Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact This year marks the 20th year of Cyber Storm, a full-scale national cybersecurity exercise that for two decades has brought together the people who defend the systems Americans rely on. Held every two years, Cyber Storm X arrives as threats from geo-political activity, compromised edge devices, AI risks, and more present new challenges to our nation’s critical infrastructure. As the nation’s largest cybersecurity exercise, Cyber Storm plays a vital role in preparing for potential cybersecurity incidents by testing and strengthening the nation’s ability to coordinate a unified cyber response. Participants from private and public organizations work together through a simulated crisis. Together, they learn as a team and build stronger relationships that will speed response during an actual event. Importantly, organizations can also update their response plans based on lessons learned during the exercise. Building Partnerships for a More Secure Nation Cyber Storm began with 500 participants 20 years ago as a national effort to bring government and industry together in one place when our nation needed a way to understand how a major cyber incident could unfold across many sectors at once. This number has grown, and this fall’s Cyber Storm exercise will bring together 2,000 critical infrastructure owners and operators from around the country, spanning everything from large national companies to local utilities. Participants include legal teams, crisis communication, IT managers, and organizational leaders. For many of them, this exercise is the first time they meet those who they will need to work with during a cybersecurity crisis. How Organizations Practice for Real Events Cyber Storm features a simulated attack on the services our nation counts on every day. These are services that keep communities moving and can’t afford downtime. For example, in 2024's Cyber Storm IX,
Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact | CISA
Read the original article
cisa.gov →