Plan (COOP) sitting on the shelf. Preparedness is really about organizational readiness.
It means knowing how you will continue essential operations when something goes wrong, how you will respond to a cyber incident, how technology will recover, who can make critical decisions, and where the organization is heading over the next several years.
And perhaps most importantly, it means starting before you need the plan.
Preparedness Is Bigger Than a COOP Plan
We’ve talked before about making COOP a living plan instead of a binder that gets created, placed on a shelf, and forgotten. That remains important. But continuity doesn't exist in isolation.
Consider how quickly one disruption can cross organizational boundaries. A cyber incident becomes an operational problem when employees can't access systems. A technology failure becomes a customer-service problem when residents, students, clients, or staff can't access services. A staffing issue becomes a continuity problem when only one person knows how to perform a critical function.
Preparedness connects all of these areas. That means leaders should be thinking about:
Continuity of Operations (COOP/COG): What services absolutely must continue, and how will you deliver them during a disruption?
Cyber Incident Response: Who makes decisions during an incident? Who gets called? How will you communicate if normal technology isn't available?
Technology and Disaster Recovery: Are backups working? What systems get restored first? Do your recovery priorities match your operational priorities?
Operational Continuity: What happens if a facility, vendor, system, or key employee suddenly isn't available?
Succession and Staffing: Where does critical knowledge reside, and who can step in when someone is unavailable?
Strategic Planning: Are you investing today in the capabilities your organization will need tomorrow?
None of these plans should live on separate islands. Together, they create organizational resilience.
Planning Is Increasingly a Leadership Issue
For local government technology leaders in 2026–27, continuity, cybersecurity, aging infrastructure, staffing, modernization, budgeting, and growing service expectations are competing for attention.
The challenge is that daily operations rarely leave much extra time for planning. There is always another ticket. Another budget issue. Another project. Another meeting. Another system demanding attention.
Strategic work can easily become something you'll tackle "when things settle down."
Things rarely settle down. And waiting for an incident to expose a gap is an expensive way to discover what needs attention.
Good preparedness turns that around. Instead of asking What do we do now? during a crisis, leaders have already asked What could happen, what matters most, and what will we do about it?
That doesn't eliminate disruption. It makes disruption manageable.
You Don't Need to Solve Everything This September
Preparedness can feel overwhelming because organizations sometimes approach it as one enormous project... Don't.
Use National Preparedness Month as the reason to start moving!
Pull out your COOP and see when it was last updated. Review your cyber incident response plan. Ask IT when backups were last tested. Identify your five most critical technology systems. Talk with department leaders about their essential functions. Look at where institutional knowledge rests with a single employee. Review your technology and operational roadmap.
Then identify the gaps. Some may take years and significant investment to address. Others might take an afternoon.
The objective isn't to become perfectly prepared by September 30. The objective is to be better prepared on September 30 than you were on September 1.
Turn Preparedness Into a Roadmap
Once you've identified the gaps, don't create another list that disappears into a folder. Build them into your organization's strategic and operational roadmap.
Perhaps this year you update COOP and incident response plans. Next year's budget funds backup improvements or aging infrastructure replacement. Staff cross-training becomes part of normal operations. A tabletop exercise gets scheduled every year. Technology, cybersecurity, staffing, and operational risks become recurring leadership discussions.
Over time, preparedness stops being a project and becomes part of how the organization operates. That's where strategic planning and continuity planning intersect. A strong three-to-five-year roadmap helps organizations connect mission, technology, cybersecurity, staffing, budgets, and operational priorities rather than addressing each independently. And because conditions change, that roadmap should be reviewed and adjusted regularly, not treated as another static document.
Practice Before It Matters
There is one more step leaders shouldn't overlook: exercise the plan.
You don't need an elaborate emergency simulation. Try putting one scenario on the agenda of an upcoming leadership meeting:
"Our primary systems will be unavailable for the next eight hours. What do we do?"
"We discovered ransomware at 9:00 a.m. Who has authority to make decisions, and who is our first phone call?"
"The person who performs this critical function will be unavailable for the next month. Who takes over?"
Give your team 20 minutes to work through it. You may learn more from that short conversation than from another 50 pages added to your preparedness plan.
And when you find gaps, and you probably will, that's a success. You found them on a Tuesday morning around a conference table instead of during an actual emergency.
There May Never Be a Better Time Than Now
Organizations can always find reasons to postpone planning… The budget is tight. Staff are busy. A system implementation is underway. Leadership is changing. Next year's strategic planning process is coming. We'll address it after the budget. We'll revisit it next quarter.
Preparedness doesn't require everything to stop while you develop the perfect plan.
It requires taking the next practical step. National Preparedness Month gives leaders a convenient reminder to do exactly that. Open the plan. Ask the uncomfortable question. Schedule the exercise. Identify the risk. Put the project on the roadmap. Start the conversation.
Because continuity isn't ultimately about predicting the next disruption. It's about building an organization capable of continuing its mission when the unexpected inevitably arrives.
September is as good a time as any to get moving.
If National Preparedness Month has you thinking about your organization's COOP, cyber incident readiness, technology resilience, operational continuity, or longer-term strategic roadmap, Sage 497 Consulting LLC would be happy to join the conversation. Sometimes the most valuable first step isn't creating another plan, it's figuring out where you are today, where the gaps are, and what practical step should come next.




Comments