Call Consultation
All posts

Cybersecurity

The Pennington County cyberattack: what it means for Black Hills businesses

August 24, 2026 8 min read

On July 5, 2026, Pennington County South Dakota announced that it had been a victim of a cyberattack. The impact was an immediate disruption of civic services, with most county offices closed to the public the next day. Critical services remained operational, including 911 dispatch, the jail, the courts, and the sheriff's office, but computer-based communications, internet access, and public-facing systems were down. These disruptions lasted well into August, with the Treasurer's Office still unable to process vehicle registrations or take payments normally, and public-facing systems only slowly coming back online.

A culprit has still not been named, and officials have kept details close while the investigation is ongoing. Cybersecurity experts quoted in local reporting believe a foreign state-backed actor is the most likely explanation, and they note that no ransom demand was made, which suggests the goal may have been access and disruption rather than a quick payout. The attack has brought together a joint state and federal task force consisting of the South Dakota National Guard's cyber response team, the state Fusion Center, and the federal Cybersecurity and Infrastructure Security Agency.

This incident is unusual for both its scope and its target. The target was not a large national hospital chain, prime defense contractor, or international bank, but the county building where people in Rapid City renew their plates. And it was not an isolated event: in mid-July someone attempted to breach the monitoring system for Rapid City's sewer lift stations, which city IT staff contained quickly, and in early August the city of Mitchell's email system went down in a separate incident. South Dakota's attorney general has received over a thousand breach reports in the past five years.

The lesson is "not if but when"

The uncomfortable takeaway from Pennington County is more specific than that, and it is worth walking through what actually happened, because the county did some things right and still took a multi-week hit.

The segregated systems worked as intended. Emergency services, the jail, and the courts remained online. It is standard procedure to keep critical systems off the general network so they keep operating when that network is compromised. Most small businesses run everything on one flat network, which means their version of this event has no surviving systems. The point-of-sale, the accounting machine, the file server, and the front-desk PC all go down together. Network segmentation is a design decision, and it is one of the most cost-effective pieces of network design a business can make.

Recovery took weeks, not days. The county had insurance, a National Guard cyber team, and CISA on the phone, and its payment systems were still affected 30 days later. Chances are your business does not have access to those resources. Your defense on day one of an incident is whatever you built beforehand: backups, network documentation, and a partner who knows the systems. Ask what four weeks without taking payments would do to your business, because that is roughly what the Treasurer's Office just lived through.

Most attacks on small organizations are not this sophisticated, and that is the good news. The common case in South Dakota looks like Tripp County, which lost $826,000 of taxpayer money in 2025 to an ordinary phishing scam that worked. The common threats are automated: scanners probing every internet-facing firewall and camera system for known holes, and phishing emails sent by the million. Automated attacks are simply playing the numbers game and are target agnostic.

What a Black Hills business should actually do

None of this requires an enterprise budget. It requires the basics, done deliberately.

Turn on multi-factor authentication everywhere it exists. Email, CRM, ERP, and financial systems are all mandatory.

Have backups you have actually tested. Make sure your backups are up to date and that at least one copy is offline or otherwise unreachable from the main network. Encrypting the backups first is a common tactic of most cyber criminals. This is the core of backup and disaster recovery done properly.

Segment the network. Cameras, guest WiFi, payment systems, and office computers should not all sit on one network. If one device is compromised, the walls should already be up.

Put a real firewall at the edge, and keep it updated. The router the internet provider supplied is not a security tool, and firmware that is a few updates behind is a huge security risk.

Create a specific SOP. The county had an incident response structure. A business needs at least a one-page version: who takes charge, who gets called, what gets unplugged, where the backups are.

We build this into our cybersecurity work for commercial clients across the Black Hills, and for businesses that want the ongoing version, monitoring, patching, and someone accountable for all of it, that is what managed IT is for.

The investigation will eventually tell us more about who did this and why. But for local business owners, the important question is not who attacked Pennington County. It's how your business would handle this type of event.

If you don't like your honest answer, fix it now, while it's still cheap. At Brink Design we specialize in putting a security posture and plan in place that meets your needs.

Ready when you are

Talk to a local integrator, not a call center.