HomeSecurityUSA: Bill would oblige companies to report hacks to the government

US: Bill would force companies to report hacks to the government

A new bill unveiled in the USwould require some companies to report hacks . The bipartisan Cyber ​​Incident Reporting Act is a response to the recent cyberattacks on SolarWinds and Colonial Pipeline. Since then, ransomware attacks – where hackers encrypt files until the victim pays a ransom – have proliferated.

The problem, according to federal law, is that companies are not required to report these incidents. This means that some incidents may occur without the government knowing about it, which could have serious consequences if the government's systems are potentially involved in an attack.

The bill introduces a new notification requirement for federal agencies, federal contractors, and critical infrastructure companies to notify the Department of Homeland Security (DHS) when they discover a breach of their systems. It also gives these companies limited immunity when they report a breach – for example, shareholders would not be able to access the disclosed information to use as evidence in a lawsuit – and requires DHS to anonymize personally identifiable information. This way, companies can report incidents quickly and allow the government to take effective action where necessary.

Read also: China: Denies US hacking allegations and accuses them of cyber espionage

USA - Bill companies hacks
US: Bill would force companies to report hacks to the government

Senate Intelligence Committee Chairman Mark Warner, Vice Chairman Marco Rubio, and ranking member Susan Collins led the legislation, which responds to concerns raised in a previous hearing about the SolarWinds attack.

During the hearing, Microsoft President Brad Smith testified that the only reason the government and the public knew about the incident was because cybersecurity firm FireEye reported what it believed was a state-sponsored attack on its own systems in December. Following that disclosure, Reuters reported a possible connection to adversaries in U.S. agencies through software updates from SolarWinds. Sources later told Reuters that the attack was linked to the FireEye incident.

See also: Tokyo 2021: Will hackers "hit" the Summer Olympics?

USA Bill companies hacks
US: Bill would force companies to report hacks to the government

The incident showed lawmakers how easily they could have been left in the dark about a major government hack. It also exposed the hurdles companies face when deciding whether to report a cyberattack or not.

FireEye CEO Kevin Mandia told CNBC's Eamon Javers in an interview during that hearing that the disclosure is "a complex issue.

Suggestion: Pegasus spyware: Used to hack mobile journalists and other targets

USA Bill companies hacks
US: Bill would force companies to report hacks to the government

Specifically, he said: “The reason it’s a complicated issue is all the liabilities that companies face when they go public with a disclosure. They have shareholder lawsuits, they have a lot of opinions about the impact of the business. They also don’t want to unnecessarily create a lot of fear, uncertainty and doubt.”

The new bill aims to alleviate this fear for businesses by introducing limited liability protection.

Information source: cnbc.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS