Reporting Cyber Incidents Within 72 Hours: Challenges Ahead episode artwork

EPISODE · Jul 19, 2023

Reporting Cyber Incidents Within 72 Hours: Challenges Ahead

from Info Risk Today Podcast · host InfoRiskToday.com

Many critical infrastructure sector organizations, especially smaller entities, will likely struggle to comply with an upcoming requirement to report cyber incidents to federal regulators within 72 hours - due to an assortment of reasons, said Stanley Mierzwa of Kean University.

Episode metadata supplied by the publisher feed · Published Jul 19, 2023

Embed this episode

NOW PLAYING

Reporting Cyber Incidents Within 72 Hours: Challenges Ahead

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Colby-Saklicki, executive editor at Information Security Media Group. Today I'm speaking with Stan Merzwe who is managing assistant director at the Center for Cybersecurity at King University in New Jersey. Stan is also a fellow of the Institute for Critical Infrastructure Technology and a member of the New Jersey Infogard. We're going to be discussing incident response issues.

So Stan, rulemaking is still underway for the Cyber Incident Reporting for Critical Infrastructure Act of 2022 and a notice of proposed rulemaking from the Cybersecurity Infrastructure and Security Agency is expected to be published no later than March 2024. But as it stands now, the act will require that a cover entity report a covered cyber incident to CISA, no later than 72 hours after the covered entity reasonably believes the incident hasn't occurred. And based on the work you do, including some of the work you do with Infogard and in your other roles, what are some of the key challenges that you foresee health sector entities having in complying to a 72-hour reporting mandate for cyber incidents and why? I think organizations of all types in the different sectors should welcome this opportunity to be able to report.

One of the things, and in my unit here in the Center for Cybersecurity, we often partner with student researchers and we pick topics that are interesting that we discuss in class and some of them are current events such as this was in 2022 and begin to deep dive into the topic a bit more. And so as part of that, we have begun to do some research on this topic. We looked at things such as, hey, what is a covered entity quite honestly, right? There are many in education and in technology who may not recognize that there are 16 critical sectors.

This was all outlined by the Presidential Policy Directive created by President Obama back in 2013, which really focused on the critical infrastructure areas of our nation's backbone. So think areas such as agriculture and food, health care, as you mentioned, communications, government facilities, financial services. When it comes to health care, one of the things we found, and this is quite interesting, many sectors do not report cyber incidents, but health care, when posed, some questions, and this was from the Cyber Peace Institute. Just in 2021, they asked why health care organizations may be under reporting cyber incidents.

And one of the reasons they reported is they weren't sure how to do it, or who to report it to. So right there, we have an issue surrounding awareness of reporting. So this activity around Circia is, I think, welcoming, at least to me, because I think we should be collecting this information and data, but it's helpful to organizations, as you mentioned, in health care, because they'll have directions on where to report. What are the kinds of organizations that you think will likely face the biggest challenges and why?

And as you mentioned, health care entities, if they're a covered entity or a business associate, they have to report breaches that affect 500 or more to the Department of Health and Human Services within 60 days of discovering an incident. But we know that that doesn't always happen. So now shortening it to 72 hours is probably going to be a big challenge for many. What sorts of organizations do you think will face the biggest challenges and why?

Yeah, you know, one area that we picked up on is obviously we have the 16 critical sectors, but many of our important sector areas might actually sit in that right when it comes to the government sectors, we, you know, there's strong mandates to do so. But the private sector, which could be smaller outfits, may struggle with this. They may not be able to know exactly what has transpired, quite honestly, with an attack or a breach, not have all the information lines up to be able to meet the constraints of the timeline. So I think there's some issues there, quite honestly.

Other things I'll mention, lots of organizations are grappling with to report or not to report. And one of the findings we had, we wanted to, you know, find information about why organizations don't report. And most of it may seem obvious. You may think, well, it's reputational loss.

We don't want the bad press. But there are other areas that may make it hard for organizations to report. Number one, there might be areas around facing liability issues. So you might need to first contact your legal departments and speak about that your insurance companies before actually reporting.

There's concerns about regulators and whether there'll be any reprisal from regulators if you do report other issues around this is it may also, and this is for me, a big one, it's coming to grips with recognizing the fact that you may be lacking necessary cybersecurity defenses or the funding. So you're, you're kind of, if you do, and you shouldn't be ashamed by it, but if you are attacked and hit with ransomware and binded by reporting it, we shouldn't feel bad about that. And we shouldn't feel that, you know, goodness, we were lacking in our cybersecurity defenses, because quite honestly, the internet was designed to share and be open, and we're seeing the ramifications of that. Some other reasons which may make it a challenge for organizations to report is that because of the transnational nature of attacks happening from across the globe, it's difficult to find sometimes the threat actor.

And in short-sighted thinking, you could have organizations who may think, you know what, I'll throw my hands up, nobody's going to help with this in my specific situation. But that I think is, as I said, short-sighted thinking, because you could be helping other organizations in that sector with awareness into the attacks and what transpired, so that they can actually prevent it from happening to other organizations. So there's quite a few reasons and constraints, which will make it difficult. But I think at the same point, this conversation, just having this conversation with you, Mary Ann, I think is helpful in being open and transparent about this topic.

