On March 15, 2022, President Biden signed into law the 2022 Consolidated Appropriations Act containing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (the “Cyber Incident Reporting Act”). While President Biden’s remarks highlighted the $13.6 billion in funding “to address Russia’s invasion of Ukraine and the impact on surrounding countries,” the 2022 Consolidated Appropriations Act contained numerous other laws, including the Cyber Incident Reporting Act, which should not be overlooked. The Cyber Incident Reporting Act puts in motion important new cybersecurity reporting requirements that will likely apply to businesses in almost every major sector of the economy, including health care, financial services, energy, transportation and commercial facilities. Critical infrastructure entities should monitor the upcoming rule-making by the Cybersecurity and Infrastructure Security Agency (“CISA”), as the final regulations will clarify the scope and application of the new law.
Blog Editors
Recent Updates
- Watch: DOJ’s New Self-Disclosure Rules: Decide Fast or Lose the Credit – Speaking of Litigation
- AI Medical Technology Meets IP Law in Patent Infringement Suit
- DOJ Civil Division Announces Accelerated Review of FCA Whistleblower Complaints Involving Federally Funded, State-Administered Benefits Programs
- Washington Amends CEMA: Plaintiffs Rush to File Actions Before June 11, 2026 Effective Date
- Five Cases Health Care and Life Sciences GCs Should Keep Watching in 2026