The U.S. federal cybersecurity agency CISA admitted that it lacked a pre-prepared response plan for dealing with a cybersecurity incident in May. This was following an investigative reporter’s notification that a contractor had unintentionally exposed sensitive keys and credentials required for accessing U.S. government systems. CISA, which is a unit of Homeland Security and is responsible for defending federal networks and securing critical infrastructure, disclosed in a post-incident report that its employees had to construct a ‘playbook’ during the initial phases of the incident. The agency emphasized the necessity of creating playbooks for all expected requirements to ensure organizations can promptly respond to security incidents without having to improvise in real time. The agency did not disclose the impact of the missing playbook on CISA’s response time. A spokesperson did not immediately provide comment to TechCrunch’s inquiry. In May, cybersecurity journalist Brian Krebs reported that a researcher from cyber firm GitGuardian discovered numerous exposed passwords in a publicly accessible GitHub repository, which was uploaded by an employee of a CISA contractor. The researcher attempted to notify the contractor but received no response. After Krebs got in touch with CISA, the agency removed the repository from service and withdrew and renewed all the compromised credentials to stop any possible future misuse. CISA confirmed that no customer or mission data was compromised during the incident and expressed their gratitude to the researcher and reporter for their assistance. The agency acknowledged that its methods for allowing security researchers to inform CISA about possible occurrences were not clearly defined, and it has modified them to make communication quicker and more accessible for researchers. CISA has not had a permanent director since January 2025, the beginning of President Donald Trump’s second term. The organization has experienced reductions, temporary job reductions, and dismissals impacting approximately one-third of its staff since Trump assumed office. When you make a purchase via links in our content, we could receive a minor commission. Our editorial independence remains unaffected by this.

US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals
- by stefan