To an unaware observer, Cyber Storm V would look pretty undramatic: A group of people in a room, using laptops to graze websites, occasionally fielding a phone call.
In reality, though, the participants were detecting simulated malware attacks and countering them, as part of the Homeland Security Department’s biennial exercise, which took place partly at the U.S. Secret Service headquarters in Washington and partly in remote locations involving participants around the country and in several foreign nations.
Cyber Storm V builds on previous exercises, said Gregory Touhill, the DHS deputy assistant secretary in charge of cyber and communications. It is an effort to gauge the cyber posture of various sectors such as the retail industry and health care.
The first three Cyber Storm events — in 2006, 2008 and 2010 — were “capstone” events, a series of exercises taking place within a short period of time. DHS departed from that format for Cyber Storm IV, which included 15 smaller-scale exercises and lasted from late 2011 to early 2014. Cyber Storm V returns to the capstone model.
The goal, regardless of the format, is to test and strengthen the human element of cybersecurity, the strategy and planning rather than specific technologies.
“Cybersecurity is all about risk,” Touhill said. “It’s not the technology. The technology is going to change.”
The exercise seeks to find the “failure points” in the defensive measures the sectors take, and to use that information to make improvements, he said. It includes analysis of processes and procedures, with an emphasis on information sharing and training.
The exercise will end Friday with a “hot wash,” a gathering of the main partners to discuss lessons learned.




