In the wake of the Russian invasion of Ukraine, the federal government is using every tool possible to deter and disrupt retaliatory cyberattacks against critical national infrastructure.
One such tool is the Strengthening American Cybersecurity Act, which the U.S. Senate passed unanimously on March 1, 2022.
The sweeping legislation establishes minimum reporting requirements that would require critical infrastructure entities and federal civilian agencies to report any “substantial cyber incident” (regardless of whether data was breached) to the Cybersecurity and Infrastructure Agency (CISA) within 72 hours and any ransomware payment within 24 hours.
CISA’s definition of critical infrastructure providers is broad and includes the energy sector, financial services, commercial facilities, information technology, healthcare, transportation, chemical manufacturing, the defense industrial base, emergency services, and more.
The Act gives CISA the ability to subpoena any of these entities for a failure to report cyber incidents.
In this blog, we assess how organizations can prepare to comply with the Act’s reporting requirements and recommend best practices they can adopt to improve data collection and understand risk in real-time.