AP

Hacked US companies to face new reporting requirements

Mar 11, 2022, 10:01 AM | Updated: Mar 15, 2022, 9:13 am

WASHINGTON (AP) — Companies critical to U.S. national interests will now have to report when they’re hacked or they pay ransomware, according to new rules approved by Congress.

The rules are part of a broader effort by the Biden administration and Congress to shore up the nation’s cyberdefenses after a series of high-profile digital espionage campaigns and disruptive ransomware attacks. The reporting will give the federal government much greater visibility into hacking efforts that target private companies, which often have skipped going to the FBI or other agencies for help.

“It’s clear we must take bold action to improve our online defenses,” Sen. Gary Peters, a Michigan Democrat who leads the Senate Homeland Security and Government Affairs Committee and wrote the legislation, said in a statement on Friday.

The reporting requirement legislation was approved by the House and the Senate on Thursday and is expected to be signed into law by President Joe Biden soon. It requires any entity that’s considered part of the nation’s critical infrastructure, which includes the finance, transportation and energy sectors, to report any “substantial cyber incident” to the government within three days and any ransomware payment made within 24 hours.

Ransomware attacks, in which criminals hack targets and hold their data hostage through encryption until ransoms have been paid, have flourished in recent years. Attacks last year on the world’s largest meat-packing company and the biggest U.S. fuel pipeline — which led to days of gas station shortages on the East Coast — have underscored how gangs of extortionist hackers can disrupt the economy and put lives and livelihoods at risk.

State hackers from Russia and China have had continued success hacking into and spying on U.S. targets, including critical infrastructure targets. The most notable was Russia’s SolarWinds cyberespionage campaign, which was discovered at the end of 2020.

Experts and government officials worry that Russia’s war in Ukraine has increased the threat of cyberattacks against U.S. targets, by either state or proxy actors. Many ransomware operators live and work in Russia.

“As our nation rightly supports Ukraine during Russia’s illegal unjustifiable assault, I am concerned the threat of Russian cyber and ransomware attacks against U.S. critical infrastructure will increase,” said Sen. Rob Portman, a Republican from Ohio.

The legislation designates the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency as the lead agency to receive notices of hacks and ransomware payments. That caused concern at the FBI, which had openly campaigned for tweaks to the bill in an unusually public disagreement over legislation endorsed overall by the White House.

“We want one call to be a call to us all,” FBI Director Christopher Wray said last week at a cyber event at the University of Kansas. “What’s needed is not a whole bunch of different reporting but real-time access by all the people who need to have it to the same report. So that’s what we’re talking about — not multiple reporting chains but multiple access, multiple contemporaneous action, to the information.”

The FBI also has expressed concern that liability protections that would cover companies that report a breach to CISA would not extend to reporting a breach to the FBI, an issue the bureau believes could unnecessarily complicate law enforcement efforts to respond to hacks and to aid victims.

Lawmakers who helped write the bill have pushed back against the FBI, saying the bureau’s concerns about being notified of hacks and liability concerns were adequately addressed in the final version of it.

The new rules also empower CISA to subpoena companies that fail to report hacks or ransomware payments, and those that fail to comply with a subpoena could be referred to the Justice Department for investigation.

___

Suderman reported from Richmond, Va.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Asylum processing for new migrants: Changes could come soon...

Associated Press

The Biden administration is planning more changes to quicken asylum processing for new migrants

The Biden administration is planning to quicken the asylum processing for new migrants as an interim step rather than an executive order.

8 hours ago

Record-setting rally for U.S. stocks reflects inflation slowing down...

Associated Press

Stock market today: Asian shares advance after another round of Wall St records

The S&P 500 jumped 1.2% to top its prior high set a month and a half ago. This move reflects a record-setting rally for U.S. stocks.

9 hours ago

This combo image shows President Joe Biden, left, Jan. 5, 2024, and Republican presidential candida...

Associated Press

Biden and Trump agree to hold presidential debates in June and in September

President Joe Biden and former President Donald Trump have agreed to hold two campaign debates, on June 27 hosted by CNN and on Sept. 10 hosted by ABC.

13 hours ago

Michael Cohen testified Tuesday: Check stubs, fake receipts...

Associated Press

Check stubs, fake receipts, blind loyalty: Cohen offers inside knowledge in Trump’s hush money trial

Check stubs, fake receipts and blind loyalty were all pivotal in Donald Trump's hush money schemes, lawyer Michael Cohen testified Tuesday.

1 day ago

Dorothy Jean Tillman II graduated ASU at 17...

Associated Press

17-year-old ‘genius’ graduates from ASU with doctorate in integrated behavioral health

Dorothy Jean Tillman II entered college at the age of 10. This year, she earned a doctorate from Arizona State University at 17 years old.

1 day ago

Airlines are suing the Biden administration over legislation change...

Associated Press

US airlines are suing the Biden administration over a new rule to make certain fees easier to spot

Multiple U.S. airlines are suing the Biden administration over a new rule that would require them to be more transparent about fees.

2 days ago

Sponsored Articles

...

DESERT INSTITUTE FOR SPINE CARE

Desert Institute for Spine Care is the place for weekend warriors to fix their back pain

Spring has sprung and nothing is better than March in Arizona. The temperatures are perfect and with the beautiful weather, Arizona has become a hotbed for hikers, runners, golfers, pickleball players and all types of weekend warriors.

...

COLLINS COMFORT MASTERS

Here are 5 things Arizona residents need to know about their HVAC system

It's warming back up in the Valley, which means it's time to think about your air conditioning system's preparedness for summer.

...

Collins Comfort Masters

Here’s 1 way to ensure your family is drinking safe water

Water is maybe one of the most important resources in our lives, and especially if you have kids, you want them to have access to safe water.

Hacked US companies to face new reporting requirements