
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The Cybersecurity and Infrastructure Security Agency’s biannual cyber exercise involved a nation-state adversary attacking the transportation and water sectors and the threats to those systems, according to CISA chief operating officer Ryan Donaghy, who highlighted efforts to strengthen relationships with government and private sector partners.
Summary
“Critical infrastructure is frequently being targeted by cyber threat actors whose aim is to disrupt vital systems, such as the transportation sector and water and wastewater sectors,” Donaghy told Inside Cybersecurity . Donaghy said, “In addition to that, our focus was on understanding our preparedness and response capabilities across both the government and the private sector, as it relates to potential impacts to two sectors or multiple sectors at once.” Cyber Storm X took place Sept. 14-18, with the last day focused on reviewing takeaways from the workshop.
CISA announced the conclusion of the exercise on Sept. 18. Donaghy spoke with Inside Cybersecurity on the last day of the exercise.
“In 2024 in Cyber Storm IX , we focused on a vulnerability attack, and that vulnerability attack was focused on one particular sector, the food and agriculture sector, and then we examined and explored through the course of that exercise how it [was] distributed and had cascading disruptions across retail, production and distribution systems,” Donaghy said. The 2026 exercise was based on a “nation-state attack,” Donaghy said, “and how that nation-state attack could potentially impact multiple systems” in the transportation and water and wastewater sectors. Donaghy provided high-level takeaways from the exercise, noting that a full after-action report will be published in the coming “months” through work with CISA’s Joint Cyber Defense Collaborative.
“Some of the higher-level takeaways that we found from this exercise is the importance of a whole-of-government and all-of-nation approach to how we are managing a significant cyber incident,” Donaghy said. “Secondly,” she said, “we have found through the course of this exercise that the private sector is continuing to look to the federal government for guidance in response to a significant cyber incident.” The last takeaway is the “really critical role that fusion centers are able to play in consolidating the intelligence and then successfully distributing that information to our federal, state and local partners,” according to Donaghy. The tenth exercise involved 2,000 participants from the public and private sectors including federal agencies, state governments, international partners and industry players.
Two hundred participants joined the exercise from “all levels of government and the private sector,” according to a CISA release. Work on Cyber Storm X started in June 2025, with a “concept and objectives meeting,” Donaghy said. CISA will look to incorporate the findings from Cyber Storm X in “best practices or guidance,” Donaghy said, adding that the lessons learned “would inform the broader work that we do here as an agency.” The first Cyber Storm exercise took place in 2006.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.