The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hosted Cyber Storm X, a four-day national cybersecurity exercise designed to test and ultimately strengthen the nation’s resilience. This year’s exercise included 2,000 participants from across the public and private sectors and marks the tenth exercise in the 20-year history of Cyber Storm. The biennial exercise brings together the people who manage the services our nation relies on, including water, energy, and other vital sectors. During the exercise, participants practice how they would respond to a major cyber incident affecting critical infrastructure.
“Cyber Storm helps critical infrastructure owners and operators understand how we would manage a large-scale cyber incident,” said Acting CISA Director Nick Andersen. “Exercises strengthen our national resilience by making sure our plans, policies, and partnerships are ready when we need them. As a nation, we need the ability to respond swiftly and effectively to critical threats. That’s exactly what Cyber Storm does and why it’s a vital exercise for our nation’s security.”
This year’s exercise focused on a scenario involving a nation-state adversary targeting the transportation systems sector, including rail and ports, along with the water and wastewater systems sector. The exercise allowed participants to test response plans, practice coordination, and strengthen information sharing in a safe environment. Cyber Storm X included over two hundred organizations across all levels of government and the private sector.
CISA will now collaborate with participating organizations to identify lessons learned from the exercise. The findings will be used in a public after-action report that captures observations, analyses, and recommendations. CISA is committed to providing access to a wide range of cybersecurity tools and training opportunities, with exercises being a critical part of that toolkit to enhance the nation’s cyber preparedness.
As cyber threats grow in scale and sophistication, the nation must continually refine its cyber incident response capabilities. Building on insights from past iterations, Cyber Storm X will explore the full spectrum of cyber incident response by simulating an adversary-driven cyberattack on critical infrastructure. The exercise will enable participants to test internal response plans while strengthening coordination across federal, state, local, and private sector partners. Through active partnership, stakeholders will identify capability gaps, reinforce existing strengths, and develop actionable strategies to advance the nation’s overall cyber resilience.
Cyber Storm X will include organizations across federal, state and local governments and the private sector. Participants are divided into working groups to support planning and collaboration among specific communities of interest.
Participation can help organizations improve their response plans and capabilities, strengthen relationships with counterparts, and increase awareness of resources available to respond to and mitigate impacts.
Cyber Storm X’s primary goal is to strengthen cybersecurity preparedness and response capabilities by exercising policies, processes and procedures for identifying and responding to a multi-sector significant cyber incident impacting critical infrastructure.
Cyber Storm X has several specific objectives. The exercise will explore the challenges of cyber incident response, with an emphasis on real-world threats. It will examine and clarify roles and responsibilities in responding to a significant cyber incident. It will assess information-sharing capabilities and resource needs during a cyber incident. It will also increase understanding of current national-level cyber plans and policies.


