The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled an updated version of the National Cyber Incident Response Plan (NCIRP), a strategic framework for coordinating how federal, state, local, tribal, and territorial (SLTT) governments, private sector entities, and international partners address significant cyber incidents under Presidential Policy Directive 41 (PPD-41).
This move is a direct response to the increasingly sophisticated cyber threats targeting critical infrastructure and government systems nationwide.
The NCIRP update aligns with the 2023 National Cybersecurity Strategy, which called for a revision of the 2016 version to reflect the current cyber threat landscape, legal developments, and advancements in organizational capabilities.
The revised plan introduces new mechanisms to enhance collaboration across government entities and the private sector, empowering stakeholders to detect, respond to, and recover from significant cyber attacks.
The NCIRP emphasizes flexibility and national unity of effort, recognizing that each cyber incident is unique. While the plan does not provide step-by-step instructions, it offers a clear framework for coordination and partnership during a cyber incident.
The document outlines participants’ potential roles, decision-making processes, and key response activities across the incident lifecycle.
CISA encourages the private sector, SLTT governments, and civil society organizations to review the updated NCIRP and integrate its principles into their own cybersecurity planning and operations.
The plan is structured around four key “lines of effort” (LOEs), each managed by designated lead agencies:
The NCIRP also integrates insights from other federal frameworks, such as the Federal Emergency Management Agency’s (FEMA) National Response Framework, to address incidents with broader consequences beyond cyberspace, such as disruptions to critical physical infrastructure or risks to public health.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
To address the growing complexity of cyber incidents, the NCIRP defines two key coordination structures:
These structures are activated based on the severity and impact of an incident, as determined by the Cyber Incident Severity Schema, which assesses incidents on a five-level scale. Significant incidents (Level 3 and above) require full implementation of the NCIRP’s coordinating mechanisms.
The NCIRP divides cyber incident response into two primary phases:
Following a major cyber incident, the NCIRP emphasizes the importance of capturing and implementing lessons learned to improve future response efforts.
Reviews led by the CRG and other entities, such as the Cyber Safety Review Board established under Executive Order 14028, will evaluate the effectiveness of the response and recommend improvements.
The update comes amid heightened concerns about foreign cyber threats. During a congressional hearing earlier this year, CISA Director Jen Easterly warned of advanced persistent threats from nation-state actors, including Chinese groups like “Volt Typhoon,” which have reportedly infiltrated U.S. critical infrastructure. The revised NCIRP aims to bolster the nation’s ability to detect and respond to such attacks swiftly.
CISA is urging organizations across sectors to integrate the NCIRP into their cybersecurity planning and operations.
This includes adopting best practices for incident reporting, developing relationships with key agencies and sector-specific risk management entities, and participating in collaborative initiatives such as the Joint Cyber Defense Collaborative (JCDC).
As cyber threats continue to evolve, CISA has committed to regularly updating the NCIRP to ensure it remains a practical and effective tool for coordinating national responses to cyber incidents.
The agency also plans to develop additional resources, such as sector-specific annexes and contingency plans, to further enhance preparedness.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…