Another reason is that the vast majority of successful attacks come not from being targeted by an elite team of hackers but from employee ignorance and negligence. There's a reason I keep writing about how to avoid being phished. Unfortunately, it still happens all the time. Simple e-mail phishing tricks to get you to click on a link or open a file are still one of the top ways an attacker makes it into your systems. The other big reason companies get hacked: someone inside maliciously — or stupidly, it's sometimes hard to tell the difference — opens the door to an attacker. In either case, no one inside a company wants to admit to those kinds of "fire me now" mistakes. Well, the days when you could just do your best to fix the blunder and then pretend it never happened are ending. While the exact regulations are yet to be written, going forward, the Department of Homeland Security's (DHS's) Cybersecurity and Infrastructure Security Agency (CISA) will demand you keep them in the loop when your security goes awry. If your business is in one of 16 critical infrastructure sectors, you'll need to let the CISA know when you've been successfully attacked. For clarity, the new law requires you to report hacks within 72 hours of discovering an incident and 24 hours if you make a ransomware payment. Before you hyperventilate, take a deep breath. It may be the law of the land, but the regulations that turn that law into something you must comply with haven't been written yet. According to the major international law firm Holland & Knight, "The new cyber reporting obligations will not become effective until CISA promulgates rules to define the entities within the critical infrastructure sectors that will be impacted by this law and the types of substantial cyber incidents it covers." The CISA has two years to write up the regulations and then 18 months until they become final. Making laws and regulations is a long, tedious process. In addition, not everyone in the government is keen on this new law. In what appears to be a classic governmental turf war, the Justice Department and FBI don't care for it one little bit. FBI Director Christopher Wray thinks it "has some serious flaws" and "would make the public less safe from cyber threats" because it sidelines the FBI in favor of the CISA. Be that as it may, some kind of legal insistence that businesses actually report and track break-ins and ransomware attacks is coming. Get ready. And — just a thought — how about taking better care of your security today, so you don't need to worry about explaining why you didn't report a significant incident when the day comes. | | |