[HN Gopher] Firms must report hacks to DHS in 72 hours under law
       ___________________________________________________________________
        
       Firms must report hacks to DHS in 72 hours under law
        
       Author : marc__1
       Score  : 115 points
       Date   : 2022-03-16 14:07 UTC (8 hours ago)
        
 (HTM) web link (www.bloombergquint.com)
 (TXT) w3m dump (www.bloombergquint.com)
        
       | robin_reala wrote:
       | This is presumably based on the same reporting requirements that
       | are stipulated in section 85 of GDPR: https://eur-
       | lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
        
       | tehwebguy wrote:
       | Is there any evidence that DHS employs anyone who would even
       | understand a report about a breach?
       | 
       | Making a report to police about a crime they won't understand
       | sounds extremely risky for the reporter.
        
         | xxpor wrote:
         | CISA is under DHS.
        
       | boomboomsubban wrote:
       | I may be missing something, law is a pain to read, but I'm not
       | seeing any penalty for failure to report being mentioned. So you
       | must report or we'll be cross with you?
        
         | supercheetah wrote:
         | From what I can see, that's pretty much it. It might affect
         | future funding, but I'm betting lawyers would successfully
         | argue that some occurrence doesn't count.
        
         | awb wrote:
         | It's also not clear which businesses are mandated:
         | 
         | > The current impact of the legislation also remains unclear
         | due to lack of definition over exactly which companies will
         | fall under the reporting requirements, which will be clarified
         | in regulation
        
         | rmah wrote:
         | My guess is that a failure to report is essentially be a
         | regulatory violation, not a crime. Thus, a regulating agency
         | will determine how to enforce. Which likely means they start
         | with notices of violation and finally escalate to "reasonable"
         | fines after repeated violations for normal cases. And finally
         | the regulating agency/agencies may forward cases to the DOJ for
         | civil lawsuits for extremely egregious violations.
        
       | ericbarrett wrote:
       | Here's the text of the newly signed bill:
       | https://www.congress.gov/bill/117th-congress/house-bill/2471...
       | 
       | The ransomware reporting stuff is at the bottom; search for
       | "ransom" and you'll find the section easily.
       | 
       | Note this is amending existing law, so think of it as a legal
       | diff. There may be important context not presented in this text.
        
         | pooper wrote:
         | > Note this is amending existing law, so think of it as a legal
         | diff. There may be important context not presented in this
         | text.
         | 
         | Thank you. I thought it was strange that it seemed a little
         | vague what happens when I fail to report an incident. To me, it
         | reads like if I fail to disclose, they can request me to
         | disclose and give me 72 hours. I will be in contempt only after
         | those 72 hours.
         | 
         | So what is the incentive to report before being asked to
         | report? What are the penalties for failure to report?
         | 
         | Also it is not clear to me when that 72 hours starts. Who is
         | the firm? Sometimes things take time to "bubble up" and get
         | prioritized. I am sure there are people who have backlogs that
         | span months.
         | 
         | Thank you in advance for answering if you have a better
         | understanding of the process. (:
        
           | elliekelly wrote:
           | > Also it is not clear to me when that 72 hours starts.
           | 
           | This is always the issue with mandatory incident reporting
           | and, in my experience*, regulators tend to be fairly
           | understanding. Generally the rule is the clock starts ticking
           | "upon discovery" of the incident and there's usually a
           | "reasonable likelihood" aspect. So even if you aren't
           | _certain_ a reportable incident has occurred you 'd still be
           | required to report an event you've discovered that you're
           | reasonably sure is/may be a breach.
           | 
           | Even that leaves lots of grey area, though. Is it
           | "discovered" when the IT help desk worker comes across it or
           | is it "discovered" when it comes to the attention of senior
           | management? I think in most cases as long as it's timely(ish)
           | reported regulators aren't going to be counting the hours and
           | minutes. If I had an incident where a low-level employee
           | "discovered" it and then sat on it for three days before
           | management found out I'd probably just proactively explain
           | the timeline/delay to the regulator when we reported it and I
           | wouldn't expect it to be much of an issue.
           | 
           | *I'll add the giant caveat that I've only dealt with
           | (comparatively) low-stakes cybersecurity regulatory
           | reporting. I suspect timeliness is much more important to DHS
           | since the goal is national security rather than consumer
           | privacy/preventing crime.
        
             | citizenpaul wrote:
             | The important thing here is all the do nothing high paying
             | jobs this will create. Seriously.
             | 
             | The bad thing is all the security incident response
             | "experts" we will have to endure. Along with all the take
             | my incident response course and such.
        
