Firms must report hacks to DHS in 72 hours under law
bloombergquint.com
bloombergquint.com
The ransomware reporting stuff is at the bottom; search for "ransom" and you'll find the section easily.
Note this is amending existing law, so think of it as a legal diff. There may be important context not presented in this text.
Thank you. I thought it was strange that it seemed a little vague what happens when I fail to report an incident. To me, it reads like if I fail to disclose, they can request me to disclose and give me 72 hours. I will be in contempt only after those 72 hours.
So what is the incentive to report before being asked to report? What are the penalties for failure to report?
Also it is not clear to me when that 72 hours starts. Who is the firm? Sometimes things take time to "bubble up" and get prioritized. I am sure there are people who have backlogs that span months.
Thank you in advance for answering if you have a better understanding of the process. (:
This is always the issue with mandatory incident reporting and, in my experience*, regulators tend to be fairly understanding. Generally the rule is the clock starts ticking "upon discovery" of the incident and there's usually a "reasonable likelihood" aspect. So even if you aren't certain a reportable incident has occurred you'd still be required to report an event you've discovered that you're reasonably sure is/may be a breach.
Even that leaves lots of grey area, though. Is it "discovered" when the IT help desk worker comes across it or is it "discovered" when it comes to the attention of senior management? I think in most cases as long as it's timely(ish) reported regulators aren't going to be counting the hours and minutes. If I had an incident where a low-level employee "discovered" it and then sat on it for three days before management found out I'd probably just proactively explain the timeline/delay to the regulator when we reported it and I wouldn't expect it to be much of an issue.
*I'll add the giant caveat that I've only dealt with (comparatively) low-stakes cybersecurity regulatory reporting. I suspect timeliness is much more important to DHS since the goal is national security rather than consumer privacy/preventing crime.
The bad thing is all the security incident response "experts" we will have to endure. Along with all the take my incident response course and such.
> sweeping cybersecurity legislation that will require critical infrastructure operators to quickly report data breaches and ransomware payments.
Pretty expansive though:
> The agency lists 16 broad sectors spanning health, energy, food and transportation as critical to the U.S., although the new legislation is yet to spell out precisely which companies would be required to report cyber incidents.
This data will eventually become public. So long as the DHS database exists it will be hacked eventually.
The public finding out how badly most "critical" companies are at security and integrity is really the best thing that can happen.
> The current impact of the legislation also remains unclear due to lack of definition over exactly which companies will fall under the reporting requirements, which will be clarified in regulation
How is an impacting specific data loss inexplicitly tied to one company's compromise beyond a reasonable doubt when systems everywhere are "leaking"?
Having been involved in several financial compromise events dating back to the very earliest known I find more laws will in no way address the issue. Everyone drives the speed limit or under it too, correct? For those with experience in the financial banking realm the rules often "apply to thee but not to me" and yet companies are still hiding compromise events, even those ‘compliant’. While companies joining the fintech rush are held to standards and requirements that cost significant sums of both time and money all the while the large grandfathered entities and systems are allowed to continue not abiding by the same rules and laws those entities themselves set. Hypocrisy rolls on and exists everywhere and I welcome the changes to level the playing field but more laws are certain to not fix a problem which cannot be seen since the function of vision in our species is the primary driver for nearly all we do. If it cannot be seen then it must not be a 'real' problem so let's schedule more meetings to talk about it.
As the governments around the world continue to have meetings weekly, both publicly and privately, about the ever growing cyber issue I again reiterate that the problem lies at the source(code) and with those who write it. This is truly an issue that can only be solved through education of those writing code and it cannot be solved tomorrow. Let's schedule another meeting to talk about it.
Making a report to police about a crime they won’t understand sounds extremely risky for the reporter.
> The new law mandates that companies report hacks to the U.S. Department of Homeland Security within 72 hours of discovery of the incident, and 24 hours if they make a ransomware payment.
The burden of proof is on the person claiming you discovered it earlier.