The US Cybersecurity and Infrastructure Security Agency (CISA) has admitted it began writing its incident response playbook during the incident it was responding to — a breach in which a contractor exposed administrative credentials to Amazon AWS GovCloud accounts and internal CISA systems on a public GitHub repository.
An agency improvising its own response plan
In a postmortem, CISA acknowledged that staff had to spend time building a playbook during the early stages of the incident, and that its channels for allowing outside security researchers to notify the agency were not well defined. The agency, which sits inside the Department of Homeland Security and is charged with defending federal networks and critical infrastructure, did not disclose how long the missing playbook delayed containment.
CISA said no customer or mission data was ultimately compromised, and it credited the researcher and reporter who surfaced the exposure.

How the leak surfaced
The exposure involved a GitHub repository containing cloud keys, tokens, plaintext passwords in CSV files, logs, and internal build documentation.
Files reportedly included administrative credentials to AWS GovCloud servers and plaintext logins for internal systems. Commit metadata indicated that default secret-scanning protection had been actively disabled.
The institutional backdrop
The postmortem lands against a specific organisational context. CISA has faced leadership transitions and workforce reductions through cuts, furloughs, buyouts, and early retirements. The agency responsible for setting incident response standards for the rest of the federal government was, by its own admission, drafting its own playbook in real time.
Why it matters
The structural signal in this disclosure is worth isolating. CISA publishes incident response guidance that private-sector critical infrastructure operators — utilities, hospitals, banks — are effectively expected to follow. Its own admission that a playbook did not exist in advance, and that researcher notification channels were undefined, suggests that the operational maturity gap between the regulator and the regulated is narrower than the guidance implies. Combined with workforce reductions and leadership transitions, the incident illustrates how quickly institutional capacity erodes when headcount and leadership are removed faster than processes can be codified — regardless of the guidance being issued externally.