               | nullc wrote:
               | HELLO. I FOUND THAT YOUR WEB SERVER HAS DIRECTORY INDEX
               | ENABLED. THIS MAY BE A MAJOR SECURITY INCIDENT.
        
             | sofixa wrote:
             | Regarding your point if a low-level employee sitting on it,
             | it's all a matter of education, training, policy. When GDPR
             | came in force, the security team at my then workplace
             | informed every employee that any suspicion of a breach
             | should be immediately brought to their attention so that
             | they can help evaluate the seriousness of the suspicion.
             | After such a policy is brought into effect, no employee
             | will "sit" on it or they risk sanctions.
        
       | rectang wrote:
       | It's apparently "critical infrastructure operators", not all
       | "firms".
       | 
       | > _sweeping cybersecurity legislation that will require critical
       | infrastructure operators to quickly report data breaches and
       | ransomware payments._
       | 
       | Pretty expansive though:
       | 
       | > _The agency lists 16 broad sectors spanning health, energy,
       | food and transportation as critical to the U.S., although the new
       | legislation is yet to spell out precisely which companies would
       | be required to report cyber incidents._
       | 
       | This data will eventually become public. So long as the DHS
       | database exists it will be hacked eventually.
        
         | reincarnate0x14 wrote:
         | The data should eventually become public. And regardless of if
         | DHS is hacked (and lets be honest this is probably going to be
         | kept in Excel somewhere), advanced actors like state-sponsored
         | groups already know who they're hacking and already sell or
         | trade access when it suits them.
         | 
         | The public finding out how badly most "critical" companies are
         | at security and integrity is really the best thing that can
         | happen.
        
       | Brian_K_White wrote:
       | Report every day because you can't prove that you weren't and you
       | wouldn't want to be accused of failing to report or failing to
       | detect later.
        
         | mynameisvlad wrote:
         | The second paragraph of the article literally states:
         | 
         | > The new law mandates that companies report hacks to the U.S.
         | Department of Homeland Security within 72 hours _of discovery_
         | of the incident, and 24 hours if they make a ransomware
         | payment.
         | 
         | The burden of proof is on the person claiming you discovered it
         | earlier.
        
         | datalopers wrote:
         | It requires companies to report within 72-hours of discovering
         | they were hacked. If they don't know they're under no
         | obligation.
        
           | dpwm wrote:
           | I have a deep suspicion this will inevitably lead to head-in-
           | the-sand as a service.
        
             | elliekelly wrote:
             | The context is ransomware, though. It would be pretty
             | useless ransomware if they didn't _tell you_ your data is
             | being held ransom and where to make a payment. It 's not
             | exactly the kind of incident you can bury your head in the
             | sand when 99% of the time you're proactively alerted to the
             | issue.
        
               | cestith wrote:
               | One context is ransomware. The other context, the 72-hour
               | one, is reasonable belief of any breach.
        
             | Arrath wrote:
             | Similarly, the suspected or known loss or theft of
             | explosives must be reported to the ATF within 24-hours of
             | the discovery. This has, in my experience, resulted in some
             | "oh no we totally know where that inventory mismatch is"
             | incidents. Boy does their tune change when I make the
             | report for them.
        
       | bokohut wrote:
       | Enforcement will be what exactly?
       | 
       | How is an impacting specific data loss inexplicitly tied to one
       | company's compromise beyond a reasonable doubt when systems
       | everywhere are "leaking"?
       | 
       | Having been involved in several financial compromise events
       | dating back to the very earliest known I find more laws will in
       | no way address the issue. Everyone drives the speed limit or
       | under it too, correct? For those with experience in the financial
       | banking realm the rules often "apply to thee but not to me" and
       | yet companies are still hiding compromise events, even those
       | 'compliant'. While companies joining the fintech rush are held to
       | standards and requirements that cost significant sums of both
       | time and money all the while the large grandfathered entities and
       | systems are allowed to continue not abiding by the same rules and
       | laws those entities themselves set. Hypocrisy rolls on and exists
       | everywhere and I welcome the changes to level the playing field
       | but more laws are certain to not fix a problem which cannot be
       | seen since the function of vision in our species is the primary
       | driver for nearly all we do. If it cannot be seen then it must
       | not be a 'real' problem so let's schedule more meetings to talk
       | about it.
       | 
       | As the governments around the world continue to have meetings
       | weekly, both publicly and privately, about the ever growing cyber
       | issue I again reiterate that the problem lies at the source(code)
       | and with those who write it. This is truly an issue that can only
       | be solved through education of those writing code and it cannot
       | be solved tomorrow. Let's schedule another meeting to talk about
       | it.
        
       ___________________________________________________________________
       (page generated 2022-03-16 23:02 UTC)