CISA hosted Cyber Storm X this week, the tenth edition in the 20-year history of its biennial national cyber exercise, drawing 2,000 participants from more than 200 organisations across federal, state and local government and the private sector. The scenario exercised this year was unusual for a resilience drill in its specificity: a nation-state adversary targeting the transportation systems sector, including rail and ports, alongside the water and wastewater systems sector — the two critical-infrastructure verticals that have dominated this month's incident reporting, with US officials tracking cyber threats against nearly 20 shipping vessels and the Coast Guard boarding two tankers in the Gulf of Mexico in August. Acting CISA Director Nick Andersen said the exercise strengthens national resilience "by making sure our plans, policies and partnerships are ready when we need them". CISA said it will now work with participants on findings from the four-day event, which is designed to test how responders manage a large-scale incident affecting critical infrastructure rather than to certify individual organisations. The exercise is a readiness signal rather than an incident: no adversary activity is implied by the scenario choice, though the sector pairing is a statement about where CISA assesses systemic risk sits.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-21 |
| Source | CISA |
| Reliability | Tier 1 |