Security News > 2022 > March > US Critical Infrastructure Companies Will Have to Report When They Are Hacked

Companies critical to U.S. national interests will now have to report when they're hacked or they pay ransomware, according to new rules approved by Congress.
The reporting requirement legislation was approved by the House and the Senate on Thursday and is expected to be signed into law by President Joe Biden soon.
It requires any entity that's considered part of the nation's critical infrastructure, which includes the finance, transportation and energy sectors, to report any "Substantial cyber incident" to the government within three days and any ransomware payment made within 24 hours.
Even better would be if they had to report it to the public.
News URL
Related news
- US charges Chinese hackers linked to critical infrastructure breaches (source)
- Critical PostgreSQL bug tied to zero-day attack on US Treasury (source)
- 89% of Enterprise GenAI Usage Is Invisible to Organizations Exposing Critical Security Risks, New Report Reveals (source)
- CISA: Medusa ransomware hit over 300 critical infrastructure orgs (source)
- UAT-5918 Targets Taiwan's Critical Infrastructure Using Web Shells and Open-Source Tools (source)