LIVE NEWS
  • Data breach at medical billing firm MCBS affects 1.26 million people
  • Ukrainian Robots Change How Army Endures War, Not Just Save Lives
  • Tate’s attorney says allegations ‘puts a target on their backs’ | Sexual Assault
  • GSK invests £400m to move research centre to Cambridge as Burnham praises ‘vote of confidence’ in UK – business live | Business
  • Australian Army chief leaves legacy and an open door for further professionalisation
  • Make the kids’ summer holidays go with a bang – play together like orangutans | Helen Pilcher
  • Fatal Shooting in ICE Operations | Civil Rights
  • Ondo Recasts Its Blockchain as the Ondo Network
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
Cybersecurity

Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

primereportsBy primereportsJuly 26, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
Share
Facebook Twitter LinkedIn Pinterest Email


Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency about a pending cyber incident notification regulation had a few consistent messages:

We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do. 

CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.

The law was designed to let the feds share information about significant incidents more widely to prepare other would-be victims. CISA published a proposed rule on the law in 2024 to define terms like “covered cyber incident” and more, and industry groups have persistently registered their objections since then.

CISA missed the October 2025 deadline for finalizing the rule, then missed a May reset target date, and now the administration says the rule will be completed in September.

Some industry sources told CyberScoop they consider that unlikely. Most also haven’t received any indications from CISA about how much of the town hall feedback it intends to embrace, they said.

Companies, incidents, information 

Those town hall comments over the course of four June dates were often very direct.

“The rule includes too many companies,” said Grant MacIntyre, director of regulatory affairs and senior attorney at the Auto Care Association. CISA estimated that more than 300,000 entities will be subject to its requirements.

Some industries advocated for their removal entirely, such as two different groups representing elements of the insurance sector. Some sought to reduce the number affected within their sector, such as the Nuclear Energy Institute wanting the list cut down to those already subject to Nuclear Regulatory Commission cybersecurity reporting requirements.

While CISA wrote the regulation with the intention to avoid overburdening small businesses, some feared it wouldn’t work that way in practice.

“The current approach where an entity qualifies either by size or by sector effectively negates the intended limitation on small businesses,” said Douglas Leigh, vice president of legislative affairs for the Alliance for Chemical Distribution. “In chemical distribution, even small entities could be swept in under multiple cyber categories.”

Where the rule specifies what kind of data organizations should report in a major incident, CISA should “seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed,” said Samantha Burch, vice president of technology public policy at government affairs at AHIP, a health insurance industry trade association.

Many, for instance, argued the report should not include information on the affected entities’ security measures.

Others worried about what kind of incidents would trigger reporting requirements.

“My big concern is that you’re going to be asking us to report incidents on every time some foreign entity tickles our firewall, whether they do anything or not, if they just do a ping or a search,” said Tim Pospisil, chief security officer for Nebraska Public Power District. “And that could be extremely burdensome.”

Industry Expectations

One industry representative told CyberScoop that CISA’s willingness to hold town halls, combined with the Trump administration strategy emphasizing “common sense regulation,” was a good sign about where the rule might be heading.

‘They are not picking up on the Biden administration’s approach and tweaking it. They’re thinking, ‘What are the specific pieces of information we need during a cyber incident to help critical infrastructure companies respond?’” said Henry Young, senior director of policy for the Business Software Alliance. “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”

But multiple industry sources said they haven’t gotten many indications about CISA’s intentions. Nor are they optimistic CISA can meet the September target date in the Unified Agenda of Regulatory and Deregulatory Actions.

“It could slip,” one said. “But I think they’re going to try.”

That industry source said they’d like to see a proposal from CISA before it cements anything forever.

Another industry source said it’s hard to trust the September date given past CISA delays, some of which aren’t CISA’s fault, such as dealing with multiple government shutdowns. Some of the delays trace to the Trump administration, given the massive cuts to CISA’s personnel.

Congress is also getting impatient.

The House Appropriations Committee “is concerned about delays in publishing the final CIRCIA rule and urges CISA to finalize it promptly following stakeholder review and feedback,” the panel wrote in the committee report for its fiscal 2027 Department of Homeland Security spending bill.

It’s a much different world than when CISA began writing the rule, something the agency also has to take into account now.

“AI has fundamentally changed the playing field,” the source said. “When this was set up, we didn’t even have the first generation of ChatGPT. We’re now in a mythos class environment.” That’s changed “how quickly we can identify threats, mitigate them, the level of human intervention, potential machine engagement.”

While CISA might have good intentions, past interactions give cause for skepticism about how capable it is of working collaboratively with industry, the source said.

Another industry source said conversations with CISA suggest the agency will look to simplify the regulation to keep it smaller and narrower, then potentially build upon it later.

From CISA’s mouth

Nick Andersen, the acting director of CISA, talked about his overarching intentions with CIRCIA at the town halls.

“CISA does not view CIRCIA as simply a check-the-box compliance exercise,” Andersen said at one. “CIRCIA will enhance visibility into the cyberthreat landscape to enable a robust national early warning capability for critical infrastructure. By quickly reporting covered cyber incidents and ransom payments to CISA, we will be able to provide timely and actionable defensive and eviction measures to your network defenders.”

Asked by CyberScoop about next steps for CIRCIA, and how it might incorporate the industry feedback, a spokesperson provided a statement.

“CISA recognizes the importance of CIRCIA, however, multiple funding lapses impacted CISA’s ability to conduct rulemaking activity for CIRCIA. CISA continues to work on the final rule,” the spokesperson said, adding that 1,200 critical infrastructure stakeholders attended the town halls.  “CISA will continue to communicate updates on the CIRCIA rulemaking process and timeline through CISA.gov/CIRCIA and the Office of Information and Regulatory Affairs’ Unified Agenda of Regulatory and Deregulatory Actions.”

Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleI’m a professional baker and former Trader Joe’s employee. I still head back to the store for these 7 products.
Next Article South Korea’s largest bank brings cross-border payments to Kinexys
primereports
  • Website

Related Posts

Cybersecurity

Data breach at medical billing firm MCBS affects 1.26 million people

July 28, 2026
Cybersecurity

Breaking Affiliate Trust Sped Along LockBit’s Takedown

July 27, 2026
Cybersecurity

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

July 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Data breach at medical billing firm MCBS affects 1.26 million people
  • Ukrainian Robots Change How Army Endures War, Not Just Save Lives
  • Tate’s attorney says allegations ‘puts a target on their backs’ | Sexual Assault
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.