Reading view

There are new articles available, click to refresh the page.

Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency about a pending cyber incident notification regulation had a few consistent messages:

We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do. 

CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.

The law was designed to let the feds share information about significant incidents more widely to prepare other would-be victims. CISA published a proposed rule on the law in 2024 to define terms like “covered cyber incident” and more, and industry groups have persistently registered their objections since then.

CISA missed the October 2025 deadline for finalizing the rule, then missed a May reset target date, and now the administration says the rule will be completed in September.

Some industry sources told CyberScoop they consider that unlikely. Most also haven’t received any indications from CISA about how much of the town hall feedback it intends to embrace, they said.

Companies, incidents, information 

Those town hall comments over the course of four June dates were often very direct.

“The rule includes too many companies,” said Grant MacIntyre, director of regulatory affairs and senior attorney at the Auto Care Association. CISA estimated that more than 300,000 entities will be subject to its requirements.

Some industries advocated for their removal entirely, such as two different groups representing elements of the insurance sector. Some sought to reduce the number affected within their sector, such as the Nuclear Energy Institute wanting the list cut down to those already subject to Nuclear Regulatory Commission cybersecurity reporting requirements.

While CISA wrote the regulation with the intention to avoid overburdening small businesses, some feared it wouldn’t work that way in practice.

“The current approach where an entity qualifies either by size or by sector effectively negates the intended limitation on small businesses,” said Douglas Leigh, vice president of legislative affairs for the Alliance for Chemical Distribution. “In chemical distribution, even small entities could be swept in under multiple cyber categories.”

Where the rule specifies what kind of data organizations should report in a major incident, CISA should “seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed,” said Samantha Burch, vice president of technology public policy at government affairs at AHIP, a health insurance industry trade association.

Many, for instance, argued the report should not include information on the affected entities’ security measures.

Others worried about what kind of incidents would trigger reporting requirements.

“My big concern is that you’re going to be asking us to report incidents on every time some foreign entity tickles our firewall, whether they do anything or not, if they just do a ping or a search,” said Tim Pospisil, chief security officer for Nebraska Public Power District. “And that could be extremely burdensome.”

Industry Expectations

One industry representative told CyberScoop that CISA’s willingness to hold town halls, combined with the Trump administration strategy emphasizing “common sense regulation,” was a good sign about where the rule might be heading.

‘They are not picking up on the Biden administration’s approach and tweaking it. They’re thinking, ‘What are the specific pieces of information we need during a cyber incident to help critical infrastructure companies respond?’” said Henry Young, senior director of policy for the Business Software Alliance. “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”

But multiple industry sources said they haven’t gotten many indications about CISA’s intentions. Nor are they optimistic CISA can meet the September target date in the Unified Agenda of Regulatory and Deregulatory Actions.

“It could slip,” one said. “But I think they’re going to try.”

That industry source said they’d like to see a proposal from CISA before it cements anything forever.

Another industry source said it’s hard to trust the September date given past CISA delays, some of which aren’t CISA’s fault, such as dealing with multiple government shutdowns. Some of the delays trace to the Trump administration, given the massive cuts to CISA’s personnel.

Congress is also getting impatient.

The House Appropriations Committee “is concerned about delays in publishing the final CIRCIA rule and urges CISA to finalize it promptly following stakeholder review and feedback,” the panel wrote in the committee report for its fiscal 2027 Department of Homeland Security spending bill.

It’s a much different world than when CISA began writing the rule, something the agency also has to take into account now.

“AI has fundamentally changed the playing field,” the source said. “When this was set up, we didn’t even have the first generation of ChatGPT. We’re now in a mythos class environment.” That’s changed “how quickly we can identify threats, mitigate them, the level of human intervention, potential machine engagement.”

While CISA might have good intentions, past interactions give cause for skepticism about how capable it is of working collaboratively with industry, the source said.

Another industry source said conversations with CISA suggest the agency will look to simplify the regulation to keep it smaller and narrower, then potentially build upon it later.

From CISA’s mouth

Nick Andersen, the acting director of CISA, talked about his overarching intentions with CIRCIA at the town halls.

“CISA does not view CIRCIA as simply a check-the-box compliance exercise,” Andersen said at one. “CIRCIA will enhance visibility into the cyberthreat landscape to enable a robust national early warning capability for critical infrastructure. By quickly reporting covered cyber incidents and ransom payments to CISA, we will be able to provide timely and actionable defensive and eviction measures to your network defenders.”

Asked by CyberScoop about next steps for CIRCIA, and how it might incorporate the industry feedback, a spokesperson provided a statement.

“CISA recognizes the importance of CIRCIA, however, multiple funding lapses impacted CISA’s ability to conduct rulemaking activity for CIRCIA. CISA continues to work on the final rule,” the spokesperson said, adding that 1,200 critical infrastructure stakeholders attended the town halls.  “CISA will continue to communicate updates on the CIRCIA rulemaking process and timeline through CISA.gov/CIRCIA and the Office of Information and Regulatory Affairs’ Unified Agenda of Regulatory and Deregulatory Actions.”

