logo

US critical infrastructure cyberattack reporting rules inch closer to reality

ID: 6ceecd21-717d-5dc0-823f-de07cfcb4de5

STIX ID: report--6ceecd21-717d-5dc0-823f-de07cfcb4de5

Feed Name: The Register (Security)

Date Published: 2024-03-28

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

CISA has proposed rules to implement CIRCIA, requiring critical infrastructure operators to report substantial cyber incidents within 72 hours and any ransom payments within 24 hours, with submissions expected to include technical details like indicators of compromise, exploited vulnerabilities, and operational impacts; while victim identities will be anonymized, key information will be shared across sectors. The proposal includes limited small-business exemptions, a forthcoming reporting portal and guidance, an April 4 Federal Register publication with a 60-day comment period, and an anticipated final rule within 18 months, amid industry concerns about added compliance burdens and OT security staffing shortages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.