Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • House Bill Targets Privacy Risks, Mental Health Harms From AI Chatbots
    • CISA Admits Cyber Missteps Prior to May Data Breach
    • Huawei Code in White House App Raises ‘Grave Concerns,’ Rep. Khanna Says
    • Massachusetts Senate Passes Bill Aimed at Protecting Youth on Social Media
    • Risk of Cyber Attacks From AI Highlighted by Dutch Privacy Agency
    • Router Exempted From FCC’s ‘Covered List’
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, CISA Admits Cyber Missteps Prior to May Data Breach, (Jul 10, 2026)

    By Tom Leithauser

    The Cybersecurity and Infrastructure Security Agency yesterday identified gaps in its cybersecurity practices that complicated its response to a May data breach but said it was instructive to cyber defenders to disclose such errors.

    The breach, caused ...

    By Tom Leithauser

    The Cybersecurity and Infrastructure Security Agency yesterday identified gaps in its cybersecurity practices that complicated its response to a May data breach but said it was instructive to cyber defenders to disclose such errors.

    The breach, caused by a CISA contractor who uploaded sensitive government data into a publicly accessible GitHub repository, led to inquiries by congressional Democrats (CPR, May 20).

    “Sharing experiences from incident response activities helps other organizations learn from such experiences and enables them to take necessary precautions to prevent similar incidents from happening in their environments,” according to a report posted by Preston Werntz, CISA’s acting chief information officer, and Brad Libbey, the agency’s acting chief information security officer.

    “CISA has said this type of information exchange is critical to identifying trends and contributing to broader national awareness. Now, it is our turn,” the officials said.

    CISA learned about the incident from an unnamed “investigative reporter,” they said, likely referring to Brian Krebs, author of the KrebsonSecurity blog, who reported on the breach after hearing about it from a security researcher.

    “Within moments of receiving this information, CISA’s Office of the Chief Information Officer (OCIO) took swift and comprehensive action to mitigate any exposure to CISA’s cloud resources and code repositories,” the officials reported.

    “The reported public repository was taken offline and a copy was saved for later analysis. This repository was not part of CISA’s official GitHub but rather was a personal repository owned by a contractor. CISA’s development environment was taken offline and associated credentials were reset. The individual who exposed the keys had their system access revoked,” they said.

    CISA’s investigation revealed that leaked credentials “were not used outside of CISA’s environments” and that “customer or mission data” was not exposed in the breach, they said.

    CISA’s mistakes prior to learning about the breach included its failure to have a “playbook” for managing cyber incidents involving its GitHub repository or cloud environments, they admitted.

    “It is important to prepare playbooks for all anticipated needs to ensure a rapid response if an incident occurs. CISA had missed creating a GitHub/Cloud playbook and, therefore, had to spend time building one during the early stages of the incident,” they said.

    CISA also lacked well-defined channels for security researchers to report breaches involving CISA’s data, they noted. “Clear and distinct reporting channels are essential to ensure that incidents affecting the organization itself are handled differently from those involving its products or customers,” they said.

    “In CISA’s case, these channels were not well defined, leading the security researcher to try multiple avenues—including emailing the contractor, submitting through CISA’s vulnerability disclosure platform (which is intended for vulnerabilities impacting the broader cybersecurity community), and ultimately involving a reporter. To reduce ambiguity, CISA is refining its reporting channels to make them easier and faster for researchers to use,” the officials said.

    “It is not a matter of ‘if,’ but ‘when,’ a cybersecurity incident will happen to your organization,” Messrs. Werntz and Libbey concluded. “It is important to the broader cybersecurity community that we address these matters openly to strengthen trust and foster transparency. Such transparency unlocks opportunities for learning that will enhance not only CISA’s security posture but that of other organizations as well.”

    News: FederalLegislation DataSecurity DataBreach

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use