US cyber agency CISA had to build its incident playbook during the incident, agency reveals

The U.S. cybersecurity agency CISA admitted it lacked a formal incident response playbook when a contractor exposed sensitive government credentials earlier this year. The agency had to develop its response strategy in real-time and is now working to improve its reporting channels for security researchers.
Why it matters
This highlights significant operational vulnerabilities within the primary agency responsible for protecting U.S. federal networks and critical infrastructure.
U.S. federal cybersecurity agency CISA said it did not have a prepared response plan for how it should handle a cybersecurity incident in May, after an investigative reporter notified the agency that a contractor had publicly exposed sensitive keys and credentials for accessing U.S. government systems.
CISA, the Homeland Security unit tasked with defending federal networks and helping to safeguard critical infrastructure, revealed Friday in a post-mortem report that its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency said it is important to prepare playbooks for “all anticipated needs” to ensure that organizations are ready to respond in the event of a security incident rather than scrambling to improvise one in real time.
The agency did not say how long the missing playbook delayed CISA’s response, and a spokesperson did not immediately respond to TechCrunch’s request for comment.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in