The Inland Empire’s economy runs on three industries that make attractive, under-defended targets: logistics, healthcare, and local government. That combination isn’t unique to Southern California, but the concentration is. Riverside and San Bernardino counties are home to more than 4.6 million residents, and a large share of the businesses serving them run lean, between 20 and 200 employees, with one internal IT hire handling password resets, server maintenance, and network security under the same job title, if that.
National cybersecurity coverage tends to talk in averages: average breach cost, average ransom demand, average time to detect an intrusion. Averages flatten out what actually matters here. The specific mix of industries, staffing patterns, and public-sector history in Riverside and San Bernardino counties determines what attackers find when they look at this region specifically, and that mix looks different from the national picture.
Here’s what that mix looks like, and why it’s worth treating as a present reality rather than a hypothetical.
Local government has already provided the case study
In April 2023, ransomware locked San Bernardino County’s Sheriff’s Department out of systems used for basic law enforcement functions, including checks on whether a person had outstanding warrants elsewhere. The county paid $1.1 million to regain access, with insurance covering most of it. Deputies spent weeks working around a system they couldn’t use.
Rialto Unified School District went through something similar in 2020, when malware forced roughly 25,000 students offline and the district had to collect and inspect thousands of devices before anyone could safely reconnect. Neither of these organizations was careless in any obvious way. Both were running the kind of lean IT operation that describes most public agencies in this region: a small internal team responsible for security alongside every other technology function the agency needs.
That’s the part worth sitting with. Both are public agencies with budgets and staffing closer to a mid-sized regional employer than to a national government body or a major metro system with a dedicated security operations center. If a county sheriff’s department and a 25,000-student school district can be locked out for weeks, the assumption that a 60-person logistics company or a 40-person medical group is too small to be worth targeting doesn’t hold up.
Healthcare is growing faster than its security posture
Healthcare is one of the only sectors adding jobs in the Inland Empire right now, even as logistics and retail shed positions. San Bernardino County’s healthcare and social assistance sector alone is projected to add roughly 46,600 jobs this decade, a 20% increase, driven by population growth that shows no sign of slowing. Riverside County is following a similar trajectory.
Growth in this context means more clinics, more urgent care locations, and more small practices opening to meet demand that outpaces what the region’s hospital systems can absorb on their own, most of them launching with the same lean-IT model found everywhere else in the region, except they’re holding patient records instead of shipment manifests.
Medical records consistently carry more resale value on dark web markets than stolen credit card numbers, because a credit card gets canceled and a Social Security number doesn’t. That fact matters more in a region actively adding healthcare capacity than in one where the sector is flat. Every new practice opening to meet demand is also a new target opening with whatever security posture its founders happened to prioritize during setup, which for most small practices is not much.
Logistics didn’t get safer when it got smaller
Warehousing built this region’s identity, and it’s worth acknowledging that identity is shifting. The Inland Empire lost roughly 26,000 transportation and warehousing jobs in the first half of 2025 alone, driven by softening port traffic, automation, and tariff uncertainty that’s made shippers cautious. That contraction has continued into 2026.
Fewer people now manage the same volume of freight, the same number of logins, and the same footprint of connected systems that existed when headcount was higher. The attack surface didn’t shrink with the workforce. If anything, a leaner logistics operation has fewer people available to notice a phishing email that got through, an unfamiliar login at 2 a.m., or a vendor invoice that looks slightly off. Automation reduced labor costs. It didn’t reduce the number of systems that need monitoring, and in many cases it added new ones.
This is the part of the region’s economic story that gets less attention than warehouse job losses themselves: the industries picking up the slack, healthcare and public sector employment among them, are exactly the ones with the least mature security operations to begin with.
The staffing model is the real common thread
Logistics, healthcare, and local government have almost nothing in common regulatorily, operationally, or culturally. What they share in this region is a staffing model built around keeping operations running day to day.
Security usually rides along as one item on a much longer list of IT responsibilities, handled by one person, sometimes one vendor, rather than a dedicated team.
That model works reasonably well for day-to-day technology support. It works poorly against attackers who specifically target organizations too small to have a security operations center but large enough to hold data or process payments worth stealing. San Bernardino County had an IT department. Rialto Unified had one too. Neither had the dedicated security capacity that would have caught what got through.
What this means for decision-makers here
Most of what hits organizations in this region is opportunistic and automated, built to find whoever has the weakest defenses on a given day. The region’s risk comes from facing that kind of ordinary attack with fewer defenses in place than the value of what’s being protected would justify.
Businesses evaluating their own exposure should start with an honest look at three things: how much of security is actually someone’s full-time responsibility versus a task squeezed between other priorities, how quickly the organization would notice if something looked wrong, and how long recovery from a lockout would realistically take. For most 20-to-200-person organizations in this region, right now, at least one of those answers is uncomfortable.
At Syntech Group, this is the exact profile of client this region requires most: logistics operators, healthcare practices, and public agencies running lean, holding data and systems worth protecting, without the internal capacity to build that protection alone. A regional risk profile shaped by industry mix and staffing reality calls for an assessment built around those specific conditions. If it’s been a while since anyone looked at where your organization’s exposure actually sits, that’s a reasonable place to start.