Cybersecurity Dive July 8, 2024
In a last-minute push, critical infrastructure stakeholders urged federal officials to give more flexibility on the detail required during the first 72 hours of covered cyber incidents.
A flurry of critical infrastructure providers are making a final push to urge the Cybersecurity and Infrastructure Security Agency to place guardrails around new incident reporting requirements.
The Cyber Incident Reporting for Critical Infrastructure Act, which will go into effect next year, requires covered critical infrastructure providers to report major security breaches or attacks within 72 hours. Those entities will also have to report ransomware payments within 24 hours.
In pushback against the proposed rule during the public comment period, which was extended to July 3, critical infrastructure providers want to...