Blog
Who files at hour 72: what Cyber Storm X is actually testing
CISA's Cyber Storm X is four days of live play for about 2,000 operators. The part every IR team can steal is the reporting clock: who starts it, who files, and what the room still does not know.
This fall CISA runs Cyber Storm X, the tenth biennial National Cyber Exercise: four days of live play for about 2,000 critical infrastructure owners and operators. The roster is the point. Legal, crisis communications, IT, and leadership sit in the same scenario. CISA is explicit that the exercise never touches live systems. It is a decision exercise at national scale.
On 11 September, TechTarget covered the launch and pointed at the clock sitting next to it. CISA is still writing the final rule for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The proposed windows, public since the 2024 notice, are 72 hours after a covered entity reasonably believes a covered cyber incident has occurred, and 24 hours after a ransom payment is disbursed. CISA's own FAQs still say those requirements are not in effect until the final rule says so. The windows are already useful as injects. You do not need a seat in Cyber Storm, and you do not need to wait for the rule, to find out whether your plan can name a filer.
On 2 September, CISA, the FBI, and international partners published Communicating Under Pressure: say what is known, what is unknown, and what is under investigation; skip the spin; keep the wording aligned with the legal clocks you actually have. That is the same family of pressure. A national exercise and a comms note are both asking whether the room can produce a factual report under a deadline.
The clock starts when someone reasonably believes
Most IR plans bury reporting in a paragraph that says notify regulators as required. That sentence cannot be exercised. The decision that starts the clock is earlier and more awkward: at what time did a named person record that the organisation reasonably believes a covered incident is underway, and who is allowed to make that call with incomplete facts.
Walk it on a clock, not as open discussion.
- 02:14. EDR flags encryption on billing-db-02. The SOC analyst pages the incident commander.
- 02:54. Sev-1 declared. Containment is in progress. Legal is not yet on the bridge.
- 06:40. Legal joins and asks whether anyone has recorded that the org reasonably believes a ransomware incident is in progress. The room has been treating that as obvious for four hours and has not written it down. If a 72-hour window applies, it may already have been running.
- 20:10. Communications wants to post that the company is investigating a service issue. The CISA/FBI guidance says to state what is known, unknown, and under investigation, and to keep that wording aligned with any filing. Nobody has drafted the factual summary.
- Next calendar day, 03:00. Finance has a ransom demand. If anyone pays, the proposed CIRCIA window for that payment is 24 hours from disbursement: a different clock, a different form. The plan does not name who reports a payment.
A tabletop that never reaches who files, through which portal, with which blanks still open, has not practised the part Cyber Storm is built around: roles, information sharing, and a report under a deadline. Ransomware with a reporting clock is one of the scenario families we actually run.
Weak inject, then the one that costs something
A weak inject reads:
Discuss how you would notify CISA and customers.
The room says it would coordinate with legal and moves on. An assessor who later reads the packet learns nothing about who holds the portal account, when the 72 hours started, or which fields were still blank. The sentence would also be true of a team that has never opened the form. That is what it costs: the record looks complete and the gap stays invisible until a real filing is due overnight.
A strong inject reads:
T+6h12. Dana K (legal, named CIRCIA filer in the plan) is asked to start the covered-incident form with the facts on the table. She cannot name the portal, the required fields, or who holds the login. The room defers filing until it knows more. Record: clock-start at 06:40 (incident commander), filer seat filled, form not exercisable, follow-up owned by Dana before the next run.
Both produce a meeting. Only the second produces evidence, because only the second can be checked by someone who was not in the room. A session like that records that named people practised a filing decision under a concrete scenario. It does not prove CIRCIA applies to you, that a real filing would be accepted, or that restore works.
Do not send a live customer email or a live regulator filing from the exercise. Practise the wording and the ownership. Leave the send for a real event.
What to write down
Whether you run ninety minutes or you have a seat in the four-day national exercise, the artifact that travels is the same shape:
- Clock start. Who recorded that the org reasonably believes, at what time, against which facts.
- Filer. Named person against the role the plan lists, including if the seat was empty or reassigned.
- Form. Portal or process named, fields the room could fill, fields still blank.
- External wording. The factual summary (known, unknown, under investigation), who can approve it, and that it was not sent live.
- Follow-ups with owners. What will change before the next run.
That is the shape of our free evidence template, and it sits with three other formats in the template library. If the plan cannot tell you who files, stop and run the free plan self-check before you book the room. An empty filer seat is a finding about the roster, not a scheduling inconvenience. The invite-list post covers how to write that down so someone who was not present can still trust the record.
Bottom line: you do not need a seat at Cyber Storm X to practise the 72-hour clock. Name the filer, start the clock when someone reasonably believes, write down what was still blank, and keep the live send for a real event.