Cyber Storm X simulated nation-state attack on water and transportation
CISA's tenth biennial exercise drew 2,000 participants; the after-action report won't land for months, but two sectors got a rare chance to rehearse a multi-front coordinated incident.
TL;DR
CISA concluded Cyber Storm X on September 18, simulating a nation-state adversary attacking the transportation and water and wastewater sectors simultaneously. The exercise involved 2,000 participants from federal agencies, state and local governments, international partners, and private-sector critical infrastructure operators. COO Ryan Donaghy told Inside Cybersecurity that high-level takeaways include the importance of a whole-of-government approach and the private sector's continued reliance on federal guidance during significant incidents. A full after-action report will follow, CISA's Cyber Storm IX after-action landed about five months after that exercise concluded.
Cyber Storm X, which ran September 14 (18, marked the tenth iteration of CISA's biennial national cyber exercise and the first to simulate a nation-state threat actor hitting two critical infrastructure sectors at once) transportation systems and water and wastewater systems. CISA COO Ryan Donaghy told Inside Cybersecurity that the 2024 exercise, Cyber Storm IX, had focused on a vulnerability attack originating in food and agriculture and then cascading across retail, production, and distribution. This time the adversary was a nation-state, and the scenario was built to test response when multiple sectors are under simultaneous pressure.
Donaghy offered three high-level takeaways on the exercise's final day. First, the exercise reinforced "the importance of a whole-of-government and all-of-nation approach" to managing a significant cyber incident. Second, the private sector continues to look to the federal government for guidance during a major incident. Third, fusion centers played a "really critical role" in consolidating intelligence and distributing it to federal, state, and local partners.
CISA began planning for Cyber Storm X in June 2025 with a concept and objectives meeting. The agency says it will fold the findings into future best practices and guidance, and a full after-action report will be published through the Joint Cyber Defense Collaborative. If the timeline mirrors Cyber Storm IX (which concluded in April 2024 and published its after-action in September 2024) operators should expect the report around early 2027. For water-sector utilities, many of which are small municipal operators with lean cyber staffing, the gap between exercise and published guidance is itself a planning variable.
Published ·Deep Fathom