Free Cybersecurity Webinar Series: Expert insights on AI, cybersecurity, compliance, and emerging tech. Register today.
April 24, 2024 by FoxPointe Solutions
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) recently released a Notice of Proposed Rule Making (NPRM) detailing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). This proposal mandates that companies report cybersecurity incidents and ransomware payments within strict timelines. Public comments on the NPRM are open until June 3, 2024, and the Final Rule is expected by October 4, 2025.
The forthcoming regulations would require covered entities to inform the federal government of certain cyber incidents within 72 hours of detection and/or within 24 hours of ransomware payment. Financial Institutions are among the entities that would be considered a covered entity under the proposal and would need to comply with the requirements.
The proposed rule outlines several examples of incidents that would require reporting under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). Those include:
While not yet finalized, FoxPointe recommends reviewing your current incident response plans and breach notification programs to begin preparations for potential adjustments. Ensuring your information security program can detect, protect, respond, and recover from cyber incidents is critical. Institutions should also ensure that their third parties also have robust cybersecurity policies and incident response programs.
Please contact FoxPointe Solutions with any questions you may have.
The proposed rule can be found here: https://dd80b675424c132b90b3-e48385e382d2e5d17821a5e1d8e4c86b.ssl.cf1.rackcdn.com/external/2024-06526-1.pdf
This material has been prepared for general, informational purposes only and is not intended to provide, and should not be relied on for, tax, legal or accounting advice. Should you require any such advice, please contact us directly. The information contained herein does not create, and your review or use of the information does not constitute, an accountant-client relationship.