Senator Mark Warner (D-VA) is considering mixing aspects of his Cyber Incident Notification Act with related proposals in the House-passed National Defense Authorization Act, which would require CISA to develop mandatory rules for infrastructure companies to report cyber incidents. Industry prefers the more lenient deadlines of the House bill over Warner’s 24-hour time limit. Warner is critical of the penalties in the House bill, which he calls “toothless.”
Meanwhile, the Senate Homeland Security and Governmental Affairs Committee has approved a bill written by Senators Gary Peters (R-MI) and Rob Portman (R-OH) which would set a 72-hour deadline for reports, and add ransomware payments to the notification requirement list.
Source:
