Critical infrastructure owners and operators would be required to report a cyber attack within 72 hours to the Cybersecurity and Infrastructure Security Agency (CISA) if a newly-introduced Senate bill becomes law.The Cyber Incident Reporting Act also requires federal contractors--including MSSPs, MSPs and managed detection and response (MDR) service providers--along with government agencies, companies of more than 50 employees and other organizations to report to CISA within 24 hours of making a ransom payment.A separate measure is forthcoming to update the Federal Information Security Modernization Act that requires federal agencies and contractors to report cyber attacks.Peters minced no words in describing the threat the nation faces from ransomware hackers and the necessity for timely incident reporting. “The scourge of cyber-attacks that have disrupted the lives of countless Americans shows we are facing a crisis we are not fully prepared to address,” he said. “When entities – such as critical infrastructure owners and operators – fall victim to network breaches or pay hackers to unlock their systems, they must notify the federal government so we can warn others, prepare for the potential impacts, and help prevent other widespread attacks.”
Cyber Incident Disclosure Legislation: What's Proposed?
The bipartisan legislation, proposed by Gary Peters (D-MI), who chairs the Homeland Security and Governmental Affairs Committee and ranking member Rob Portman (R-OH), means to set cyber incident reporting standards at the federal level where previously none have existed. The bill, segments of which have been brewing in Congress for months, comes on the heels of multiple ransomware attacks aimed at the nation’s vital infrastructure, including the Colonial Pipeline energy hijack, the JBS food processor lock down and the recent New Cooperative agricultural freeze out. Both CISA director Jen Easterly and National Cyber Director Chris Inglis have repeatedly voiced support for federal reporting requirements as well as enforcement mechanisms.Here’s what in the bill:- Requires critical infrastructure owners and operators to notify CISA within 72 hours of a cyber incident.
- Requires federal contractors, including service providers and other organizations, to report to CISA within 24 hours after making a ransom payment. Entities would be required to explore alternatives before meeting ransom demands.
- Establishes a Cyber Incident Review Office to access reports related to cyber incidents, including tracking ransom payments and ransomware attacks, facilitating cyber attack information sharing among federal agencies and publishing quarterly unclassified reports.
- Requires the CISA director to submit to the National Cyber Director and Congressional leaders a monthly status update report on cybersecurity incidents and other related information.
- Requires CISA to conduct an outreach and education campaign to help organizations affected by a ransomware attack.
- Grants CISA subpoena power to demand an incident report from an entity hit by a cyber attack or making a ransom payment.
- Allows the federal government to share incident information with other federal agencies.
- Protects submitted information with established data security policies.
- Establishes a pilot program to identify security vulnerabilities that hackers could exploit and to notify owners of those system weaknesses.
- Establishes a joint ransomware task force to coordinate an ongoing, nationwide campaign against ransomware attacks and solicit international cooperation.