Cyber Storm X tested whether critical-infrastructure organisations can make shared decisions during a simulated national cyber incident. CISA said the four-day exercise involved 2,000 participants from more than 200 public and private organisations, with a scenario affecting transportation systems—including rail and ports—and water and wastewater services.
What Cyber Storm X tested
The exercise was not a live attack and did not touch operational systems. Its purpose was to test response plans, coordination and information sharing under pressure. CISA’s primary statement says participants included the people who manage services the public relies on. TechTarget independently described the exercise as a model for CISOs, and WaterISAC recorded its participation.
The scenario design matters because rail, ports and water are operationally different but economically connected. A cyber incident can create physical delays, public-safety concerns and competing communications demands. Testing those interfaces exposes questions that a single-company exercise misses: who shares what, which authority leads and how organisations coordinate when facts remain incomplete.
Why the after-action report is the real deliverable
CISA says it will work with participants to identify lessons and publish observations, analysis and recommendations. Participation counts show scale, not success. The useful evidence will be whether teams found unclear authorities, slow notification paths, incompatible terminology or dependencies without an owner.
Organisations can apply the same standard internally. An exercise should record decision time, unresolved questions, unavailable roles and actions with named owners and deadlines. It should include legal, communications, operations and suppliers—not only the security operations centre. The next drill should verify that the earlier fixes worked.
This is also why static guidance eventually needs replacement or consolidation. Our review of the CISA Cyber Performance Goals sunset examined how programmes must move into maintained operating systems. Mobile security teams face a similar measurement problem; see the Android Security State libraries briefing.
What enterprise leaders should copy
Start with a scenario that crosses at least two operational domains and one external dependency. Give participants incomplete information, force an executive decision and test the handoff to public communications. Avoid scoring the exercise by whether defenders “won.” Score it by whether the organisation discovered a gap before a real incident did.
Cyber Storm X does not yet publish performance results, so it should not be presented as proof of national readiness. It is evidence of rehearsal at meaningful scale. The public after-action report will determine how much of that rehearsal becomes reusable guidance for operators beyond the room.
Frequently asked questions
Was Cyber Storm X a real cyberattack?
No. CISA describes it as a simulated exercise that did not touch live operational systems.
Who participated?
CISA reports 2,000 participants from more than 200 organisations across government and the private sector.
What happens next?
CISA plans to analyse lessons with participants and issue a public after-action report with observations and recommendations.
Boards can ask one immediate question: when the exercise reveals a dependency outside the company, who owns the relationship before the next incident? Naming that owner converts a scenario into resilience work and prevents an external dependency from remaining an unassigned observation.
Sources
- CISA — primary
- TechTarget — independent
- WaterISAC — participant
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



