News.Bloomberglaw
CISA Finalizes Cyber Incident Reporting Rules for Critical Infrastructure
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Cybersecurity and Infrastructure Security Agency (CISA) is finalizing rules under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), requiring covered entities to report cyber incidents within 72 hours and ransom payments within 24 hours. The rules will apply to entities in critical infrastructure sectors, including healthcare and energy, even if they do not own critical assets. During town hall meetings, industry representatives expressed concerns about overlapping reporting requirements and the burden of detailed reporting. CISA is accepting feedback on the proposed rules, which are expected to significantly impact incident response planning for affected companies. The rules aim to enhance national cybersecurity by ensuring timely reporting of significant cyber incidents.
Key Points: • CISA's new rules require reporting of cyber incidents within 72 hours. • Entities in critical infrastructure sectors must comply, regardless of asset ownership. • Industry representatives are advocating for limits on the reporting requirements.