TechOptima Ignite
TechOptima Solutions (636) 777-7702

US cybersecurity agency CISA had to build its incident playbook during the incident

July 10, 2026

CISA revealed it lacked a prepared response plan when a contractor publicly exposed sensitive keys and credentials for U.S. government systems in May. Staff had to build an incident playbook during the early stages of the response. The agency has since stressed the need to prepare playbooks for all anticipated needs ahead of time.

U.S. federal cybersecurity agency CISA said it did not have a prepared response plan for handling a cybersecurity incident in May after an investigative reporter notified the agency that a contractor had publicly exposed sensitive keys and credentials for accessing U.S. government systems. In a postmortem report, CISA revealed its staff had to spend time building a playbook during the early stages of the incident. The agency emphasized that organizations should prepare playbooks for all anticipated needs so they are ready to respond rather than improvising in real time. It did not disclose how long the missing playbook delayed its response.

Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository uploaded by an employee of a CISA contractor. The researcher had tried to alert the contractor without success. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent potential abuse.

CISA said no customer or mission data was exposed and thanked the researcher and reporter for their help. The agency acknowledged that its channels for security researchers to report potential incidents were not well defined and said it has made changes to make contact easier and faster. CISA has been without a permanent director since the start of President Donald Trump’s second term in January 2025 and has faced cuts, furloughs, and layoffs affecting about a third of its workforce.

Tags: SECURITY | INCIDENT PLAYBOOK | CYBERSECURITY | CISA

Source: us-cyber-agency-cisa-had-to-build-its-incident-playbook-during-the-incident-agency-reveals

← Back to Blog