Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-06 · updated: 2026-10-06 · tags: [incident, government, ransomware] · confidence: high · severity: high · affected_sectors: [government] · au_impact: true

The US Cybersecurity and Infrastructure Security Agency (CISA) has finalised the rule implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022 and sent it to the White House's Office of Information and Regulatory Affairs for review. When final, CIRCIA will require covered entities across all 16 critical infrastructure sectors — including healthcare and public health — to report substantial cyber incidents to CISA within 72 hours of a determination that a substantial incident occurred, and to notify CISA within 24 hours of any ransomware payment made. Reporting thresholds are generally tied to company size and annual revenue, with sector-specific variations. CISA developed the rule with the 16 Sector Risk Management Agencies, the Department of Justice and the DHS-chaired Cyber Incident Reporting Council. Why it matters: a mandatory, sub-72-hour incident and 24-hour ransomware-payment reporting regime at the scale of US critical infrastructure is the single largest forcing function yet for cyber-incident disclosure practice, and a benchmark other jurisdictions — including Australia, in its SHARED-ISAC and security-of-critical-infrastructure settings — watch closely when modelling their own mandatory-reporting regimes.

Attribute Detail
Sector Government
Date 2026-10-06
Source HIPAA Journal
Reliability Tier 2