Home » Trends » The obsession with faster cybersecurity incident reporting
Trends

The obsession with faster cybersecurity incident reporting

Requirements for reporting cybersecurity incidents to some regulatory or governmental authorities are not new, but there has always been a large number of inconsistencies, worldwide, and exactly what the requirements are. More recently, there has been a growing trend across governmental and regulatory bodies in the U.S. toward shorter time frames for reporting cybersecurity incidents. Here’s a brief overview of recent activity.

At the end of last year, the US Congress passed the National Defense Authorization Act (NDAA). The latest version of the NDAA includes a cybersecurity incident notification rule that only applies to critical infrastructure entities. It sets the final threshold for notifying the Director of the Cybersecurity Incident Review Office, but states that “in no case shall the Director’s report from a covered entity be required earlier than 72 hours after confirmation that a covered cybersecurity incident has occurred. “This part of the legislation, however, has gone through several revisions. The in-house version includes a 72-hour notification that is more widely used, as well as a 24-hour notification requirement for ransomware payments. In mid-March, both the House and the Senate passed a separate bill, the “Cyber ​​Incident Reporting for Critical Infrastructure Act,” including the Consolidated Appropriations Act, which clearly specifies a 72-hour reporting requirement for critical infrastructure entities.

Also at the end of last year, the FDIC was washed into the incident notification pool with a 36-hour necessity. The latter rule was issued by the Federal Deposit Insurance Corporation (FDIC), the Board of Directors of the Federal Reserve System (Board), and the Office of the Comptroller of the Currency (OCC). Affected organizations must comply by May 1, 2022. The National Law Review points out that “[t]its timeline is shorter than any U.S. state data breach notification law and even covers the shortest time frame on U.S. books.

Finally, to reverse this trend, the Securities and Exchange Commission (SEC) issued a proposed rule in March requiring 48 hours’ notification for a subset of covered entities. This rule applies specifically to Registered Investment Advisers (RIAs), Registered Investment Firms (RICs) and Business Development Firms (BDCs). This list excludes other publicly traded companies regulated by the SEC. As this is a proposed rule, it is open for comments for 60 days after publication.

While there is certainly other cybersecurity content in these rules, the focus around notification is over-balanced towards timeliness and away from completeness. Whether it is 72, 48 or 36 hours, no organization will have a full picture of a cybersecurity incident in that time. Investigating an incident takes time, and it is not an easy process. An attacker may have been present in the environment for weeks or months, and disrupting their activity during this time requires skill, diligence, and patience.

A focus on the actuality of the report, without an appropriate focus on completeness, feeds a news cycle that favors headlines across the analysis. Reporting on the recent incident is much more interesting than reporting on the completed analysis of last year’s incident, especially when that analysis is not actually available.

Timely reporting of incidents is valuable. It allows external organizations, whether regulatory bodies or governments, to respond to incidents. It allows for data aggregation, and potentially for understanding larger patterns in the game, which, in turn, allows for faster response to a multi-pronged incident that spans organizations or industries.

Completeness of reporting has equal, if not more, value. By understanding the details of an incident, ideally the entire timeline, both the organization concerned and others can implement controls and mitigations to prevent attacks using similar tools or patterns. Industry organizations can use the data to provide insights. We can see the value of this kind of information today in annual reports like the Verizon Data Breach Investigations report, and in tools like the MITER ATT & CK framework.

However, the detailed data collected on incidents are often incomplete or voluntarily provided. Standards for what a complete incident report contains and methodologies for producing one are usually kept private, for profit organizations. Increasing the baseline on incident investigations benefits everyone, and there are some signs that industry and government will go in that direction.

The launch of the Cyber ​​Safety Review Board as part of CISA promises a new approach to investigating nationally significant incidents, and bringing a new level of transparency to the process. The CSRO is often compared to the National Transportation Safety Board. Over its history, the NTSB has issued more than 14,000 safety recommendations, with a total of 73% of them being accepted by the entities to which they are directed. If the CSRO follows the same path, we can see affected cybersecurity recommendations directly from this more public, more transparent process for investigations.

On a smaller scale, the SEC takes an approach that also addresses completeness and transparency. While the focus of the proposed SEC rule may be on rapid reporting, it also includes an interesting requirement to provide updates within 48 hours “if previously reported information about a significant cybersecurity incident becomes materially inaccurate or if the consultant discovers new material information. in connection with an incident. ” Since the SEC is focused on informing investors about risk, it is possible that this type of information will be more publicly available because of this rule, assuming it is accepted as it is.

With the ever-changing threat environment, increasingly rigorous reporting requirements are likely to spread. It is important that the trend in the timeliness of the report is balanced with emphasis on the quality and completeness of the data.