Nevada Cyberattack: How Preparedness & Partnerships Enabled Fast Recovery

by Alex Thompson — Chief Editor
0 comments

Nevada’s Cyber Resilience: A 28-Day Recovery from Ransomware Attack

In August 2025, the State of Nevada faced one of the most significant cyberattacks in its history. A ransomware incident impacted multiple government services, prompting a swift and coordinated response that ultimately led to a recovery within 28 days. This success story highlights the importance of proactive preparedness, strong partnerships, and strategic investments in modern cybersecurity infrastructure.

The Attack and Initial Response

The cyberattack was detected on Sunday, August 24, 2025, by the state’s data center operations team, who identified anomalous activity within its server infrastructure [1]. Tim Galluzi, State Chief Information Officer and Executive Director of the Governor’s Technology Office, immediately activated the state’s cyber action plan [2]. The attack resulted in the temporary disruption of several government services, including phone systems and state agency websites [3]. It was later determined that data had been exfiltrated during the intrusion, though the full extent of the compromised information remained under investigation [3].

Preparedness as a Key Factor

According to Timothy Galluzi, the State’s rapid recovery was not accidental. Years of investment in strengthening cybersecurity resilience, coupled with proactive preparation, were critical to mitigating the impact of the attack [1]. Prior to the incident, Galluzi focused on technical modernization and governance alignment, and ensured IT teams were prepared to act as a unified force in a crisis.

  • Tabletop Exercises: Regular tabletop exercises were conducted to pressure-test incident response plans and ensure clear decision-making paths.
  • Playbook Updates: Incident response playbooks were tightened and updated, outlining roles, escalation procedures, and recovery steps.
  • Cross-Functional Coordination: Practices were implemented to improve coordination between different teams and agencies.

Strategic Technology Investments

Several key technology investments proved crucial during the recovery process. Moving identities to the cloud with Entra ID was particularly vital, allowing the State to maintain communication and coordination even although on-premises components were affected [1]. The state similarly benefited from its investment in network infrastructure and cyber insurance.

Phased Recovery and Transparency

The recovery effort was conducted in a phased manner, prioritizing services based on their impact on public safety and critical citizen needs [1]. Despite the severity of the incident, the state was able to restore its network within two days and complete the restoration across more than 60 agencies in just 28 days [1]. The State of Nevada also demonstrated a commitment to transparency by publishing a comprehensive After Action Report (AAR) documenting the incident and lessons learned [1].

The Role of Partnerships

Strong partnerships were instrumental in Nevada’s successful response. Galluzi highlighted the support of Info-Tech Research Group, which assisted with updating incident response playbooks earlier in 2025 and provided ongoing expertise and resources during the crisis [1]. The state also received assistance from network partners, its cyber insurance provider, the Federal Bureau of Investigations, and the Department of Homeland Security [2].

Lessons Learned and Future Resilience

The State of Nevada’s experience underscores the importance of proactive cybersecurity preparedness and the value of strong partnerships. The state is using the lessons learned from this incident to further strengthen its resilience and protect its citizens and critical infrastructure. As Galluzi stated, “The State of Nevada is stronger and more resilient now because of you.” [1]

Related Posts

Leave a Comment