CIRCIA's Looming Impact on Network Systems
CIOREVIEW >> Legal >> NEWS

Frost Brown Todd

Gene Forrest Price, Attorney and Member of the Firm, Partner

CIRCIA's Looming Impact on Network Systems

Gene Forrest Price, Attorney and Member of the Firm, Partner
Gene Forrest Price, Attorney and Member of the Firm, Partner, Frost Brown Todd

A lot of challenges have been thrown at CIOs since the beginning of this decade. It began with the most IT-stressing epidemic in world history— millions and millions of people trying to work from home at the same time. That was followed in 2021 with a 100%+ increase in ransomware attacks and with ransomware payments rising to a historic record average of $570,000, cyber insurance became more expensive and harder to acquire. Federal cybersecurity and privacy regulations and guidance went into overdrive, with many federal agencies wading deeper into the IT compliance arena. California and other states issued privacy regulations due to Congress’ inability to pass a comprehensive privacy bill.

All these and other challenges often made it difficult to be proactive with enterprise solutions for corporate systems. With more executives paying attention to cybersecurity headlines, many discussions suddenly focused on how events could affect a company, and less about investments in enterprise solutions needed to keep the company competitive. The good news is that there will be opportunities in 2023 for CIOs to take advantage of the most significant of these events to drive home some security-related enterprise solutions they believe their companies need. That event is the long-awaited federal cybersecurity bill called the Cyber Incident Reporting for Critical Infrastructure Act of 2022, better known as CIRCIA.

Enforcement of CIRCIA is subject to new regulations that have not yet been issued, but begins no later than 2025, perhaps next year. It is time to plan investments in cybersecurity architectures, policies, and incident response plans. Understanding where your data is stored, how it is transported, how it is protected, and who it is going to outside your IT enterprise will be more vital than ever to ensure reporting readiness under the new law. Although the full scope of its four W’s (who, what, when, where) has not been established, we do know enough to begin preparing:

Who Must Report?

Businesses designated as “covered entities” must report. These will likely consist of the 16 critical infrastructure sectors defined by Presidential Policy Directive 21. In the private sector, these should include (but are not limited to) chemical, commercial facilities, communications, critical manufacturing, defense industrials, emergency services, energy, financial services, food and agriculture, healthcare, information technology, waste transportation, waste, and wastewater systems. The new regulations will refine this list, but to stay on the safe side, presume your business will be subject to CIRCIA.

What Does a Covered Entity Report?

Covered entities will be required to report “covered cyber incidents” and ransom payments made to resolve ransomware attacks. What comprises a covered cyber incident is not yet fully clear, but indications are it will include negatively impactful events:

•Substantial loss to confidentiality, integrity, and availability of information systems, or serious impact to safety and resiliency of operational systems.

•Disruption of business or industrial operations

•Unauthorized access or disruptions by third parties

•Numbers of people impacted, and

•WImpacts to industrial control systems.

 ​Understanding where your data is stored, how it is transported, how it is protected, and who it is going to outside your IT enterprise will be more vital than ever to ensure reporting readiness under the future enforcement of CIRCIA 

Not only will impacts be reportable, but also ransomware payments, including:

• Descriptions of ransomware attacks, including date ranges

• Vulnerabilities, tactics, techniques, and procedures used in ransomware attacks

• Contact information related to the attackers believed responsible

• Information about the company making the payment or on whose behalf it was made

• Ransomware amount demand, type of currency, or another commodity requested

•Ransomware payment instructions, including where paymen was sent, and

• The date and amount of payment(s).

When Must Covered Entities Report?

The rule will require a covered entity to report covered cyber incidents (whether known or based on reasonable belief) within 72 hours and ransomware payments within just 24 hours.

Where Does a Covered Entity Report?

Reports go to CISA (Cybersecurity and Infrastructure Security Agency) but CIRCIA disallows litigation, and some regulatory claims based on reports if written solely for statutory compliance. CIRCIA grants exemptions from freedom-of-information requests and provides limited attorney/client privileges. Legal guidance here, as with other CIRCIA issues, should come from company counsel, but CIOs should be prepared to discuss what goes in the required reports once the reporting extent is known.

What Could the Four W’s Mean for Your Business?

CIRCIA includes incidents involving industrial control systems.

Many CIO’s have little to do with company operational technology networks, but usually have some oversight where the demilitarized zone network boundaries meet company operational network systems. Who will be responsible for reporting incidents in that area, should be pre-de ermined.

Understanding tactics, techniques, and procedures will almost certainly require logging.

Logging is not done automatically on many networks, but it is invaluable when it comes to fighting through a ransomware attack. Reporting vulnerabilities could be embarrassing for a company, such as weak passwords when multi-factor authentication is a widely-accepted improvement over passwords alone.

New Company Procedures

Companies regarded as being within any of the critical infrastructure sectors could be required to implement monitoring and investigate suspicious activity that could lead to discovering reportable incidents. Investing now in tools and procedures that ensure accurate understanding of an attack will not only help compliance, but help protect and defend your networks.

It will be a while before CIRCIA’s final rulemaking is complete and we know Who will be responsible to report What to Whom, and When. But it will be upon us before we’re ready unless we start thinking now.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.