2026 New Jersey Municipal, School, and Public Safety Technology Readiness Checklist

Security camera monitoring a public-sector facility

Municipal buildings, schools, police departments, EMS organizations, fire stations, and public-facing facilities depend on technology that has to work during routine operations and stressful moments.

That usually means more than computers and Wi-Fi. It can include Microsoft 365, dispatch or administrative systems, VoIP phones, public-facing internet, surveillance cameras, access control, alarm systems, PA systems, backup, disaster recovery, vendor portals, and aging network equipment.

This checklist is built for New Jersey administrators, school business officials, public safety leaders, office managers, facility teams, and technology decision-makers who need a practical way to find gaps before they create downtime, security exposure, or response problems.

This is not legal, procurement, life safety, or compliance advice. It is an operational readiness checklist. Public-sector organizations should confirm procurement requirements, life-safety requirements, emergency communication obligations, union/workplace policies, insurance requirements, and applicable legal obligations with the proper advisors and authorities.

Rivell supports New Jersey organizations with managed IT, cybersecurity, Microsoft 365, cloud platforms, disaster recovery, VoIP, surveillance cameras, access control, commercial fire and burglar alarm systems with 24/7 monitoring, hardware procurement, application hosting, and commercial audio/video and PA systems.

Fast Readiness Score

Score each section from 0 to 3.

0 = not in place
1 = partially in place
2 = mostly in place
3 = documented, tested, and actively managed

AreaScore
Identity, MFA, and account lifecycle0-3
Microsoft 365, email, and records access0-3
Endpoint, server, and network security0-3
Backup and disaster recovery0-3
VoIP, E911, and emergency communications review0-3
Cameras, access control, alarms, and PA systems0-3
Vendor, procurement, and warranty tracking0-3
Incident response and continuity planning0-3

1. Identity, MFA, and Account Lifecycle

  • MFA is required for email, Microsoft 365, VPN, remote access, finance systems, cloud platforms, and vendor portals.
  • Admin accounts are separate from daily accounts.
  • Former staff, vendors, temporary users, volunteers, contractors, and board-related accounts are removed quickly.
  • Shared accounts are eliminated or documented with compensating controls.
  • Access is reviewed by department, role, and facility.
  • Emergency access accounts are documented, secured, and monitored.

First fix: review active users and remove stale access.

2. Microsoft 365, Email, and Records Access

  • MFA is enforced for all Microsoft 365 users.
  • External mailbox forwarding is reviewed and restricted.
  • Admin roles are limited and reviewed.
  • Shared mailboxes and delegated access are documented.
  • Email authentication is configured for the domain.
  • Records retention, mailbox access, and backup expectations are documented.
  • Phishing reporting and security alert review are assigned to a real owner.

First fix: review mailbox forwarding, admin roles, and MFA enforcement.

3. Endpoint, Server, and Network Security

  • Workstations, laptops, servers, switches, firewalls, access points, and network-connected devices are inventoried.
  • Devices are patched and supported.
  • Endpoint protection or EDR is deployed and monitored.
  • Guest Wi-Fi is segmented from internal systems.
  • Cameras, door controllers, phones, printers, and IoT systems are segmented where appropriate.
  • Firewall rules, VPN access, and remote management tools are reviewed.
  • Network diagrams and warranty/support details are current.

First fix: build a current inventory and identify unsupported or unmanaged devices.

4. Backup and Disaster Recovery

  • Critical files, servers, SaaS systems, and Microsoft 365 data are included in the recovery plan.
  • Backup alerts are monitored.
  • At least one backup layer is protected from ransomware.
  • Restore tests are performed and documented.
  • Recovery time and recovery point targets are defined for critical systems.
  • Recovery documentation can be accessed if the network is down.
  • Critical vendor contacts are stored offline or in a separate emergency-access location.

First fix: run a restore test and document the actual recovery time.

5. VoIP, E911, and Emergency Communications Review

VoIP systems need operational review, especially in multi-building, school, municipal, healthcare, and public safety environments.

  • Phone numbers, extensions, locations, and assigned users are documented.
  • E911 and dispatchable location information are reviewed with the phone provider.
  • Front desk, after-hours, and emergency routing rules are documented.
  • Phone system admin access is secured with MFA where supported.
  • Internet outage and power outage impact is understood.
  • PA, paging, intercom, and notification workflows are reviewed where they are part of the communication plan.

First fix: verify location data and emergency calling behavior with the phone provider.

6. Cameras, Access Control, Alarms, and PA Systems

Physical security technology has to be managed like business-critical infrastructure.

  • Camera placement and retention settings match operational needs.
  • Camera system remote access is secured.
  • Access control users and door permissions are reviewed after role changes or departures.
  • Door schedules and emergency procedures are documented.
  • Fire and burglar alarm monitoring contacts are current.
  • Alarm escalation paths are tested and updated.
  • PA and audio/video systems are documented, supported, and tied into emergency workflows where appropriate.
  • Security devices are segmented from sensitive administrative systems where appropriate.

First fix: review who can access cameras, access control, and alarm platforms.

7. Vendor, Procurement, and Warranty Tracking

  • Critical vendors are documented with contacts, contract dates, support levels, and emergency procedures.
  • Hardware warranty status is tracked.
  • Procurement decisions consider supportability, cybersecurity, compatibility, and lifecycle.
  • Cloud and application hosting vendors document backup, export, and incident notification expectations.
  • Vendor portal access uses named accounts and MFA where available.
  • Decommissioned hardware is securely wiped or destroyed.

First fix: create a current vendor and hardware lifecycle list.

8. Incident Response and Continuity Planning

  • Leadership knows who to call after ransomware, account takeover, network outage, phone outage, camera outage, alarm issue, or vendor incident.
  • The incident response plan includes communications if email or phones are down.
  • The continuity plan identifies the systems needed for public-facing operations.
  • Tabletop exercises are run at least annually.
  • Insurance and reporting requirements are documented.
  • Public communication responsibilities are assigned before an incident happens.

First fix: write a one-page emergency technology contact sheet.

30-Day Action Plan

WeekFocusOutcome
Week 1Account cleanup, MFA, vendor accessReduce the most common access risks.
Week 2Backup restore test and critical system inventoryKnow what can actually be recovered.
Week 3Network, camera, access control, and phone reviewFind connected systems that need segmentation, updates, or access cleanup.
Week 4Incident response contact sheet and continuity tabletopMake the first hour of an outage or incident less chaotic.

Useful Rivell Resources

Sources

FAQs

Who should use this checklist?

Municipal administrators, school business officials, public safety leaders, office managers, facility managers, and technology decision-makers can use it to structure a practical technology risk review.

Does this replace procurement, legal, or life safety guidance?

No. It is an operational readiness checklist. Public-sector organizations should confirm procurement, legal, life safety, insurance, and emergency communication requirements with the proper authorities and advisors.

Why include cameras, access control, alarms, and PA systems in an IT checklist?

These systems are often network-connected and business-critical. They need secure access, documentation, monitoring, maintenance, and continuity planning.

What should be reviewed first?

Start with MFA, stale user access, backup restore testing, critical system inventory, phone/E911 location review, and administrative access to cameras, alarms, access control, and vendor portals.

Facebook
Twitter
LinkedIn