Skip to Primary Navigation

CISA proposes landmark rule for sweeping cyber incident reporting

Montage of a man at a computer with several other computers nearby.
GRIP Montage: China Photos/Getty Images

CISA has published long-awaited draft rules on how critical-infrastructure companies must report cyberattacks to the government.

In one of the most significant cybersecurity policy reforms in recent memory, the Cybersecurity and Infrastructure Security Agency (CISA, part of the US Department of Homeland Security or DHS) has released its much-anticipated notice of proposed rulemaking (NPOR) to require critical infrastructure organizations to report cybersecurity incidents.

The move is

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience