Monday, August 3, 2026

Policy & Regulation

US cyber agency CISA lacked playbook during security incident

The US cybersecurity agency CISA admitted it lacked a prepared response plan and had to build its incident playbook in real time during a May security breach.

The Cybersecurity and Infrastructure Security Agency (the US federal cybersecurity agency), a unit of Homeland Security, the US cabinet department overseeing CISA, said it did not have a prepared response plan for how it should handle a cybersecurity incident in May. In a postmortem report published Friday, CISA said its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency also said organizations should prepare playbooks for all anticipated needs so they are ready to respond to a security incident rather than improvising one as it unfolds.

The incident began when an employee of a CISA contractor publicly exposed sensitive keys and credentials for accessing U.S. government systems in a repository on GitHub. A researcher at GitGuardian, a cybersecurity firm, discovered the exposure. According to Brian Krebs, the independent cybersecurity journalist who reported the incident, the researcher first tried to alert the contractor directly but did not hear back. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent further misuse. CISA said no customer or mission data was exposed in the incident, but acknowledged that its channels for allowing security researchers to notify the agency of potential incidents were not well defined.

The operational gap surfaced at a vulnerable moment for the agency. CISA has been without a permanent director since President Donald Trump’s second term began in January 2025, and it has been affected by cuts, furloughs, and layoffs affecting about a third of its workforce since then.

Why it matters

The operational gap at CISA highlights the compounding risks of a leadership vacancy and workforce cuts during active security incidents, raising questions about the agency’s readiness to respond to future threats against U.S. federal systems.