Security News > 2022 > March > US Critical Infrastructure Companies Will Have to Report When They Are Hacked

Companies critical to U.S. national interests will now have to report when they're hacked or they pay ransomware, according to new rules approved by Congress.
The reporting requirement legislation was approved by the House and the Senate on Thursday and is expected to be signed into law by President Joe Biden soon.
It requires any entity that's considered part of the nation's critical infrastructure, which includes the finance, transportation and energy sectors, to report any "Substantial cyber incident" to the government within three days and any ransomware payment made within 24 hours.
Even better would be if they had to report it to the public.
News URL
Related news
- China reportedly admitted directing cyberattacks on US infrastructure (source)
- CISA warns of hackers targeting critical oil infrastructure (source)
- Majority of Browser Extensions Pose Critical Security Risk, A New Report Reveals (source)
- Kubernetes has grown up: From testbed to critical infrastructure (source)