This year marks the 20th year of Cyber Storm, a full-scale national cybersecurity exercise that for two decades has brought together the people who defend the systems Americans rely on. Held every two years, Cyber Storm X arrives as threats from geo-political activity, compromised edge devices, AI risks, and more present new challenges to our nation’s critical infrastructure.
As the nation’s largest cybersecurity exercise, Cyber Storm plays a vital role in preparing for potential cybersecurity incidents by testing and strengthening the nation’s ability to coordinate a unified cyber response. Participants from private and public organizations work together through a simulated crisis. Together, they learn as a team and build stronger relationships that will speed response during an actual event. Importantly, organizations can also update their response plans based on lessons learned during the exercise.
Building Partnerships for a More Secure Nation
Cyber Storm began with 500 participants 20 years ago as a national effort to bring government and industry together in one place when our nation needed a way to understand how a major cyber incident could unfold across many sectors at once.
This number has grown, and this fall’s Cyber Storm exercise will bring together 2,000 critical infrastructure owners and operators from around the country, spanning everything from large national companies to local utilities. Participants include legal teams, crisis communication, IT managers, and organizational leaders. For many of them, this exercise is the first time they meet those who they will need to work with during a cybersecurity crisis.
How Organizations Practice for Real Events
Cyber Storm features a simulated attack on the services our nation counts on every day. These are services that keep communities moving and can’t afford downtime. For example, in 2024’s Cyber Storm IX, a simulated threat actor infiltrated networks modeled after those found across the Food and Agriculture sector, triggering cascading disruptions across retail, production, and distribution systems. These “interruptions” slowed the movement of food products from manufacturing plants to store shelves, caused payment processing outages at grocery retailers, and fueled public confusion as media reports highlighted delays and errors. Participants collaborated to regain system control, address the exposure of sensitive data, and coordinate communications to stabilize the situation and maintain consumer trust.
The exercise never touches live systems, but it does replicate a cyber incident. The cyber incident is fully simulated, and it gives the players room to practice response without touching real networks. The lasting results show the impact of this exercise.
The Results Speak for Themselves
The practical result of holding this exercise is a more resilient, unified national response posture. As one past participant put it, “Building these relationships and partnerships now is how Cyber Storm is going to help me in my future.” A critical infrastructure operator noted that the exercise helped them strengthen cyber preparedness and see where cross functional coordination needed to improve, and a state agency representative said it improved their posture tenfold.
Learn more about Cyber Storm and past events at cisa.gov/cyber-storm.
The original announcement can be found here.


