Don’t do SECURITY. Do business SECURELY.

US Cyber Incident Reporting for Critical Infrastructure Act signed

CIRCIA will require US critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) has today been signed into law in the United States, as part of the Consolidated Appropriations Act 2022.

Key points

  • Covered entities will have to report covered cyber incidents to CISA within 72 hours.
  • Ransom payments will have to be reported within 24 hours.
  • Related data must be preserved.
  • The detailed requirements, including who is covered, will be set by CISA in a final rule.

UK organisations with US operations in critical infrastructure sectors, or providing services to US operators, should start preparing their incident classification and reporting processes.

Source: Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CISA)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights