CISA releases draft rule for cyber incident reporting
ID: 8e248767-0afd-5dc6-8b51-7a04491158b7
STIX ID: report--8e248767-0afd-5dc6-8b51-7a04491158b7
Feed Name: CyberScoop
CISA released a proposed rule under CIRCIA to require critical infrastructure entities to report cyber incidents within 72 hours and ransomware payments within 24 hours, with sector-specific criteria, exceptions, and broad applicability to organizations supplying IT products or services to the federal government. The proposal aims to improve threat visibility and enable trend analysis and coordinated response, forecasts around 25,000 reports annually and a combined cost of $2.6 billion through 2033, and must be finalized after public comment. Observers highlight potential gaps due to size thresholds (such as smaller hospitals), reliance on outdated sector plans, and resource challenges for entities like community water systems, while noting potential overlap with SEC breach disclosure rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
