Fisherphillips Upcoming Federal Cyber Incident Reporting Rules Set for Implementation
Article Content
- •CISA's new rules require reporting of cyber incidents within 72 hours and ransomware payments within 24 hours.
- •Over 300,000 entities across 16 critical infrastructure sectors will be affected by these regulations.
- •Delays in finalizing the rules may impact businesses' ability to comply effectively.
The Cybersecurity and Infrastructure Security Agency (CISA) is finalizing new federal rules under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which mandates that over 300,000 businesses across 16 critical infrastructure sectors report substantial cyber incidents within 72 hours and ransomware payments within 24 hours. The rules aim to transition from voluntary reporting to a formal enforcement regime, with potential civil penalties for non-compliance. Although the final rules were expected by May 2026, recent funding disruptions and staff shortages have delayed the timeline, raising concerns about the clarity and feasibility of the reporting obligations. Businesses are advised to prepare proactively to meet the stringent reporting deadlines once the rules are enacted. The proposed definitions and reporting thresholds have faced criticism from industry stakeholders, indicating that further adjustments may be necessary. CISA's expectations for compliance remain high despite the delays in rule finalization.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…