[HN Gopher] Firms must report hacks to DHS in 72 hours under law
___________________________________________________________________
Firms must report hacks to DHS in 72 hours under law
Author : marc__1
Score : 115 points
Date : 2022-03-16 14:07 UTC (8 hours ago)
(HTM) web link (www.bloombergquint.com)
(TXT) w3m dump (www.bloombergquint.com)
| robin_reala wrote:
| This is presumably based on the same reporting requirements that
| are stipulated in section 85 of GDPR: https://eur-
| lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
| tehwebguy wrote:
| Is there any evidence that DHS employs anyone who would even
| understand a report about a breach?
|
| Making a report to police about a crime they won't understand
| sounds extremely risky for the reporter.
| xxpor wrote:
| CISA is under DHS.
| boomboomsubban wrote:
| I may be missing something, law is a pain to read, but I'm not
| seeing any penalty for failure to report being mentioned. So you
| must report or we'll be cross with you?
| supercheetah wrote:
| From what I can see, that's pretty much it. It might affect
| future funding, but I'm betting lawyers would successfully
| argue that some occurrence doesn't count.
| awb wrote:
| It's also not clear which businesses are mandated:
|
| > The current impact of the legislation also remains unclear
| due to lack of definition over exactly which companies will
| fall under the reporting requirements, which will be clarified
| in regulation
| rmah wrote:
| My guess is that a failure to report is essentially be a
| regulatory violation, not a crime. Thus, a regulating agency
| will determine how to enforce. Which likely means they start
| with notices of violation and finally escalate to "reasonable"
| fines after repeated violations for normal cases. And finally
| the regulating agency/agencies may forward cases to the DOJ for
| civil lawsuits for extremely egregious violations.
| ericbarrett wrote:
| Here's the text of the newly signed bill:
| https://www.congress.gov/bill/117th-congress/house-bill/2471...
|
| The ransomware reporting stuff is at the bottom; search for
| "ransom" and you'll find the section easily.
|
| Note this is amending existing law, so think of it as a legal
| diff. There may be important context not presented in this text.
| pooper wrote:
| > Note this is amending existing law, so think of it as a legal
| diff. There may be important context not presented in this
| text.
|
| Thank you. I thought it was strange that it seemed a little
| vague what happens when I fail to report an incident. To me, it
| reads like if I fail to disclose, they can request me to
| disclose and give me 72 hours. I will be in contempt only after
| those 72 hours.
|
| So what is the incentive to report before being asked to
| report? What are the penalties for failure to report?
|
| Also it is not clear to me when that 72 hours starts. Who is
| the firm? Sometimes things take time to "bubble up" and get
| prioritized. I am sure there are people who have backlogs that
| span months.
|
| Thank you in advance for answering if you have a better
| understanding of the process. (:
| elliekelly wrote:
| > Also it is not clear to me when that 72 hours starts.
|
| This is always the issue with mandatory incident reporting
| and, in my experience*, regulators tend to be fairly
| understanding. Generally the rule is the clock starts ticking
| "upon discovery" of the incident and there's usually a
| "reasonable likelihood" aspect. So even if you aren't
| _certain_ a reportable incident has occurred you 'd still be
| required to report an event you've discovered that you're
| reasonably sure is/may be a breach.
|
| Even that leaves lots of grey area, though. Is it
| "discovered" when the IT help desk worker comes across it or
| is it "discovered" when it comes to the attention of senior
| management? I think in most cases as long as it's timely(ish)
| reported regulators aren't going to be counting the hours and
| minutes. If I had an incident where a low-level employee
| "discovered" it and then sat on it for three days before
| management found out I'd probably just proactively explain
| the timeline/delay to the regulator when we reported it and I
| wouldn't expect it to be much of an issue.
|
| *I'll add the giant caveat that I've only dealt with
| (comparatively) low-stakes cybersecurity regulatory
| reporting. I suspect timeliness is much more important to DHS
| since the goal is national security rather than consumer
| privacy/preventing crime.
| citizenpaul wrote:
| The important thing here is all the do nothing high paying
| jobs this will create. Seriously.
|
| The bad thing is all the security incident response
| "experts" we will have to endure. Along with all the take
| my incident response course and such.
