Fire and Wildfire Readiness
Protect life first, preserve irreplaceable records before an incident, and design district technology so the loss of an entire site does not become the loss of the district.
Immediate danger: Activate the site emergency plan, call 911, and follow fire-department and evacuation instructions. Do not delay evacuation to shut down equipment, retrieve media, or fight a fire. Only trained personnel should use an extinguisher, and only when the plan authorizes it and a safe exit remains available.
The Paradise lesson: plan for complete site loss
The 2018 Camp Fire destroyed 18,804 structures and damaged or destroyed fourteen schools; 99 schools closed temporarily and more than 31,000 students were displaced. A credible district plan therefore assumes that buildings, local servers, paper records, staff homes, roads, electricity, cellular service, and ordinary suppliers may all be unavailable at once.
Design objective: authorized staff should be able to reestablish essential student, payroll, communications, identity, special education, and instructional services from an unaffected location without entering the disaster area.
Prevent total data loss
Separate the copies
- Maintain at least three copies on two types of storage, with one offline or immutable and one geographically separated.
- Do not count replication alone as backup; corruption and deletion can replicate.
- Keep encryption keys, recovery codes, vendor contacts, configurations, and runbooks available outside the primary site.
- Back up cloud applications and SaaS data when the vendor’s retention or recovery capability does not meet district needs.
Prove recovery
- Assign recovery-time and recovery-point objectives from a documented business-impact analysis.
- Restore representative files monthly and perform full, isolated system recovery at least annually.
- Test identity, DNS, certificates, integrations, reports, and downstream reconciliation—not merely file restoration.
- Record test evidence, elapsed time, defects, owners, and corrective-action deadlines.
Harden server and network rooms
| Risk | Control |
|---|---|
| Unauthorized access | Dedicated locked room; least-privilege electronic access; door alarms; visitor escort and logs; periodic access review; no shared keys. |
| Fire and smoke | Code-compliant detection and suppression selected with the fire marshal and qualified engineer; monitored alarms; sealed penetrations; no combustible storage; tested emergency notification. |
| Heat and power | Independent temperature/humidity monitoring; remote alarms; maintained cooling; UPS for orderly ride-through/shutdown; generator strategy based on load, fuel, maintenance, and safe transfer. |
| Water | Avoid plumbing above equipment where feasible; leak sensors; known and accessible shutoff/isolation valves; equipment raised from the floor. |
| Earthquake | Seismically brace racks, batteries, cable trays, and equipment; protect falling hazards; use qualified facilities professionals. |
| Regional loss | Alternate internet, voice, identity, storage, and processing arrangements outside the same fire, utility, and telecommunications failure zone. |
Wildfire operational checklist
- Coordinate evacuation procedures with the operational area when a qualifying school is in a high or very high fire-hazard severity zone, as required by Education Code section 32282.
- Predefine evacuation, reunification, transportation, accessibility, medication, multilingual messaging, and student-accounting procedures; keep essential rosters securely available offline.
- Subscribe to authoritative alerts and define who can close sites, issue messages, fail over systems, and contact vendors.
- Maintain current insurance schedules, photographs, serial numbers, licenses, contracts, warranties, facility drawings, and procurement authority in an off-site repository.
- Before reopening, use qualified professionals to assess structural, electrical, HVAC, smoke, ash, water, and environmental conditions; document clearance and remediation.
Recovery sequence
- Account and stabilize: account for people, activate incident command, preserve communications, and document decisions and costs.
- Establish alternate operations: shift leadership, help desk, enrollment, payroll, public information, records requests, and instruction to predetermined locations or cloud services.
- Recover trusted identity first: restore clean administrative access, MFA, DNS, networking, and logging before applications.
- Restore by approved priority: health/safety and student accountability; communications; payroll and finance; SIS and special education; teaching and learning; lower-priority services.
- Validate: reconcile totals, transactions, integrations, permissions, retention, and audit logs with business owners.
- Reopen deliberately: obtain facilities clearance, communicate accommodations, monitor health and system performance, and retain recovery evidence.
California planning baseline
Education Code sections 32280–32289.5 require each K–12 school to maintain and annually update a Comprehensive School Safety Plan. Required content includes disaster procedures, disability adaptations, earthquake procedures, fire drills, crisis response, and an instructional continuity plan. Coordinate the CSSP, district emergency operations plan, continuity plan, IT disaster-recovery plan, cyber incident-response plan, records schedule, and vendor continuity obligations so they do not conflict.
Primary resources
- California Department of Education: Comprehensive School Safety Plans
- CDE: Instructional Continuity Plan Guidance
- CDE: Reopening a School after a Fire Disaster
- CAL FIRE: Camp Fire incident record
- NIST SP 800-34: Contingency Planning Guide
- NIST SP 800-53 Rev. 5: Physical, environmental, and contingency controls


































































