CISA announces Cyber Storm IX cybersecurity exercise to strengthen national cyber readiness
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Monday that Cyber Storm IX, the ninth iteration of the series, is scheduled for Spring 2024. Participants will exercise their cyber incident response plans and identify opportunities for coordination and information sharing in a simulated environment. Like previous iterations, Cyber Storm IX will engage over 2,000 distributed participants throughout three days of live exercise play.
Cyber Storm IX includes organizations across federal, state, and international governments, and the private sector. Participating organizations work directly with CISA to understand CISA’s role and capabilities in a cyberattack. Participants operate in working groups to meet organization- and sector-specific objectives. Benefits of participation include exercising organizational response plans and capabilities, fostering relationships with counterparts, and improving organizational and national cyber readiness.
Cyber Storm IX will assess the most recent national cybersecurity guidance and clarify federal roles and responsibilities as cyber threats continue to evolve. Its primary goal is to strengthen cybersecurity preparedness and response capabilities by exercising policies, processes, and procedures for identifying and responding to a multi-sector significant cyber incident impacting critical infrastructure.
Cyber Storm IX specific objectives include exercising and evaluating cybersecurity response, operational collaboration, and support; examining and clarifying roles and responsibilities in response to a significant cyber event. It also works on assessing information-sharing capabilities and resource needs during a cyber incident and reviewing and evaluating relevant national cybersecurity policy, guidance, and doctrine.
The Cyber Storm exercise series provides a venue for the federal government, state and local government, the private sector, and international partners to come together to simulate a response to a large-scale, coordinated, significant cyber incident impacting the nation’s critical infrastructure. The series focuses on policy, procedure, information sharing, coordination, and decision-making.
Each iteration of the Cyber Storm exercise series builds on the previous one to provide the most relevant environment possible for learning and advancement. In February 2006, the cyber response community came together for the first time in Cyber Storm I to examine the national response to cyber incidents. Cyber Storm IV included 15 building block exercises to help communities and states exercise cyber response capabilities for escalating incidents.
The most recent iteration, Cyber Storm VIII, consisted of a multi-layered scenario that impacted both industrial control systems/operational technology and information technology networks, raising awareness of the rapidly expanding cyberattack surface. Cyber Storm IX will have a core scenario that challenges participants to improve their system preparedness against emerging threats.
The exercise provides participants with a safe, realistic environment to evaluate response capabilities without real-world ramifications through simulated attacks and impacts distributed as injects. Players react to the simulated injects from their regular workplaces and communicate through standard channels.
The Cyber Storm IX planning team manages all aspects of play from a central exercise control location while implementing a series of mechanisms to capture player response, player action, and findings to evaluate systems and improve cyber resilience.
In January, the CISA opened registrations for its fifth annual President’s Cup cybersecurity competition this month. Registration runs Jan. 3 to 23 for the Teams Competition and Jan. 3 – Feb. 6 for the Individuals Competition. Participants can compete as an individual, on a team of up to five members, or both. Teams can be made of individuals from one or more departments or agencies.