| nullc wrote:
| HELLO. I FOUND THAT YOUR WEB SERVER HAS DIRECTORY INDEX
| ENABLED. THIS MAY BE A MAJOR SECURITY INCIDENT.
| sofixa wrote:
| Regarding your point if a low-level employee sitting on it,
| it's all a matter of education, training, policy. When GDPR
| came in force, the security team at my then workplace
| informed every employee that any suspicion of a breach
| should be immediately brought to their attention so that
| they can help evaluate the seriousness of the suspicion.
| After such a policy is brought into effect, no employee
| will "sit" on it or they risk sanctions.
| rectang wrote:
| It's apparently "critical infrastructure operators", not all
| "firms".
|
| > _sweeping cybersecurity legislation that will require critical
| infrastructure operators to quickly report data breaches and
| ransomware payments._
|
| Pretty expansive though:
|
| > _The agency lists 16 broad sectors spanning health, energy,
| food and transportation as critical to the U.S., although the new
| legislation is yet to spell out precisely which companies would
| be required to report cyber incidents._
|
| This data will eventually become public. So long as the DHS
| database exists it will be hacked eventually.
| reincarnate0x14 wrote:
| The data should eventually become public. And regardless of if
| DHS is hacked (and lets be honest this is probably going to be
| kept in Excel somewhere), advanced actors like state-sponsored
| groups already know who they're hacking and already sell or
| trade access when it suits them.
|
| The public finding out how badly most "critical" companies are
| at security and integrity is really the best thing that can
| happen.
| Brian_K_White wrote:
| Report every day because you can't prove that you weren't and you
| wouldn't want to be accused of failing to report or failing to
| detect later.
| mynameisvlad wrote:
| The second paragraph of the article literally states:
|
| > The new law mandates that companies report hacks to the U.S.
| Department of Homeland Security within 72 hours _of discovery_
| of the incident, and 24 hours if they make a ransomware
| payment.
|
| The burden of proof is on the person claiming you discovered it
| earlier.
| datalopers wrote:
| It requires companies to report within 72-hours of discovering
| they were hacked. If they don't know they're under no
| obligation.
| dpwm wrote:
| I have a deep suspicion this will inevitably lead to head-in-
| the-sand as a service.
| elliekelly wrote:
| The context is ransomware, though. It would be pretty
| useless ransomware if they didn't _tell you_ your data is
| being held ransom and where to make a payment. It 's not
| exactly the kind of incident you can bury your head in the
| sand when 99% of the time you're proactively alerted to the
| issue.
| cestith wrote:
| One context is ransomware. The other context, the 72-hour
| one, is reasonable belief of any breach.
| Arrath wrote:
| Similarly, the suspected or known loss or theft of
| explosives must be reported to the ATF within 24-hours of
| the discovery. This has, in my experience, resulted in some
| "oh no we totally know where that inventory mismatch is"
| incidents. Boy does their tune change when I make the
| report for them.
| bokohut wrote:
| Enforcement will be what exactly?
|
| How is an impacting specific data loss inexplicitly tied to one
| company's compromise beyond a reasonable doubt when systems
| everywhere are "leaking"?
|
| Having been involved in several financial compromise events
| dating back to the very earliest known I find more laws will in
| no way address the issue. Everyone drives the speed limit or
| under it too, correct? For those with experience in the financial
| banking realm the rules often "apply to thee but not to me" and
| yet companies are still hiding compromise events, even those
| 'compliant'. While companies joining the fintech rush are held to
| standards and requirements that cost significant sums of both
| time and money all the while the large grandfathered entities and
| systems are allowed to continue not abiding by the same rules and
| laws those entities themselves set. Hypocrisy rolls on and exists
| everywhere and I welcome the changes to level the playing field
| but more laws are certain to not fix a problem which cannot be
| seen since the function of vision in our species is the primary
| driver for nearly all we do. If it cannot be seen then it must
| not be a 'real' problem so let's schedule more meetings to talk
| about it.
|
| As the governments around the world continue to have meetings
| weekly, both publicly and privately, about the ever growing cyber
| issue I again reiterate that the problem lies at the source(code)
| and with those who write it. This is truly an issue that can only
| be solved through education of those writing code and it cannot
| be solved tomorrow. Let's schedule another meeting to talk about
| it.
___________________________________________________________________
(page generated 2022-03-16 23:02 UTC)