So, again, once this rule does kick in, and entities have 72 hours to report a cyber incident to SISA, you know, an entity that's part of this, of these 16 critical infrastructure sectors, do you think it will force some of these entities to sort of reevaluate sort of their preparedness plans for incident response that they have now so that, you know, they know that, okay, we're going to have the 72 hour deadline all of a sudden, you know, we better get our acts together if we're not really prepared to do that now, but we know we're going to have to do that. What will they need to do? For now, I would recommend all organizations look at their incident reporting procedures and their standard operating procedures on how they are to handle incidents and think about how this should be integrated into those strategies. I think that's an important one that will be a change for organizations with their plans, and quite honestly, May warrants a tabletop exercise, for example, to see how that fits in.

So, I think that's one area where organizations may improve other things to think about with organizations. I think, right, we walk greater harmony and data collection, and when it comes to events like these, and the reason is it can help, as I said earlier, the other organizations in our sectors, I think it's important to our nation, right, we think about our economy, we think about our individuals, many of these critical sectors deal with, you know, humans, right, we're dealing with people in healthcare. I want to be able to go to the hospital if I need medical assistance and not have to be concerned about whether the systems are up and running in the operating room, for example. So, I think there's a greater sense of community when it comes to reporting.

So, I think that will be certainly one benefit of harmonizing this data collection. The other thing, we just wrote a small piece around the element of greater partnerships with law enforcement for cybersecurity. And the part of this write up, which is a small, it's not long, I think it's just over 1,000 words, but we bring up the topic of let's partner in larger percentages, our research efforts with both state, federal, and local enforcement for the benefit of cybersecurity. By reporting, I think we're going to be able to defend a bit better.

I think we will certainly be more open. I don't think we're going to be as ashamed if an attack happens. And quite honestly, I think we'll be given some more guidance too, rather than feeling we're on our own. San, as you know, that act also requires a system to develop and issue regulations requiring cover entities to report to Cesar within 24 hours of making any ransom payments as a result of a ransomware attack.

If entities have to report ransomware payments to Cesar within 24 hours of making a payment, do you think that will make some entities more hesitant to pay ransoms, being that they know they're going to have to let the government know about this? Will this for some entities maybe to think twice about why are we paying and why? The one thing I will mention, it will certainly get organizations at the top. And I'm thinking the board of directors, if they haven't done this already, but have that conversation around, well, if we are hit with ransomware, what is our strategy?

If an organization hasn't done that yet, this could be that opportunity to do so, because there should be some sort of strategy. And each organization, and I think the FBI recognizes this, they obviously don't want to see the ransomware payments made, but they're changing their strategy. Also, if you look at some of the guidelines over the past few years, they've said, well, each organization will have to make their decision on, from their perspective, what's important. Think of the pipeline, colonial pipeline.

Days and days were passing, and they ended up paying the ransom. It was extremely critical for the movement of, in this case, pipeline fuel in the pipeline. And I think that was one example of, yes, we paid, there was a little bit of feeling of being dejected. I would assume but soon after, the FBI was able to actually recover some of those funds.

And in fact, as I recall, they recovered quite a bit of it. So at a minimum, I think organizations should have a good strategy in place for ransomware payments. And I think this might help bring this to light a bit more. And again, what we're trying to do is improve, right, when it comes to our strategies.

And finally, Stan, you mentioned colonial pipeline, and we've talked a bit about the healthcare sector. But are there other industries that you think that will have difficulty in complying with the requirements of this act, in terms of the 72 hour reporting and perhaps the 24 hour ransom payment reporting, and why? There have been reporting guidelines, as we talked about in healthcare, you know, there are HIPAA guidelines, the energy area, there's certainly reporting guidelines that have existed already. So some of these are in better shape than others.

And in fact, we created the table of all the sectors. And what we're trying to do, we haven't completed this yet. We've noted all the sectors. And what we said is, which agency provides guidance, and what is the detailed reporting mechanism as it stands now.

Now, I could only assume that CISA is probably looking at this right now as well to try to determine what's in place, and what they can actually leverage what's been already utilized. But some sectors are in better shape. I would certainly think transportation is in good shape, or better shape than others. Healthcare certainly, government facilities, water and wastewater systems, maybe there's some area there.

But I don't want to pick on any of the sectors, because I think any of them, regardless, could be targeted, right? If there are motives against a particular sector, that will make it even more difficult to contend with incidents and increase reporting. So, right, if you think the World Economic Forum continues to cite and recognize that cyber attacks are among the top five risks to our critical infrastructure. This remains one of the top fives.

And I think, as that continues, we're going to continue to look for ways to improve our resilience of our critical infrastructures. Well, thank you so much, Stan. I've been speaking to Stan Merzwa. I'm Mary Ann Kolpasek McGee of Information Security Media Group.

Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on July 19, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!