More than a dozen critical infrastructure sectors are now required to report cyberattacks within days or hours of their discovery. But, with a new warning released this week about an increase in possible Russia-backed cyberattacks against private U.S. enterprises, will the federal government extend those reporting requirements to more private sector entities?
Last week, President Joe Biden signed an omnibus spending bill into law that includes support for the Cyber Incident Reporting for Critical Infrastructure Act, which is part of the Strengthening American Cybersecurity Act of 2022. It mandates that operators report a cyberattack to the Cybersecurity & Infrastructure Security Agency (CISA) within 72 hours and a ransomware payment within 24 hours.
Currently, the reporting requirements only cover 16 critical infrastructure sectors identified in Presidential Policy Directive 21 (PPD-21), spanning government facilities, health care, transportation, energy, and water systems.
“With the dramatic increase in cyberattacks on natural gas suppliers and exporters and the corresponding stream of threats in parallel sectors, such as nuclear, water, and electric power generation and transmission, the reporting requirements are timely,” said Jim McKenney, practice director at IT security advisory firm NCC Group.
McKenney explained that even for large and well-resourced organizations, the 72-hour reporting requirement can be challenging. He noted that two main challenges that critical infrastructure operators face will be “resource constraints for operators to obtain and maintain cyber incident processes, and lack of tooling and instrumentation in operational technology environments."
Tom Kellermann, head of cybersecurity strategy at VMware, called it “truly a game-changing piece of legislation,” adding that it “finally created a federal data breach law, meaning organizations can no longer hide behind implausibility and deny responsibility.”
How to Address Cyber Incident Reporting Challenges?For those that are resource constrained, McKenney suggested operators run cyberattack response tabletop exercises with their OT environment partners to “rightsize” the response plan with the necessary tools, processes, and people.
He added that the new CISA funding opens an opportunity for the agency to help critical infrastructure owners and operators respond quickly with actionable information by establishing a feedback mechanism. This also “helps turn reporting into more than simply another step to execute during a cyber incident,” he added.
On top of the free services and tools that CISA is currently offering, Kellermann said a great next step would be “for CISA to distribute virtual patches to their constituency to defend against zero days” in wake of over 140 high severity vulnerabilities exploited over the past year.
Organizations also should take a page from CISA’s book to understand and implement basic cybersecurity measures, Kate Kuehn, SVP at vArmour, wrote in response to questions.
“Every organization should review their cyber hygiene and get full observability into their application, user, and data relationships from a workload perspective, as well as the subsequent blast radius,” Kuehn wrote. And “they should have a resiliency plan in place for quick remediation as soon as new CVEs are released.”
Are the Public Companies Next?Kellermann expects the requirements will expand to other private sectors starting with public companies. “I think the SEC is gonna mandate the same reporting requirements for publicly traded companies very soon,” he said.
The SEC earlier this month proposed a cyberattack disclosure requirement for public companies. Kellermann said he expects other financial regulators will follow suit in proposing similar regulations to shared service providers. However, “beyond that, I'm not sure if there's going to be any true movement in the next year,” he said.
If the SEC rule is enacted, Kellermann recommends that public companies hire a CISO or a CSO directly reporting to the CEO and provide that office with budget and authority for cyber protection and defense, and also to invest heavily in extended detection response (XDR) across their infrastructure.
For companies that are not yet regulated, he noted that “it is to their competitive advantage to invest in cybersecurity to ensure that their customers and partners are safe when they use their capabilities.”
Is the Cyberattack Report Requirement Realistic?The U.S. is far from the first country to require timely cyberattack reporting.
“Multinational companies like Cisco that currently do business in Europe recognize that the 72-hour incident reporting requirement is consistent with timelines required in many countries for reporting data protection incidents,” said Eric Wenger, senior director for technology policy at Cisco Systems. “And the shorter 24-hour deadline for ransom payment reporting is reasonable given the requirement is triggered by a discrete event—transmitting funds."
Illumio CEO and co-founder Andrew Rubin added that organizations have historically also been hesitant to report breaches publicly due to commercial reasons. “It’s understandable … it can lead to damages to brand reputation, a loss of consumer trust, etc.”
But the potential benefits of the reporting outweighed the challenges, cybersecurity practitioners noted.
“By not reporting breaches, we’re missing out on the ability to get ahead of attackers and innovate together,” Rubin said. “Attacks on critical infrastructure can have real-world consequences on both essential operations and human lives.”
“In today's environment, particularly within Linux platforms, the adversaries … manifest these long-term systemic cybercrime conspiracies or espionage conspiracies after being within systems for days, if not weeks, so you need to shrink that dwell time,” Kellermann said. “I think [reporting within] 72 hours is very important because some segment of your information supply chain has been compromised in real time.”
Comments