Security News > 2022 > March > US Critical Infrastructure Companies Will Have to Report When They Are Hacked
Companies critical to U.S. national interests will now have to report when they're hacked or they pay ransomware, according to new rules approved by Congress.
The reporting requirement legislation was approved by the House and the Senate on Thursday and is expected to be signed into law by President Joe Biden soon.
It requires any entity that's considered part of the nation's critical infrastructure, which includes the finance, transportation and energy sectors, to report any "Substantial cyber incident" to the government within three days and any ransomware payment made within 24 hours.
Even better would be if they had to report it to the public.
News URL
Related news
- CISA: Network switch RCE flaw impacts critical infrastructure (source)
- AT&T, Verizon reportedly hacked to target US govt wiretapping platform (source)
- Iranian hackers act as brokers selling critical infrastructure access (source)
- U.S. and Allies Warn of Iranian Cyberattacks on Critical Infrastructure in Year-Long Campaign (source)