
CISA Admits It Had No Incident Response Plan When Contractor Exposed Government Credentials
The U.S. cybersecurity agency CISA had no prepared response playbook when a contractor leaked sensitive government credentials online — and had to build one mid-crisis.
CISA Was Caught Off Guard With No Response Plan During Major Security Incident
The United States Cybersecurity and Infrastructure Security Agency — better known as CISA — has admitted something deeply uncomfortable for a federal body charged with protecting government networks: when a serious security incident unfolded earlier this year, the agency had no prepared response plan in place.
In a postmortem report released Friday, CISA revealed that its staff members were forced to construct an incident response playbook from scratch during the early stages of the crisis — a crisis that could have been far more damaging had it gone unnoticed.
How the Security Breach Came to Light
The incident dates back to May, when independent cybersecurity journalist Brian Krebs was alerted by a researcher at cyber intelligence firm GitGuardian. The researcher had discovered a trove of exposed passwords and sensitive credentials sitting in a publicly accessible GitHub repository — files that had been uploaded by an employee of a CISA contractor.
According to Krebs, the researcher initially attempted to notify the contractor directly but received no response. It was only after Krebs reached out to CISA himself that the agency stepped in, took the repository offline, and moved quickly to revoke and replace all compromised credentials.
A Playbook Built in Real Time
CISA's own postmortem report laid bare the agency's lack of preparedness. Staff had to dedicate valuable time during the early phases of the incident just to develop the response framework they needed — time that could have been spent actively containing the threat.
In its report, CISA acknowledged the critical importance of having playbooks ready for all anticipated scenarios before an incident occurs, rather than scrambling to create them under pressure. The agency did not specify how much time was lost as a result of the missing playbook, and a CISA spokesperson had not responded to media inquiries at the time of publication.
Communication Gaps and Structural Shortcomings
Beyond the missing playbook, CISA also acknowledged that its channels for receiving tips and vulnerability reports from external security researchers were poorly defined at the time of the incident. The agency stated it has since made structural changes to streamline communication, making it faster and easier for researchers to flag potential threats directly to CISA.
CISA also took the opportunity to thank both the GitGuardian researcher and journalist Brian Krebs for their roles in surfacing the issue. The agency confirmed that no customer data or mission-critical information was exposed during the incident.
Leadership Vacuum and Workforce Reductions Add to Concerns
The incident raises broader questions about CISA's current operational capacity. The agency has been without a permanent director since President Donald Trump began his second term in January 2025. On top of the leadership vacuum, CISA has endured significant workforce reductions — including cuts, furloughs, and layoffs — that have affected approximately one-third of its total staff since the new administration took office.
These developments have prompted concern among cybersecurity experts and policy observers about the agency's ability to maintain its core mission of defending federal networks and protecting critical national infrastructure.
Key Takeaways
- CISA had no incident response playbook ready when a contractor leaked government credentials online
- A publicly accessible GitHub repository contained sensitive access keys uploaded by a contractor employee
- The breach was discovered by an outside researcher and surfaced through investigative journalist Brian Krebs
- CISA has since improved its researcher communication channels and updated its internal protocols
- The agency continues to operate without a permanent director and has lost roughly a third of its workforce
