As cited
Copy frozen at (site build).
regulatory
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
Industry groups told CISA during town halls on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) that they want the rule to cover fewer companies, require fewer incident reports, and demand less detailed information when reporting does occur. The rule, which Congress designed to require critical infrastructure owners to report major cyberattacks within 72 hours and ransomware payments within 24 hours, has missed multiple finalization deadlines, with CISA now targeting September for completion. Industry representatives expressed concerns about the scope affecting over 300,000 entities, the burden of reporting minor intrusion attempts, and the sensitivity of sharing security measure details.
Why it matters: Critical infrastructure operators, risk and compliance teams, and CISA stakeholders should track how much industry feedback shapes the final rule, as a narrower scope or reduced reporting requirements could limit the government's visibility into incidents that affect sector-wide defenses and incident response coordination.
- Source published
- First seen by Cybersecurity Tracker