The post Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks appeared first on CyberScoop.

Most federal cybersecurity reporting rules are duplicative, study finds

Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.

And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.

At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”

The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.

The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D-Mich.

In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.

Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted.

A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals.

But the executive branch paused some of those efforts after Trump issued an executive order in March of last year while the administration conducted a study of the 2024 memo, a study that was still underway as of last month, according to the GAO.

As such, on harmonization, “many past federal efforts have experienced delays and made limited progress,” the GAO concluded in its report Wednesday, its latest on the topic

Congress has also looked at ways to streamline cybersecurity regulations.

GAO’s study was focused only on federal rules. BreachRx, a cyber incident response firm, published its own report Wednesday looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.

The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector

The Cybersecurity and Infrastructure Agency wants to fundamentally reevaluate how it prioritizes risks and vulnerabilities, both for privately-owned critical infrastructure and within the federal government, acting director Nick Andersen said Tuesday.

The plans include a binding operational directive for federal agencies set to be published Wednesday and getting more specific with critical infrastructure owners and operators about which assets they need to protect most and how, Andersen said while speaking at an event hosted by Axonius in Washington, D.C. and talking with reporters afterwards.

The binding operational directive looks to revise how federal agencies do vulnerability management, he said. “Overall, our approach to date has been ‘A patch is released, apply this patch as quickly as you can,’” he said.

“We’re really asking people to take more of a focus on risk associated with each vulnerability. Is it with an asset that is internet-exposed? Does it align to a KEV entry?” he said, referring to CISA’s list of known exploited vulnerabilities. “Is it automatable in its exploitation? Really, we need to be able to highlight that some patches just aren’t as important as others, and plugging the holes for some vulnerabilities is simply not as important as others.”

Andersen said he has made setting the right priorities the focus of his tenure.

“We have to be okay with saying there are some systems that are less important than others, there are some elements of critical infrastructure that are less important than others,” he said. “Those things are very easy for us to rationalize [for] physical crises, but we need to start wrapping our minds around how we’re going to do that during cyber crises.”

Andersen said artificial intelligence-enhanced threats have fueled the directive in part, based on “a recognition that we’re a different dynamic environment with the shorter timeline to weaponization and exploitation,” but the discussions on the directive have been going on for months, before the splashy announcements about frontier AI models and the risks they might deepen. Wednesday’s directive is unrelated to the AI-focused executive order released by the Trump administration last week.

The idea of prioritizing certain potential hacking targets over others isn’t a new one in critical infrastructure, with concepts like “Section 9” designations under a 2013 executive order for entities whom an attack upon could have catastrophic effects; “systemically important critical infrastructure” designations, as recommended by the Cyberspace Solarium Commission; or the creation of the National Risk Management Center established during President Donald Trump’s first term but now the subject of proposed budget cuts.

Andersen said past concepts haven’t worked well, citing Section 9 designations as an example.

“We would sit here and say, ‘Congratulations, you’re with this company, and you’re a Section 9 entity, isn’t that fantastic?’” he said. “That’s really not the level of fidelity that we have to be able to get to to have a real measurable conversation about risk. I need to be able to go to a company and say, ‘Here’s the specific function you’re supporting that makes you more critical. Let’s have a conversation about the specific assets that support that function, and how do we get to a measurable level of resilience for those assets?’”

Those discussions need to get down to a “fine grain,” Andersen said.

“If I’ve got a major bank that I’m talking to, is it as important to me that the bank’s process that supports the bulk payment system is resilient, or is it just as important to me that the branch location two blocks away is continuing to operate?” he said. “Those things just are apples and oranges, even though it’s the same entity that might be affected.”

CISA’s capabilities under the Trump administration have drawn considerable scrutiny, given deep budget cuts at the agency, with more planned. The administration is now making moves to hire back personnel.

Andersen said the agency is working to hire 329 people, and will have job offers out to 182 of them by the end of June. He said the emphasis of the first tranche of hires under the hiring sprint is operational capabilities, meaning areas like emergency communications, infrastructure security and regional personnel.

The agency also has had some of its work hampered by the government shutdowns, such as the delay in plans for town-hall meetings about implementation of the Cyber Incident Reporting for Critical Infrastructure Act of 2022, which will require key owners and operators to report major incidents within 72 hours.

Andersen said he couldn’t set a date for finalization of regulations related to the law — which had already been delayed prior to any funding lapses — with those town halls now scheduled to begin next week.

“We could have a lot of comments that come to us and really radically change our way of thinking about what the need is here,” he said. “But our focus is just on what’s the original congressional intent behind CIRCIA. what is the greatest need that we’re going to be able to serve, and how it’s going to be able to further the mission that we have for the nation.”

The post CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector appeared first on CyberScoop.

❌