Before You Read: This blog is about the original Cyber Incident Reporting Act and may contain outdated information. For an updated overview of the CIRCIA requirements, see our blog: A Financial Institution's Guide to CISA's Proposed CIRCIA Reporting Requirements.
On March 15, 2022, the Consolidated Appropriations Act of 2022 (H.R.2471) was signed into law. Division Y of the act is titled the "Cyber Incident Reporting for Critical Infrastructure Act of 2022" (a.k.a., "Cyber Incident Reporting Act"). As the title implies, the act has created new cyber incident reporting requirements for businesses who are deemed to be part of America's "critical infrastructure" sectors.
In this article, we will dive into the requirements of the act and discuss answers to questions, like:
The Consolidated Appropriations Act of 2022 was introduced into the House of Representatives on April 13, 2021. However, the Cyber Incident Reporting Act text was not added to the act until the Engrossed Amendment House (EAH) on March 9, 2022, six days before the act was signed into law.
The Cyber Incident Reporting Act text originated with another act titled the "Strengthening American Cybersecurity Act of 2022" (S.3600). Essentially, Congress copied Title II from S.3600 and pasted it into Division Y of H.R.2471, giving us the act as we now know it.
The new law defines the term "critical infrastructure" using the definition from Presidential Policy Directive 21. As summarized by the Cybersecurity and Infrastructure Security Agency (a.k.a., "CISA" or "the Agency"), these sectors include:
If you are a business who would fall under one of these categories, then the new law does apply to you.
The act defines a "cyber incident" as:
"An occurrence that actually jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information [or] an information system."
For those of you interested in the legal jargon, the definition is nearly identical to the legal definition of "incident" established in 6 USC 659(a), except that it leaves out the concept of "imminent" jeopardization and focuses only on "actual" compromise.
In Section 2242(c)(2), the act goes on to describe several examples of "substantial" cyber incidents which would be subject to the new act. These incidents include denial-of-service (DoS) attacks, ransomware attacks, exploitation of zero-day vulnerabilities, and the compromise of third parties (e.g., cloud service providers, managed service providers, supply chain, etc.).
In short, the definition is very broad and could apply to nearly any incident which causes "actual" harm to the organization and/or to the organization's customers.
In simplest form, there are two new reporting requirements:
While there are details regarding what must be included in each report, the act does not provide any further detail regarding how these reports are to be made. Instead, the act tasks the CISA Director to partner with other agencies to publish a Notice of Proposed Rulemaking in the Federal Register within 24 months of the act being signed into law.
Not necessarily, but there is hope.
Legally, there is nothing you are expected to do to comply. You will not be required to take any action until the Notice of Proposed Rulemaking is published in the Federal Register at some point within the next two years.
CISA will be conducting an outreach program (per Section 2242(e)) to communicate with affected entities regarding topics related to the final rule, including how to submit the required reports.
As a first step in this outreach program, on April 7, 2022, CISA published Guidance on Sharing Cyber Incident Information. The fact sheet includes resources, such as:
While reporting to CISA is not currently required, CISA encourages businesses to "voluntarily share information about cyber-related events that could help mitigate current or emerging cybersecurity threats to critical infrastructure."
Once the final rule is published in the Federal Register, applicable features in Tandem will be updated to include the required notification, including our Incident Management Communication Guidelines, as well as our Incident Management Policy. All changes will be published to the Software Updates blog.
Additionally, this article will be updated as new information becomes available, so be sure to check back for the latest status updates.
At Tandem, it is our goal to ease the burden of regulatory compliance. If you do not use Tandem and would like to see how we can help, not just with this new act, but with GLBA compliance and beyond, visit our website at Tandem.App.
Update Log: