[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-252731-105":53,"doc-detail-252731-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","cyber-storm-ix-after-action-report-executive-findings-and-recommendations","Cyber Storm IX - After-Action Report - Executive findings and recommendations","","Cyber Storm IX After-Action Report (September 2024) summarizes how the Cybersecurity and Infrastructure Security Agency (CISA) used a national exercise to strengthen cybersecurity preparedness, response, and cross-sector coordination. The April 2024 scenario focused on a cyber campaign targeting U.S. and international partners’ critical infrastructure, emphasizing cloud vulnerabilities from improper configuration. Key findings cover cloud security, internal processes, faster and more timely information sharing, incident reporting, federal and international coordination, distributed sharing networks, and established relationships, followed by consolidated recommendations.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/cyber-storm-ix-after-action-report-executive-findings-and-recommendations/252731/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/cyber-storm-ix-after-action-report-executive-findings-and-recommendations/252731.png","ImageObject",442,249,{"name":88,"@type":89},"Melati","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-22","2026-09-13",true,{"@type":98,"interactionType":99,"userInteractionCount":79},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What was the main scenario and focus of Cyber Storm IX?","Question",{"text":108,"@type":109},"Cyber Storm IX simulated a cyber campaign against U.S. and partners’ critical infrastructure, with vulnerabilities stemming from improper configuration of cloud resources. The exercise evaluated incident response, information sharing, and coordination using confidentiality, integrity, and availability as a framework.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What were the major areas covered in the exercise findings?",{"text":113,"@type":109},"The report presents eight findings spanning cloud security, internal process maturity and points of failure, incentives for timely reporting, improving incident reporting, and strengthening federal and international coordination. It also addresses distributed information-sharing networks and established relationships.",{"name":115,"@type":106,"acceptedAnswer":116},"How are the findings derived in the After-Action Report?",{"text":117,"@type":109},"Findings come from discoveries made during exercise design and development, observations captured during the exercise, and feedback recorded in after-action questionnaires and post-exercise evaluation events.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},252731,1789262674,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":140},962085570644,"https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d","Cyber Storm IX: After-Action Report  \nSeptember 2024  \nCybersecurity and Infrastructure Security Agency (CISA)  \nTABLE OF CONTENTS  \nExecutive Summary...................................................................................................................................1  \nKey Achievements ........................................................................................................................... 2  \nExercise Overview......................................................................................................................................3  \nExercise Goal & Objectives .............................................................................................................. 4  \nParticipation .................................................................................................................................... 4  \nScenario & Adversary ...................................................................................................................... 4  \nExercise Findings ......................................................................................................................................5  \nFinding 1: Cloud Security ................................................................................................................. 5  \nFinding 2: Internal Processes .......................................................................................................... 8  \nFinding 3: Facilitating Information Sharing .................................................................................... 10  \nFinding 4: Incident Reporting ........................................................................................................ 13  \nFinding 5: Federal Coordination .................................................................................................... 16  \nFinding 6: International Coordination ............................................................................................ 18  \nFinding 7: Distributed Information Sharing Networks .................................................................... 19  \nFinding 8: Established Relationships............................................................................................. 21  \nConsolidated Cyber Storm IX recommendations .................................................................................. 23  \nCybersecurity Documents Referenced in the After-Action Report ........................................................ 26  \nList of Acronyms ..................................................................................................................................... 27  \nAppendix A: Participant List ................................................................................................................... 29  \nAppendix B: Exercise Design Summary ................................................................................................. 34  \nEXECUTIVE SUMMARY  \nCybersecurity has become an essential capability, protecting our information systems and, by extension, operation of the critical infrastructure upon which our way of life depends. To face an evolving threat landscape, we require a robust national cybersecurity posture that enhances cyber preparedness, response capabilities, and cross-sector coordination for critical infrastructure operators and government partners alike. Since 2006, the Cyber Storm exercise series, sponsored by the Cybersecurity and Infrastructure Security Agency (CISA) , has provided a venue for stakeholders to exercise cybersecurity processes together, strengthening the collective resilience of critical infrastructure.  \nSince the publication of the National Cybersecurity Strategy (NCS) in 2023, an array of national reports and studies have signaled that the federal government is engaged in an ongoing process to reassess federal and partner responsibilities for safeguarding the nation’s critical infrastructure. With hundre","cbCaidFf8y2Cu7xU","https://ap.wps.com/l/cbCaidFf8y2Cu7xU","pdf",947008,37,"English","# Executive Summary\n# Key Achievements\n# Exercise Overview\n## Exercise Goal & Objectives\n## Participation\n## Scenario & Adversary\n# Exercise Findings\n## Finding 1: Cloud Security\n## Finding 2: Internal Processes\n## Finding 3: Facilitating Information Sharing\n## Finding 4: Incident Reporting\n## Finding 5: Federal Coordination\n## Finding 6: International Coordination\n## Finding 7: Distributed Information Sharing Networks\n## Finding 8: Established Relationships\n# Consolidated Recommendations\n# Documents Referenced\n# List of Acronyms\n# Appendices","[{\"question\":\"What was the main scenario and focus of Cyber Storm IX?\",\"answer\":\"Cyber Storm IX simulated a cyber campaign against U.S. and partners’ critical infrastructure, with vulnerabilities stemming from improper configuration of cloud resources. The exercise evaluated incident response, information sharing, and coordination using confidentiality, integrity, and availability as a framework.\"},{\"question\":\"What were the major areas covered in the exercise findings?\",\"answer\":\"The report presents eight findings spanning cloud security, internal process maturity and points of failure, incentives for timely reporting, improving incident reporting, and strengthening federal and international coordination. It also addresses distributed information-sharing networks and established relationships.\"},{\"question\":\"How are the findings derived in the After-Action Report?\",\"answer\":\"Findings come from discoveries made during exercise design and development, observations captured during the exercise, and feedback recorded in after-action questionnaires and post-exercise evaluation events.\"}]","Cyber Storm IX - After-Action Report - Executive findings and recommendations | PDF",13]