Security News

Cybersecurity news aggregator

INFO News SC Media

CISA to finalize critical infrastructure cyber incident reporting rule in September

  • What: CISA finalizes rule for critical infrastructure cyber incident reporting
  • Impact: Government enhances visibility into major cyber events affecting essential services
Read Full Article →

Critical Infrastructure Security CISA to finalize critical infrastructure cyber incident reporting rule in September July 7, 2026 Share By SC Staff The Cybersecurity and Infrastructure Security Agency (CISA) is expected to finalize a new rule requiring critical infrastructure providers to report significant cyber incidents directly to the agency by September. This mandate, stemming from the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), aims to enhance the government's visibility into major cyber events affecting essential services, with further coverage provided by Nextgov. The CIRCIA rule mandates that critical infrastructure entities report substantial cyber incidents within 72 hours and ransomware payments within 24 hours. This legislation, which initially passed Congress in 2022, moves from a voluntary reporting system to a mandatory regime, addressing concerns that arose after major attacks like SolarWinds and the Colonial Pipeline incident. The government historically relied on voluntary cooperation, but the new rule aims to provide a clearer picture of threats to U.S. networks. The finalization of the rule has faced delays, including a missed statutory deadline and scheduling issues related to a Department of Homeland Security shutdown, but CISA has engaged in stakeholder discussions to refine the directive. The urgency for such a rule was amplified by fears of cyberattacks on U.S. infrastructure linked to geopolitical conflicts, such as Russia's invasion of Ukraine. Source: Nextgov SC Staff Related Government security U.S. Army websites defaced in apparent 404 hijacking campaign SC Staff July 6, 2026 The defacement targeted error pages on U.S. Army websites, including oil.army.mil and ai2c.army.mil, which belong to the Army’s Open Innovation Lab and Artificial Intelligence Integration Center, respectively. Government security Canada’s spy agency conducted state-authorized cyberattacks against drug traffickers and ransomware gangs SC Staff July 6, 2026 The CSE's annual report details three foreign "active cyber operations" targeting threats to Canadian national security. Government security Washington state CISO Ralph Johnson to step down in September SC Staff July 6, 2026 Washington state's chief information security officer, Ralph Johnson, announced his departure from his role in September. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Virtual Conference Securing the Backbone: Strategies to Counter Cyber Threats to Critical Infrastructure in the Public Sector On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article