TL;DRCISA admitted it had no prepared playbook for a cybersecurity incident. A contractor leaked government credentials on GitHub. A journalist had to alert the agency.

The US Cybersecurity and Infrastructure Security Agency revealed in a postmortem report on Friday that it did not have a prepared response plan for handling a cybersecurity incident when one hit in May. CISA staff “had to spend time building [a playbook] during the early stages of the incident,” the agency said, recommending that organisations prepare playbooks for “all anticipated needs” rather than improvising in real time.

The incident began when a security researcher at cyber firm GitGuardian discovered that an employee of a CISA contractor had uploaded passwords, AWS GovCloud keys, and other sensitive credentials to a publicly accessible GitHub repository. The researcher tried to alert the contractor but received no response. Only after cybersecurity journalist Brian Krebs contacted CISA did the agency take the repository offline and revoke the exposed credentials.

CISA said no customer or mission data was exposed and thanked the researcher and reporter for their help. The agency acknowledged that its channels for allowing security researchers to report potential incidents “were not well defined” and has made changes to improve contact pathways. It did not say how long the missing playbook delayed its response. CISA is simultaneously using Anthropic’s Mythos AI to audit government code for vulnerabilities, making the admission that it lacked basic incident preparedness for its own security all the more striking.