CISA to Finalize Cyber Incident Reporting Rule for Critical Infrastructure in September
The Cybersecurity and Infrastructure Security Agency (CISA) is set to release its final rule for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) this September. This forthcoming regulation will mandate that companies operating across 16 critical infrastructure sectors report covered cyber incidents within 72 hours and ransomware payments within 24 hours. The rule is expected to apply to a significant number of entities, potentially over 300,000, based on sector categories and Small Business Administration size thresholds. CISA held virtual town halls in June where industry stakeholders raised concerns regarding the broad definition of 'covered entity,' what constitutes a 'substantial cyber incident,' the amount of information CISA might request, and how these new rules will overlap with existing reporting obligations. The agency emphasizes the importance of prompt notice, evidence preservation, and cooperation with managed security providers, forensic vendors, and outside cybersecurit...