Newly Proposed Rule Expanding Cyber Incident Reporting to Affect Financial Services Companies

ArentFox Schiff – Recently, the US Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) issued a notice of proposed rulemaking, which, if adopted, would require “covered entities” of critical infrastructure to report “substantial cyber incidents” to CISA within 72 hours, and to report ransomware payments within 24 hours.
🔒 Members Only · Compliance & Enforcement BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every case digest, six days a week.
$750/year
