Local IT support. All-inclusive service.
Get a Free IT Review

What South Dakota Businesses Can Learn From the Rapid City Cyberattacks

Cyberattacks can feel like problems that happen somewhere else, until they disrupt services in your own community.

That’s what recent incidents in the Rapid City area have brought into focus. In July 2026, Pennington County experienced a ransomware attack that interrupted government systems and public services. That same month, the City of Rapid City reported a separate attempted cyber intrusion involving a wastewater lift station.

The incidents had very different outcomes, but both raise questions worth asking in any South Dakota business: Would you recognize a threat quickly? Could you keep operating if important systems went offline? And would your team know what to do next?

What Happened in the Rapid City Area?

On July 4th, attackers compromised Pennington County’s computer systems. The county took systems offline, affecting communications and several public-facing services. Essential functions, including emergency operations and law enforcement, largely continued.

According to an October 5th report from South Dakota News Watch, nearly all county services had returned by early October. Recovery also prompted significant changes, including rebuilding the network, expanding employee training, and improving security monitoring.

Rapid City’s wastewater incident, reported in late July, unfolded differently. City officials said an attempted intrusion at a wastewater lift station was detected and contained. They reported no disruption to drinking water or wastewater services, according to KOTA’s coverage.

One incident illustrates how disruptive recovery can become. The other shows why early detection and quick action matter. Neither should be treated as evidence that the same attack methods were involved.

Black-and-white view of Mount Rushmore National Memorial in South Dakota with an American flag in the foreground.

Why Should South Dakota Businesses Pay Attention?

A business doesn’t need to operate public infrastructure to face similar operational risks. Manufacturers depend on connected production systems. Medical practices need access to patient information. Professional services firms rely on email, files, and financial applications.

When those systems are unavailable, work slows or stops. And even after an attack is contained, restoring normal operations may require more time and coordination than expected.

Here are seven areas every organization should review before an incident tests its defenses.

7 Cybersecurity Checks to Make Now

1. Can You Detect Suspicious Activity Quickly?

Rapid City’s wastewater response highlights the value of recognizing unusual activity and acting before services are affected. For businesses, that starts with knowing who’s monitoring endpoints, networks, and cloud accounts.

Antivirus alone may not reveal suspicious account access or activity across multiple systems. Security monitoring and endpoint detection tools can help, but alerts also need someone assigned to investigate them.

Ask your IT provider: If an incident happened overnight or on a weekend, who would notice and respond?

2. Are Backups Tested, Not Just Scheduled?

Pennington County’s prolonged recovery illustrates why businesses need to prepare for system outages, not simply try to prevent them.

Review which applications and data are backed up, how frequently copies are created, and whether backups are protected from attackers. Just as important, perform restoration tests. A backup that hasn’t been tested may provide false confidence.

Ask your IT provider: How quickly could we restore our most important systems, and when did we last prove that process works?

3. Do Critical Accounts Require MFA?

Stolen passwords can open the door to email, remote access, and sensitive business systems. Multi-factor authentication (MFA) adds another layer of verification, reducing the risk of an attacker signing in with a password alone.

Confirm MFA is required for Microsoft 365, cloud services, remote connections, and administrator accounts. Use phishing-resistant options where available.

Ask your IT provider: Are there any employee, vendor, or administrator accounts that still allow password-only access?

Black-and-white aerial view of downtown Rapid City, South Dakota, showing commercial buildings, neighborhoods, and the surrounding landscape.

4. Are Critical Systems Separated From Office Networks?

The attempted intrusion involving wastewater equipment is particularly relevant to manufacturers, utilities, and other organizations using operational technology (OT).

Industrial controls, connected machinery, and vendor remote-access connections shouldn’t automatically be reachable from everyday business devices. Network segmentation and tightly controlled permissions can limit how far an intrusion might spread.

Ask your IT provider: If an office computer were compromised, could an attacker reach production equipment or other critical systems?

5. Are You Fixing the Most Important Vulnerabilities?

Outdated software, exposed remote-access services, and misconfigured devices create opportunities for attackers. Regular vulnerability reviews can help identify weaknesses before they’re exploited.

Make sure someone maintains an inventory of your systems, tracks security updates, and prioritizes fixes based on risk. Not every vulnerability is equally urgent, but critical gaps shouldn’t sit unresolved.

Ask your IT provider: When was our last vulnerability assessment, and who owns the follow-up work?

6. Would Employees Recognize and Report a Threat?

Pennington County has expanded employee security training as part of its response. That’s a reminder that cybersecurity depends on people as well as technology.

Employees should know how to recognize suspicious links, fake payment requests, and unexpected sign-in prompts. They also need a simple way to report concerns without delay.

Ask your IT provider: Do we have a process for employees to report suspicious activity, and how does your team respond when something is reported?

7. Is There an Incident Response Plan Everyone Understands?

During a cyberattack, technical teams aren’t the only people making decisions. Leadership may need to coordinate customer communications, operational workarounds, outside specialists, and recovery priorities.

A written incident response plan should identify responsibilities, escalation contacts, and the order in which essential services need to return. Practice the plan so it isn’t being read for the first time during an emergency.

Ask your IT provider: If our primary systems went down tomorrow, what would your response look like in the first hour, and how would you get us back online?

Workplace IT Professional Reviewing IT Performance Metrics

Where Should Your Business Start?

You don’t need to address everything at once. Start by checking MFA coverage, backup restoration results, monitoring responsibilities, and your incident response plan. Then review vulnerabilities, employee training, and access to sensitive or operational systems.

The Cybersecurity and Infrastructure Security Agency (CISA) offers additional guidance for small and midsized organizations. A cybersecurity assessment can help you turn those recommendations into priorities based on your environment.

Take the Next Step Before an Incident

The recent Rapid City-area incidents weren’t identical, and neither tells us exactly how another organization might be targeted. They do show why both prevention and recovery deserve attention.

At Workplace by Direct, our South Dakota-based team helps organizations evaluate security risks, improve their defenses, and plan for disruptions through cybersecurity services and ongoing IT support.

Not sure where your business stands? A free IT review can help identify potential cybersecurity gaps and where to focus your efforts next.

Project Ready

Want a More Reliable IT Experience?

Discover how our proactive support model, rapid issue resolution, and round-the-clock monitoring keep your business running smoothly and without interruptions.