USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields
as encryption, multifactor authentication and third- party cybersecurity assessments. 2.3 Incident Response and Notification Obligations In the USA, incident response and notification obliga - tions for critical infrastructure owners and operators are primarily governed by sector-specific regulations. CIRCIA requirements are intended to apply in addition to, not in replacement of, these sector-specific obli - gations. If the CIRCIA regulations are finalised, they will require: • cyber-incident reporting – covered entities must report covered cyber-incidents to CISA within 72 hours of determining that a covered incident has occurred; and • ransomware payment reporting – entities must notify CISA within 24 hours of making a ransom - ware payment. These requirements aim to enable CISA to better co-ordinate incident response efforts and facilitate information sharing between government and pri - vate-sector stakeholders. Despite the comprehensive framework, several uncertainties remain, as follows. • Covered entities – CISA’s forthcoming regulations will determine which organisations within each sector are subject to CIRCIA obligations. Small or ancillary entities may be unsure whether they fall within the scope. • Incident thresholds – CIRCIA has not finalised what constitutes a “covered cyber-incident”. Without CISA’s finalised guidance, entities lack clarity on reporting triggers. • Overlapping regulations – entities operating in multiple sectors may face overlapping obligations under federal and sector-specific frameworks (eg, HIPAA versus CIRCIA). • Liability protections – while CIRCIA provides limited liability protections for reporting entities, questions remain about their interaction with confidential - ity obligations under other frameworks, such as HIPAA or NRC regulations. • International implications – organisations operating internationally may need to reconcile compliance with US frameworks such as CIRCIA and foreign
standards, including the EU’s Network and Infor - mation Security Directive 2 (“NIS2”). As noted in 2.1 Scope of Critical Infrastructure Cybersecurity Regulation , in addition to the forth- coming CIRCIA requirements, sector-specific notifi - cation requirements have been in place for quite some time. Those include the following. • Energy sector – the NERC, under FERC oversight, requires Bulk Electric System (BES) entities to report cybersecurity incidents that could impact reliability, including operational disruptions, unau - thorised access or attempted compromises, with notification timelines based on the severity of the incident. The most severe incidents (those that successfully compromise BES Cyber Systems and impact reliability) must be reported to the Electricity Information Sharing and Analysis Centre (E-ISAC) and CISA within one hour of determination. • Water and wastewater systems sector – under the AWIA, water utilities must notify local emergency planning committees of any disruptions affecting service delivery, including those caused by cyber - security incidents. • Nuclear sector – the NRC requires immediate noti - fication of cyber-incidents that compromise digital systems essential to nuclear safety, security, or emergency preparedness. • Transportation systems sector – the TSA requires pipeline, rail and aviation operators to report identi - fied categories of cybersecurity incidents within 24 hours and conduct post-incident reviews. • Healthcare sector – see 6.3 Cybersecurity in the Healthcare Sector . • Financial services sector – see 3. Financial Sector Operational Resilience Regulation (in particular, 3.1 Scope of Financial Sector Operational Resil- ience Regulation ). • DIB – contractors handling CUI must report cyber- incidents to the Department of Defence (DoD) within 72 hours of discovery. 2.4 State Responsibilities and Obligations State governments play a critical role in enhancing resilience and identifying threats to critical infrastruc - ture within their jurisdictions. While the federal gov - ernment provides overarching guidance and regu -
466 CHAMBERS.COM
Powered by FlippingBook