US cyber agency CISA had to build its incident playbook during the incident, agency reveals
The U.S. cybersecurity agency CISA revealed that it had no prepared response framework when a contractor employee accidentally published sensitive government system credentials to a public online repository in May. The breach remained unaddressed until investigative journalist Brian Krebs contacted the agency after learning of the exposure from a security researcher; only then did CISA take the repository offline and revoke the compromised access credentials. The incident prompted a post-mortem that acknowledged the agency's staff spent valuable time constructing their response procedures during the crisis itself, rather than executing a pre-established plan.
In its review, CISA identified systemic weaknesses including unclear channels for security researchers to report vulnerabilities to the agency, and emphasized the importance of preparing response frameworks in advance. The disclosure of the agency's unpreparedness comes amid broader operational challenges, including workforce reductions affecting roughly a third of CISA's staff and the agency operating without a permanent director since the Trump administration took office in January 2025.
- CISA lacked a prepared incident response playbook during a May breach where contractor exposed sensitive government access credentials
- The agency had to develop response procedures in real-time rather than follow an established plan, and has since identified gaps in security researcher communication channels